Base64 Decoder and Encoder

Paste a Base64 string to see what it contains: readable text, a formatted JSON or YAML document, or a hex dump with the file type identified. Switch direction to encode text instead.

Input

Settings

History

Load from URL

Where Base64 turns up

Base64 turns arbitrary bytes into 64 safe ASCII characters so they survive systems built for text. You meet it in Kubernetes Secret manifests, HTTP Basic auth headers, email attachments (MIME), data: URLs in CSS and HTML, webhook signatures, SAML responses and the three segments of every JWT. Each group of 3 bytes becomes 4 characters, so the encoded form is about a third larger than the original. Base64URL is the variant for URLs and file names: it swaps + for - and / for _, and usually drops the = padding.

It is an encoding, not encryption. A Kubernetes secret value or a Basic auth header can be read by anyone who can see the Base64, which is why this page exists and also why such values should be treated as plain-text credentials.

What the decoder handles for you

Paste the value and the result appears as you type, using a native decoder plus format auto-detection. The input is forgiving in the ways real copies are messy:

  • Either alphabet is accepted, standard or URL-safe, and the info panel tells you which one it saw.
  • Missing = padding is added automatically, which is the normal state for Base64URL.
  • Line breaks inside the value are ignored, so 76-column MIME blocks and wrapped PEM bodies decode as one string.
  • Surrounding quotes and a data:<type>;base64, prefix are stripped, and the declared media type is shown.

When the decoded bytes are valid UTF-8 text, the decoder looks inside. If they parse as JSON, XML, YAML or another supported format, the output is pretty-printed and the panel names the Detected inner format. Bytes that are not text become a hex dump with offsets and an ASCII column, and the file type is sniffed from its magic number: PNG, JPEG, GIF, PDF, ZIP and others. Images also get a rendered preview.

Options

  • Direction switches between Decode (the default) and Encode. Encoding takes the input as UTF-8 text, so accented and non-Latin characters become their multi-byte UTF-8 sequences before encoding, the same as btoa(unescape(encodeURIComponent(s))) used to do.
  • URL-safe alphabet (Base64URL) when encoding writes - and _ and omits padding, ready for a query parameter, a JWT segment or a file name. Decoding does not need this setting because both alphabets are read automatically.
  • Pretty-print decoded content is on by default. Turn it off to see the decoded text exactly as stored, for example to check whether a JSON payload was compact or contained a trailing newline.

The keyboard works as on every PasteKit tool: Ctrl/Cmd+Shift+C copies the result and Ctrl/Cmd+K opens the command palette to flip options without the mouse. Decoding happens on your machine, so a Secret pulled from a production cluster is not transmitted to anyone.

Things that trip people up

A length that leaves a single dangling character (5, 9, 13 characters and so on) cannot be valid in any alphabet; the value was truncated or has a stray character. An = in the middle usually means two Base64 values were pasted together. A string mixing + or / with - or _ still decodes, with a warning, because it may have been mangled by a URL encoder along the way. And remember that + in a query string is often turned into a space by URL decoding; if a decoded value looks corrupt, check whether it travelled through a URL without percent-encoding.

Examples

Kubernetes secret value holding JSON config

The decoded bytes are recognised as JSON and printed with indentation instead of as one long line.

Input
eyJhcGlWZXJzaW9uIjoidjEiLCJyZXRyaWVzIjozLCJlbmRwb2ludHMiOlsiaHR0cHM6Ly9hcGkuZXhhbXBsZS5jb20iLCJodHRwczovL2JhY2t1cC5leGFtcGxlLmNvbSJdfQ==
Output
{
  "apiVersion": "v1",
  "retries": 3,
  "endpoints": [
    "https://api.example.com",
    "https://backup.example.com"
  ]
}
Open this example in the tool

Encode a redirect payload for a URL

Base64URL output uses _ where standard Base64 would write /, so the value can go into a query string without escaping.

Input
{"order":"ord_8f2k1","next":"/checkout?step=2&ref=email"}
Output
eyJvcmRlciI6Im9yZF84ZjJrMSIsIm5leHQiOiIvY2hlY2tvdXQ_c3RlcD0yJnJlZj1lbWFpbCJ9
Open this example in the tool

PNG image in a data: URL

The data: prefix is removed, the bytes are shown as a hex dump, and the file type is identified as a PNG image.

Input
data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAADUlEQVR42mNk+M9QDwADhgGAWjR9awAAAABJRU5ErkJggg==
Output
00000000  89 50 4e 47 0d 0a 1a 0a  00 00 00 0d 49 48 44 52  |.PNG........IHDR|
00000010  00 00 00 01 00 00 00 01  08 06 00 00 00 1f 15 c4  |................|
00000020  89 00 00 00 0d 49 44 41  54 78 da 63 64 f8 cf 50  |.....IDATx.cd..P|
00000030  0f 00 03 86 01 80 5a 34  7d 6b 00 00 00 00 49 45  |......Z4}k....IE|
00000040  4e 44 ae 42 60 82                                 |ND.B`.|
Open this example in the tool

Base64 that wraps a YAML document

Inner format detection also works for YAML, XML and other formats the site supports, not only JSON.

Input
c2VydmljZTogY2hlY2tvdXQKcmVwbGljYXM6IDMK
Output
service: checkout
replicas: 3
Open this example in the tool

Common errors and how to fix them

ErrorCauseFix
Invalid Base64 character '$'
Explained
A character outside A–Z, a–z, 0–9, + / - _ and = is in the value, often from a placeholder, a stray quote or an HTML entity.Remove the character or copy the value again from its source. Spaces and line breaks are fine and need no cleanup.
Unexpected '=' padding: padding may only appear at the very end, at most twicePadding sits in the middle of the value, which nearly always means two separate Base64 strings were joined.Split the value at the = signs and decode each part on its own.
Impossible Base64 length: 5 characters leaves one character that cannot form a byteOne character is left over after the last full 4-character group, so the value is cut short or has an extra character.Copy the full value again. Check the end of the string, where truncation usually happens.
This data: URL is not Base64 encoded (it has no ";base64" marker)The data: URL stores percent-encoded text, such as an inline SVG, rather than Base64.Use the URL parser to decode percent-encoding, or remove the data: prefix if the rest is really Base64.

Frequently asked questions

What is the difference between Base64 and Base64URL?

They encode the same bytes with two different characters: Base64URL uses - and _ instead of + and /, and usually leaves out = padding. The decoder reads both automatically; the encoder writes Base64URL only when the URL-safe option is on.

How do I decode a Kubernetes secret?

Copy one value from the data section of the Secret and paste it here. Each key is encoded separately, so decode them one at a time.

Why does my decoded output show hex instead of text?

The bytes are not valid UTF-8, so they are binary data such as an image, a compressed file or encrypted content. The info panel shows the detected file type when the magic number is known.

Is Base64 a form of encryption?

No. Anyone can reverse it without a key. Treat Base64-encoded passwords and tokens exactly as you would the plain values.

Can I decode a JWT here?

You can decode one segment at a time, but the JWT decoder is easier: it splits the token, decodes header and payload together and explains the claims.

Related tools