Base64 Decode & Encode

Decode Base64 into exact bytes and UTF-8 text, or encode UTF-8 text as Standard Base64 or Base64URL.

Operation
Alphabet

ASCII spaces, tabs, and line breaks are ignored. Other whitespace is rejected.

Private by design: conversion stays in this browser. Base64 is encoding, not encryption, so do not treat encoded secrets as protected.

Decode Base64 without changing the bytes

Choose Standard Base64 or Base64URL before decoding. Standard Base64 uses + and /; Base64URL uses - and _. Letters and digits have the same byte meaning in both alphabets. The tool rejects characters from the other alphabet and rejects mixed alphabets rather than silently normalizing the input.

Spaces, tabs, line feeds, form feeds, and carriage returns from the ASCII whitespace set are ignored. Nonbreaking spaces and other Unicode whitespace remain errors. A syntax error reports the first original-input UTF-16 offset and offending character, even when earlier ASCII whitespace was ignored.

Padding and canonical pad bits

Base64 works in groups of four encoded characters. One or two terminal = characters may complete the final group, and this decoder also accepts omitted terminal padding when the remaining length is valid. It rejects interior padding, excess or mismatched padding, and data lengths whose remainder is one.

RFC 4648 requires unused pad bits to be zero for a canonical representation. ToolNeko checks those bits and rejects alternate spellings that would otherwise decode to the same bytes. Standard Base64 encoding always includes canonical padding. Base64URL encoding omits it by default and offers an explicit option to include it.

UTF-8 text and hexadecimal bytes

Decoding produces a byte array first. The UTF-8 view uses fatal decoding: valid text is shown exactly, including a leading U+FEFF byte-order mark, while invalid UTF-8 is reported at its first byte offset. The bytes are still available as lowercase, two-digit hexadecimal separated by spaces. No replacement character is inserted and no partial result is shown after a Base64 syntax or size error.

Encoding converts Unicode text to UTF-8 bytes before applying Base64. An unpaired UTF-16 surrogate is rejected because silently replacing it would change the input. This is why direct browser btoa() calls on arbitrary Unicode text are not used.

Deterministic limits and error codes

ConditionResult
Character outside the chosen alphabetinvalid_character or wrong_alphabet
Standard and URL-safe characters mixedmixed_alphabet
Padding inside data or wrong padding countmisplaced_padding or invalid_padding
Impossible data lengthinvalid_length
Discarded pad bits are not zerononcanonical_pad_bits
Decoded bytes are not valid UTF-8Bytes remain available with invalid_utf8 details

UTF-8 text input is limited to 1,048,576 bytes. Raw Base64 input, including ignored whitespace, is limited to 1,500,000 UTF-16 code units, and decoded output is limited to 1,048,576 bytes. The decoder calculates the output size before allocating the result.

Browser-only privacy and focused scope

Conversion uses memory in this page after the static files load. The tool makes no fetch, XHR, WebSocket, beacon, worker upload, or remote URL request; reads no clipboard automatically; and writes only the visible result when you choose Copy result. It does not use local storage, session storage, IndexedDB, cookies, query parameters, or URL fragments. Normal site measurement is limited to operation, alphabet, output view, a coarse size bucket, success, and an error code—never input, output, exact length, characters, offsets, or decoded bytes.

This page does not parse JWTs, verify signatures, recursively decode nested strings, upload files or images, create downloads, extract data URIs, process batches, convert legacy character sets, fetch URLs, or save history. Those tasks have different correctness and security boundaries.

Frequently asked questions

Is Base64 encryption?

No. Base64 is a reversible way to represent bytes as text. Anyone who has the encoded value can decode it, so it does not protect passwords, tokens, or other secrets.

What is the difference between Base64 and Base64URL?

Standard Base64 uses + and /. Base64URL replaces those characters with - and _ so the result fits more safely in URLs and filenames. This tool makes you choose the alphabet and never silently converts one into the other.

Can I decode Base64 without the final equals signs?

Yes. Canonical terminal padding may be present or omitted when the remaining length is valid. The tool still rejects impossible lengths, incorrect padding, and nonzero discarded pad bits.

Why do I see hexadecimal bytes instead of text?

A Base64 value can represent any bytes. When those bytes are not valid UTF-8, the tool preserves them and shows lowercase hexadecimal instead of replacing data with the Unicode replacement character.

Does ToolNeko upload or save my Base64 input?

No. The converter runs in your browser after the page loads. It does not save input or output in browser storage, cookies, the URL, a file, or a ToolNeko application request.

Sources and method

Related tools