Dev Toolbox · Windows 10 and 11
Base64 decode and encode text
Paste a Base64 string and read the text inside it, or turn text into Base64 for a header, a config file or a data field. The URL-safe alphabet is one switch away, and decoding shrugs off line breaks and missing padding. It runs in Octoolo on your PC, not on a website.
How to decode Base64
- 1
Open Base64
In the Dev Toolbox, choose Base64 encode & decode under Data.
- 2
Choose a direction
Set Direction to Decode to read Base64, or to Encode to make it.
- 3
Paste the text
Paste into Input. The decoded text, or the Base64, appears in Result as you type. Spaces and line breaks in Base64 input are skipped.
- 4
Copy the result
Press Copy. When encoding for a URL, a file name or a token, switch on URL-safe alphabet first.
How Base64 works, in one minute
Base64 writes any bytes using only 64 safe characters: A to Z, a to z, 0 to 9, + and /. It takes the input three bytes at a time. Those 24 bits are cut into four groups of 6 bits, and each group picks one of the 64 characters. Three bytes in, four characters out.
So Base64 is always about a third bigger than what it encodes: 300 bytes become 400 characters. When the input does not divide by three, the end is padded with = signs. "Hi!" encodes to SGkh, "Hi" to SGk= and "H" to SA==.
Text has to become bytes first, and Octoolo uses UTF-8, the encoding the web runs on. An English letter is one byte, é is two (w6k= in Base64) and most emoji are four, so two texts of the same length can give Base64 of different lengths.
One thing Base64 is not: encryption. There is no key. Anyone can decode it, which is exactly why a decoder is handy, and why a secret "hidden" in Base64 is not hidden at all.
Standard and URL-safe Base64
Two of the standard alphabet's characters cause trouble outside email. In a URL query, + is read as a space, and / separates folders in paths and file names. The URL-safe variant, called base64url, swaps them: - instead of +, and _ instead of /. It usually leaves off the = padding as well, because = has a job in query strings too.
| Where it is used | Alphabet |
|---|---|
| Email attachments, data: URLs, HTTP Basic auth, PEM certificate files | Standard |
| JWTs, URL parameters, file names | URL-safe |
When encoding, URL-safe alphabet makes the swap and drops the padding. When decoding there is nothing to choose: Octoolo reads both alphabets, skips spaces and line breaks (such as the 76-character lines of email), and adds back any padding that was cut off.
Where you meet Base64, and what decoding shows
- Authorization headers. HTTP Basic auth sends the user name and password as the Base64 of user:password. dXNlcjpwYXNz decodes to user:pass, which is why Basic auth is only safe over HTTPS.
- Kubernetes Secrets. Secret values are stored Base64-encoded, not encrypted. Decoding one shows the real value.
- JWTs. Each part of a token is base64url. The JWT decoder splits the token and decodes all of it for you, dates included.
- Email source. A message part sent with Content-Transfer-Encoding: base64 can be pasted in, as long as its text is UTF-8.
- Data URLs in HTML and CSS, such as data:image/svg+xml;base64,PHN2Zy... Delete everything up to and including the comma, and an SVG decodes back to its markup.
Decoding works on your own machine, which is what you want when the string is a credential pulled from a header, a cluster or a log.
Text only: what to use for files
This tool decodes to text. If the Base64 holds a picture, a PDF, a ZIP or a certificate's binary DER data, the bytes are not valid UTF-8 text and you see "This is not Base64 text, or it does not decode to text." The same message appears when the input contains characters from neither alphabet, such as a stray quote or a data: prefix.
For files, Windows has two built-in ways:
- certutil in Command Prompt: certutil -encode photo.jpg photo.txt turns a file into Base64, and certutil -decode photo.txt photo.jpg turns it back. The encoded file gets BEGIN and END lines added around the Base64.
- PowerShell: [Convert]::ToBase64String([IO.File]::ReadAllBytes("C:\Temp\photo.jpg")) prints a file's Base64, and [IO.File]::WriteAllBytes with [Convert]::FromBase64String writes decoded bytes back to a file.
To check that a downloaded file is the one it claims to be, compare hashes rather than Base64: see the SHA-256 hash generator.
Questions, answered
Is Base64 a form of encryption?
No. It is an encoding with no key or password, and anyone can reverse it in a second. Use it to carry data through text-only channels, never to hide it.
How much bigger does Base64 make data?
Four characters for every three bytes, so a third more, plus up to two = signs at the end. Email adds a line break every 76 characters on top of that.
Does it handle accents, emoji and other alphabets?
Yes. Text is encoded as UTF-8, so é, ß, 日本語 and emoji go in and come back out exactly as they were.
Why do I get an error when decoding?
Either the input contains something that is not Base64, such as quotes or a data:...;base64, prefix, or the decoded bytes are a file rather than text. Paste only the Base64 itself, and use certutil or PowerShell for files.
Is it safe to decode a secret here?
Yes. Nothing you paste is sent anywhere or saved, and the text is gone when you switch tools. Remember that the decoded value is now on your screen, and in your clipboard if you copy it.
Base64 decode, and 16 more apps.
Download for Windows7 days free, then from $3.99 a month for all 17 apps. Windows 10 and 11.