Quick Answer: A Base64 decoder converts a Base64 string back into its original data: plain text, JSON, an image or a file. For example, SGVsbG8sIFdvcmxkIQ== decodes to "Hello, World!". Base64 is an encoding, not encryption, so anyone can decode it without a key. Paste your string into the free EasifyMe Base64 Decoder to see the original data instantly.
Key Takeaways
- Base64 strings use only A–Z, a–z, 0–9, + and /, and often end with one or two = signs.
- A valid standard Base64 string has a length that is a multiple of 4 (padding included).
- Strings starting with eyJ are usually Base64-encoded JSON, as in JWTs.
- URL-safe Base64 uses - and _ instead of + and /, and often drops the padding.
- Decoding a JWT shows its contents, but it does not verify that the token is genuine.
How to Recognise a Base64 String
Before you decode, it helps to confirm you are looking at Base64. Common signs:
|
Clue |
What it tells you |
|
Only letters, digits, +, / (or - and _) |
Standard or URL-safe Base64 alphabet |
|
Ends with = or == |
Padding, a strong sign of Base64 |
|
Length divisible by 4 |
Standard padded Base64 |
|
Starts with eyJ |
Encoded JSON beginning with {" |
|
Starts with data:image/png;base64, |
An image embedded as a data URI |
|
Starts with iVBORw0KGgo |
An encoded PNG file |
|
Starts with JVBERi0 |
An encoded PDF file |
For long strings, paste them into the Character Counter to check whether the length is a multiple of 4.
How to Decode Base64 Online (Step by Step)
- Open the free Base64 Decoder.
- Paste the Base64 string. If it is a data URI, you can paste the whole thing.
- Run the decode.
- Read the decoded text, or preview and download the decoded image or file.
- If the result looks like JSON, copy it into the JSON Formatter to make it readable.
Decoding happens in your browser, so tokens, credentials or private data you paste are not sent to a server.
Worked Examples
Example 1: Decoding plain text
|
Base64 |
Decoded |
|
SGVsbG8sIFdvcmxkIQ== |
Hello, World! |
|
RWFzaWZ5TWU= |
EasifyMe |
|
dXNlcjpwYXNzMTIz |
user:pass123 |
The last one is a typical HTTP Basic Authentication value, which is a good reminder that Base64 hides nothing.
Example 2: Reading a JWT
A JSON Web Token has three parts separated by dots: header, payload and signature. The first two are URL-safe Base64-encoded JSON. The header eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 decodes to:
{"alg":"HS256","typ":"JWT"}
Decoding the payload the same way shows claims such as the user ID and expiry time. Remember: this only reads the token. Your server must still verify the signature before trusting it.
Try it free: Decode any Base64 string, JWT part or data URI in the free Base64 Decoder, right in your browser.
Example 3: Turning a data URI back into an image
You find an image in a CSS file written as data:image/png;base64,iVBORw0KGgo... Decoding the part after the comma gives you the original PNG, which you can download and edit like any other image file.
How to Decode Base64 in Code
// JavaScript (browser) - ASCII text
atob("SGVsbG8sIFdvcmxkIQ==");
// JavaScript (browser) - UTF-8 text
new TextDecoder().decode(Uint8Array.from(atob(b64), c => c.charCodeAt(0)));
// Node.js
Buffer.from("SGVsbG8sIFdvcmxkIQ==", "base64").toString("utf8");
# Python
import base64
base64.b64decode("SGVsbG8sIFdvcmxkIQ==").decode("utf-8")
# Linux / macOS terminal
echo "SGVsbG8sIFdvcmxkIQ==" | base64 --decode
For URL-safe strings in Python, use base64.urlsafe_b64decode(), and add back any missing = padding first.
Common Base64 Decoding Errors and Fixes
|
Error or symptom |
Likely cause |
Fix |
|
"Incorrect padding" (Python) |
Missing = at the end |
Add = until the length is a multiple of 4 |
|
"InvalidCharacterError" (browser atob) |
URL-safe characters, spaces or line breaks |
Replace - with +, _ with /, and remove whitespace |
|
Output is garbled symbols |
The data is binary, such as an image or file |
Save the output as a file instead of reading it as text |
|
Accented letters look broken (é) |
Text decoded with the wrong character set |
Decode the bytes as UTF-8 |
|
Output is another Base64 string |
The data was encoded twice |
Decode it again |
Why Decoded Text Sometimes Looks Wrong
Base64 stores bytes, not letters. When you decode it back to text, those bytes have to be interpreted using a character encoding. If the text was encoded as UTF-8 but decoded as another encoding (such as Latin-1 or Windows-1252), accented and non-English characters turn into strings like é or ’.
The fix is almost always the same: decode the Base64 to raw bytes, then read those bytes as UTF-8. Modern tools, including the EasifyMe decoder, default to UTF-8. In older code, check which encoding your library uses by default.
If the decoded output looks like random symbols even with UTF-8, the data probably is not text at all. It may be an image, a PDF or a compressed file, so save it as a file instead.
Decoding Base64 in Emails
Email attachments and some message bodies are Base64-encoded behind the scenes. In an email's raw source, you will see a header such as:
Content-Transfer-Encoding: base64
followed by lines of Base64, each up to 76 characters long. Most decoders ignore the line breaks, so you can paste the whole block. This is useful when an attachment will not open in your email client, or when you are investigating a suspicious message. In that case, decode it in a browser-based tool and do not open the resulting file unless you trust the sender.
Decoding Base64 Safely in Production Code
When your application decodes Base64 from users or third-party systems:
- Validate strictly. In Python, base64.b64decode(data, validate=True) rejects strings containing invalid characters instead of silently skipping them.
- Limit the input size. A huge Base64 string can use a lot of memory once decoded.
- Check the decoded content type. If you expect a PNG, confirm the decoded bytes actually start with the PNG signature before saving or processing them.
- Handle errors gracefully. Catch decode exceptions and return a clear message rather than crashing.
Is It Safe to Decode Base64?
Decoding itself is harmless: it just reverses the encoding. But be careful with what comes out. Base64 is sometimes used to hide malicious scripts or files inside emails and web pages, so do not run or open decoded content from sources you do not trust. And never assume Base64 protects secrets. If you find passwords or API keys stored in Base64, treat them as exposed.
Related Tools and Reading
To go the other way, use the Base64 Encoder. If the decoded JSON will not parse, check it with the JSON Validator. For the theory behind the format, read what Base64 encoding is and how it works. All our utilities live in the developer tools hub.
Frequently Asked Questions
How do I decode Base64 to text?
Paste the string into a Base64 decoder and read the result. In code, use atob() in the browser, Buffer.from(str, "base64") in Node.js, or base64.b64decode() in Python.
How can I tell if a string is Base64?
Look for a string made only of letters, digits, + and / (or - and _), a length divisible by 4, and one or two = signs at the end. Strings starting with eyJ are usually encoded JSON.
Why do I get an "Incorrect padding" error?
The string is missing its = padding, which often happens with URL-safe Base64. Add = characters until the length is a multiple of 4, then decode again.
Can Base64 be decoded without a key?
Yes. Base64 is a public encoding, not encryption, so anyone can decode it. It offers no security.
Does decoding a JWT verify it?
No. Decoding only shows the header and payload. A JWT is trustworthy only after your server verifies its signature with the correct key.
Why does my decoded Base64 start with "PK"?
"PK" is the signature of a ZIP file. Word, Excel and PowerPoint files (.docx, .xlsx, .pptx) are also ZIP files, so save the decoded output with the right extension and open it.