Base64 Decoder: Decode Text Online
Decode a Base64 string to inspect its text content. Paste the encoded value and check whether the decoded bytes represent the text you expect.
Why Use Our Base64 Decoder?
Instant Decoding
Convert Base64 back to text in real-time as you paste, with instant results.
Unicode Support
Properly decodes UTF-8 characters, emojis, and international text without corruption.
Privacy First
Your Base64 strings are decoded entirely in your browser. No data ever reaches our servers.
Base64 Decoder: Convert Base64 to Plain Text Online
Decode a Base64 string to inspect its text content. Paste the encoded value and check whether the decoded bytes represent the text you expect. Base64 decoding does not establish where data came from or whether it is safe. Binary files may not decode into readable text. For an encoded image, use the dedicated Base64 to Image tool instead of interpreting the bytes as a message.
How to use the Base64 decoder
- Paste your Base64 into the Base64 Input box, or click Paste to pull from your clipboard.
- The Plain Text Result updates instantly — the tool trims surrounding whitespace before decoding.
- Press Copy Result to send the decoded text to your clipboard, or Clear to start over.
- If you see "Invalid Base64 string", the input has a character outside the standard alphabet — see the URL-safe note below.
- Need the reverse? Use the Base64 Encoder to turn text back into Base64.
What is Base64 and how does decoding work?
Base64 packs binary data into 64 printable ASCII characters so it survives text-only channels like email, JSON, and URLs. Encoding splits bytes into 6-bit groups (26 = 64 symbols) and pads the end with = to a multiple of 4. Decoding reverses that: it maps each character back to 6 bits and reassembles the original 8-bit bytes. The mapping is fixed by RFC 4648, Table 1.
Browser atob() returns a raw binary string, one byte per character, which mangles any multi-byte UTF-8. This tool fixes that with decodeURIComponent(escape(atob(str))): escape percent-encodes each byte and decodeURIComponent stitches the bytes back into proper Unicode. That is why Y2Fmw6k= decodes to café here instead of the broken café a naive atob() produces. Per the spec:
"The encoding process represents 24-bit groups of input bits as output strings of 4 encoded characters."— RFC 4648, §4 (Base 64 Encoding)
Important: Base64 is encoding, not encryption. It scrambles nothing — anyone can reverse it in one step. For the difference between encoding, hashing, and encryption, read hashing vs encryption vs encoding.
Worked examples: Base64 → text
Standard string
SGVsbG8= → Hello
Emoji / UTF-8
8J+agA== → 🚀 · Y2Fmw6k= → café
Missing padding (still decodes)
SGVsbG8 → Hello — the trailing = is optional in the browser
Edge case · URL-safe input fails
PDw_Pz4- returns "Invalid Base64 string" because it uses the URL-safe alphabet (- and _). Convert it first — replace - with + and _ with / — so PDw/Pz4+ decodes to <<??>>. JWT segments are URL-safe, so decoding a token segment with -/_needs that swap; use the JWT Decoder for whole tokens.
Base64 reference: alphabet, padding & variants
These are the exact rules this decoder follows. The standard and URL-safe alphabets differ in only two characters — the 62nd and 63rd symbols — which is why a URL-safe string fails until you swap them.
| Property | Standard (RFC 4648 Table 1) | URL-safe (Table 2) |
|---|---|---|
| Char 62 / 63 | + / | - _ |
| Padding char | = | = (often omitted) |
| Output length | 4 chars per 3 bytes | 4 chars per 3 bytes |
| Decoded here? | Yes — directly | No — swap - + and _ / first |
| Whitespace | Ignored (spaces, tabs, newlines) | Ignored after swap |
The URL-safe trap most decoders gloss over
This tool decodes the standard RFC 4648 alphabet only. It does not auto-translate URL-safe characters: feed it - or _ and atob() throws, surfacing as Error: Invalid Base64 string. That is deliberate honesty — silently rewriting -→+ could corrupt a string that legitimately ends in a dash. If your source is a JWT segment, a query parameter, or a filename token, swap -→+ and _→/ before pasting.
The good news: padding and whitespace are forgiving. The browser atob() follows the WHATWG forgiving-base64 rules, so SGVsbG8 (no =) and a string broken across newlines both decode fine. Only the alphabet itself is strict. So if decoding fails, check for -, _, or a stray symbol like ! or % first — not the padding.
Related encoder, crypto & data tools
Turn text back into Base64
Base64 to ImageRender a Base64 data URI as a picture
Image to Base64Encode an image into a data URI
JWT DecoderDecode Base64url-encoded JWT segments
URL EncoderPercent-encode text for safe URLs
URL ParserBreak a URL into its components
HMAC GeneratorSign data with a keyed hash
Hash GeneratorMD5, SHA-1, SHA-256 digests
JSON FormatterValidate decoded JSON payloads
Guide: Base64 EncodingHow Base64 works, end to end
Guide: JWT StructureWhy JWTs use Base64url segments
All ToolsBrowse the full Toolk toolbox
Last updated: September 15, 2026 · Runs 100% in your browser — no uploads, tool input is not sent to Toolk.
Frequently asked questions
Why does my string fail with "Invalid Base64 string"?
After whitespace is stripped, any character outside the standard RFC 4648 alphabet (A–Z, a–z, 0–9, +, /, =) makes atob() throw. The usual culprits are URL-safe dashes and underscores from JWT segments — swap - to + and _ to / before pasting.
Does missing padding (=) break the decoder?
No. The browser's forgiving-base64 rules let this decoder accept SGVsbG8 without its trailing equals signs, as well as input broken across newlines. Only the alphabet itself is strict — padding and line wrapping are tolerated.
Can it decode emojis, Arabic, and other Unicode text?
Yes. Raw atob() returns one byte per character and mangles multi-byte UTF-8, so the decoder rebuilds proper Unicode with decodeURIComponent(escape(atob(str))). That is why Y2Fmw6k= correctly yields café instead of mojibake.
Is my Base64 input uploaded or stored anywhere?
No. Decoding is processed locally in your browser via atob(), and Toolk's page analytics do not receive the strings you paste. That matters when you are inspecting auth headers — tool input is not sent to Toolk.
Which tool should I use for whole JWT tokens?
Use the JWT Decoder at /tools/jwt-decoder. It understands the three-segment token format and decodes each Base64url part with the alphabet swap applied automatically, rather than making you convert - and _ by hand.