How to Decode a Base64 String Online
Paste the Base64 string into a decoder and read the output — Base64 is a reversible text encoding, not encryption, so any decoder turns it back into the original text instantly. The = padding at the end is normal; leave it in place. ToolNest's free Base64 encoder/decoder decodes any Base64 string in your browser, so nothing you paste is uploaded.
Decode a Base64 string in 10 seconds
Decoding takes one step: paste the string into a decoder and read the result. Try it with aGVsbG8= — paste it into ToolNest's Base64 tool and it returns hello. That's the whole operation: Base64 decoding is deterministic, so every correct decoder on Earth returns the same text for the same input. Two things to know before you paste. First, the = characters sometimes trailing the string are padding, not damage — they keep the encoded length a multiple of four, and decoders expect them, so don't strip them. Second, whitespace and line breaks inside long encoded strings (common in email) are harmless — most decoders ignore them, but if yours complains, delete the line breaks first. If the output is gibberish instead of text, the string probably wasn't Base64 at all, or it encodes binary data like an image rather than readable text — both cases are covered in the troubleshooting section below.
What is Base64 encoding?
Base64 exists because much of the internet only reliably transports text. Email, URLs, JSON payloads, and HTML attributes were designed for readable characters — raw binary like images, files, or encryption keys gets corrupted crossing those channels. Base64 solves it by re-encoding any bytes as plain ASCII text: every 3 input bytes become 4 characters drawn from a 64-character alphabet — A-Z, a-z, 0-9, +, /. Because 4 characters carry 3 bytes, encoded output runs about 33% larger than the input — the price of text-safety. When the input length isn't a multiple of 3, = padding fills the gap (one or two characters). Example: 'hello' is 5 bytes, which encodes to aGVsbG8= — 8 characters with one pad. You'll meet Base64 in data: URLs (small images embedded directly in HTML/CSS as data:image/png;base64,...), email attachments (MIME encodes every attachment in Base64), API credentials (HTTP Basic Auth sends base64(username:password) in a header), and certificates (.pem files are Base64-encoded data between BEGIN/END markers). It's plumbing — invisible until you need to read it.
Is Base64 encryption? No — and the difference matters
Base64 looks secret — aGVsbG8= reveals nothing at a glance — but it provides zero secrecy. Encoding is a transport format: a public, reversible recipe with no key. Anyone who recognizes Base64 decodes it in one click, which is exactly what this article teaches. Encryption, by contrast, needs a secret key — without the key, the ciphertext stays unreadable. Confusing the two causes real incidents: developers 'hide' API keys or passwords with Base64 and commit them to public repos, where they're decoded in seconds. The rule is simple: if there's no key, it's not encryption. Base64 is for moving data safely through text channels, never for protecting it. Need actual protection? Encrypt with a real cipher for secrecy, or hash with SHA-256 for tamper-evidence. And when you spot a Base64 blob in the wild, decode it freely — that's what it's for.
How to decode Base64 in JavaScript
In the browser, decoding is one built-in call: atob('aGVsbG8=') returns 'hello' (atob = ASCII-to-binary; its twin btoa() encodes). One catch: atob mangles non-ASCII text like emoji or accented characters, because it returns a binary string rather than proper UTF-8. The robust pattern decodes to bytes first, then interprets them as UTF-8: new TextDecoder().decode(Uint8Array.from(atob(b64), c => c.charCodeAt(0))). In Node.js it's cleaner: Buffer.from(b64, 'base64').toString('utf-8') handles Unicode correctly out of the box. Going the other direction, btoa('hello') gives 'aGVsbG8=', with the same Unicode caveat in reverse (run text through TextEncoder first for non-ASCII). For one-off strings, skip the code entirely: paste into the browser tool and read the answer. Reserve the code for when decoding lives inside an app.
Base64 vs Base64url: the JWT connection
Standard Base64 has a URL problem: its alphabet includes + and /, which carry meaning inside URLs and get mangled by servers. Base64url fixes it with two swaps — - instead of +, _ instead of / — and drops the = padding. Same data, URL-safe alphabet. This is the encoding JWTs (JSON Web Tokens) use: a JWT is three Base64url segments joined by dots — header.payload.signature — and 'decoding a JWT' mostly means Base64url-decoding the middle segment to read the claims. To decode a Base64url string with a standard decoder, reverse the swaps first: replace - with +, _ with /, then add = padding until the length is a multiple of 4. Or skip the fiddling: our JWT guide walks through reading tokens claim by claim, and the Base64 tool handles both alphabets.
Where you'll meet Base64 in the wild
Once you recognize the alphabet — long runs of mixed-case letters, digits, + and /, often ending in = — you'll spot Base64 everywhere. Data URLs: data:image/png;base64,iVBORw0KGgo... embeds an image directly in HTML or CSS — great for tiny icons, wasteful for photos given the 33% overhead. Email: open a raw .eml file and attachments appear as giant Base64 blocks under a Content-Transfer-Encoding: base64 header. Basic Auth: the Authorization header carries base64(username:password) — decode it and the credentials stare back, which is why Basic Auth is only acceptable over HTTPS. Certificates and keys: .pem files wrap Base64 between '-----BEGIN ...-----' markers. APIs: JSON can't carry raw bytes, so binary fields like thumbnails or file uploads ride as Base64 strings. In every case the move is the same: identify the blob, paste it into a decoder, read the result.
When decoding fails: the usual suspects
Four failures cover nearly every 'it won't decode' complaint. 1. Broken padding: the string length must be a multiple of 4 — if characters got trimmed (common when copying from chat apps), re-add = until it divides evenly. 2. Wrong alphabet: a Base64url string (- and _) fed to a standard decoder errors out — apply the swaps from the previous section. 3. Hidden whitespace: newlines or spaces inside long strings pasted from email or terminals choke strict decoders — strip all whitespace first. 4. It's not text: successful decoding can still yield gibberish if the payload is binary — an image, a font, compressed data. That's not a failure; the bytes are correct, they're just not words. Save them to a file with the right extension instead of staring at them. And if the string isn't Base64 at all — hex, URL-encoded, or just random — no decoder will save it; our URL-encoding guide helps identify the percent-encoded lookalikes.
Encoding: the other direction
Decoding is half the tool. Encoding turns your text or file into Base64 for the journeys above — embedding a small logo in a stylesheet, stuffing binary into a JSON API call, or generating a Basic Auth header. The same free Base64 tool encodes as well as decodes: paste text, copy the Base64, done — all client-side, so sensitive strings never leave your browser. Keep the two rules from this guide: encoding is for transport, never for secrecy, and the 33% size overhead means Base64 suits small payloads, not your photo archive.
Do it in one click
Decode or encode any Base64 string instantly — free, private, no signup.
Open the Free Tool →