Skip to content

Base64 decode

EncodeExperimentalLimited support. Verify anything critical.

Base64 decode is a developer tool that takes a 64-character alphabet sequence—whether standard or URL-safe—and reverses it back to its original UTF-8 string representation. It rejects strings with illegal characters immediately, ignoring whitespace. Use it to recover binary or text data packed for transport. Crucially, all processing happens entirely locally in your web browser, ensuring your data remains completely private and never leaves your device.

Skip to the tool

This tool processes text on your device. The text is not uploaded.

  • Decodes UTF-8 text and can download the decoded bytes as a local binary file.
  • Fails on input strings that do not map to valid UTF-8 sequences.

How to use Base64 decode

What is Base64 decode?

Base64 decode is a developer tool that takes a 64-character alphabet sequence—whether standard or URL-safe—and reverses it back to its original UTF-8 string representation. It rejects strings with illegal characters immediately, ignoring whitespace. Use it to recover binary or text data packed for transport. Crucially, all processing happens entirely locally in your web browser, ensuring your data remains completely private and never leaves your device.

Technical overview

Base64 decoding reverses the binary-to-text algorithm standardized in RFC 4648. It translates ASCII characters back into their original 8-bit byte sequences, enabling applications to recover data payload fragments transported across legacy or strict text protocols.

6-bit to 24-bit reassembly

The decoder processes input characters in sequential blocks of four:

  1. Character lookup: Each of the four characters is mapped back to its 6-bit integer value (0-63) using the standard index table.
  2. Buffer assembly: The four 6-bit values (4 x 6 = 24 bits) are concatenated into a single 24-bit buffer.
  3. Byte extraction: The 24-bit buffer is partitioned into three 8-bit bytes (3 x 8 = 24 bits), recovering the original binary data.
  4. Padding resolution: If the input ends with padding characters (=), the decoder discards the trailing zero bits to extract the final one or two valid bytes.
Practical developer use cases

Base64 decoding is an essential utility for modern software development and cybersecurity:

  • Decoding web API payloads: Extracting readable JSON data from Base64-encoded standard tokens like JSON Web Tokens (JWTs) or OpenID Connect claims.
  • Reading email MIME attachments: Unpacking inline email text bodies or multi-part attachment boundaries.
  • Security audits & forensics: Reversing encoded strings found in malicious network traffic or obfuscated application logs.
  • Decoding Kubernetes secrets: Recovering plain-text configuration values from Kubernetes Secret manifests, which mandate Base64 encoding for storage.
Best practices

To effectively work with Base64 decoded data, keep these best practices in mind:

  • Understand character encodings: This tool assumes the decoded bytes represent UTF-8 text. If your decoded output results in gibberish, the original payload might be binary data (like an image or gzip archive) or use a different character encoding.
  • Handle URL-safe variants: Ensure your decoding logic can handle URL-safe variants, where hyphens and underscores replace pluses and slashes. Our tool automatically handles this normalization.
  • Strip whitespace: Real-world Base64 payloads often contain line breaks or whitespace from formatting. A robust decoder should always safely strip these characters prior to processing.
Security considerations

Base64 encoding is not encryption. It provides no confidentiality or cryptographic security. Never assume decoded data is safe to execute, parse, or render without proper sanitization. Always treat decoded payloads as untrusted user input to prevent injection attacks and other security vulnerabilities in your applications.

Code examples

Here is how you can implement Base64 decoding in various programming languages:

JavaScript / TypeScript

function decodeBase64(base64Str: string): string {
  // Normalize URL-safe characters
  const normalized = base64Str.replace(/-/g, "+").replace(/_/g, "/");
  const binary = atob(normalized);
  const bytes = new Uint8Array(binary.length);
  for (let i = 0; i < binary.length; i++) {
    bytes[i] = binary.charCodeAt(i);
  }
  return new TextDecoder().decode(bytes);
}

Python 3

import base64

def decode_base64(encoded_text: str) -> str:
    # URL-safe b64decode handles both standard and url-safe alphabets
    return base64.urlsafe_b64decode(encoded_text).decode("utf-8")

Shell (cURL / OpenSSL)

echo "VHJlbmRhbHl6ZXI=" | base64 --decode

How it works

  1. Enter what you haveType or pick your text. Nothing is submitted anywhere.
  2. It runs in this tabThe calculation happens on your device, using your browser's own data.
  3. Take the resultRead the text, then copy, download, or share a link.

Reimplemented locally. Not derived from IT-Tools source.

Basis
independent
Licence
MIT
Last reviewed

Frequently asked questions

Why do some Base64 strings decode to meaningless gibberish?

If the decoded bytes do not form valid UTF-8 text (e.g. they represent an image file, a compiled binary, or compressed gzip data), rendering them as a text string will result in unreadable replacement characters.

Does this decoder support URL-safe Base64?

Yes. The decoder automatically handles URL-safe variants by translating '-' to '+' and '_' to '/' before decoding.

Is whitespace allowed in the input?

Yes. All whitespace characters (spaces, tabs, newlines) are safely stripped from the input string prior to decoding.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close