How to use
- Paste the string you want to check into the input field.
- Read the verdict: valid or invalid, the detected variant (standard or URL-safe) and the decoded size.
- If problems are listed, use the reported positions to find invalid characters, whitespace or misplaced padding.
- Look at the detected content type to see whether the data is text or a file such as PNG, PDF or ZIP.
What makes Base64 valid
- Alphabet. Only
A-Z,a-z,0-9and two more characters are allowed:+and/in standard Base64,-and_in Base64URL. A string that mixes both pairs has usually been damaged or pieced together from two sources. - Padding. The
=sign may appear only at the end, at most twice. Padding in the middle usually means two encoded values were concatenated. - Length. With padding, the length is a multiple of 4. Without padding, any length works except 4n + 1: one leftover character holds only 6 bits, not enough for a byte.
Strict decoders add one more rule: the unused low bits of the last character must be zero. Many decoders ignore those bits, but some, such as Go's base64.StdEncoding.Strict(), reject the string.
Common errors and how to fix them
| Problem | Typical cause | Fix |
|---|---|---|
| Invalid character | Quotes, backslashes or %2B and %3D escapes copied along with the value | Remove the extra characters or URL-decode first |
| Spaces in the middle | + turned into spaces when the value passed through a URL or form | Put the + back, or use Base64URL for URLs |
| Length of 4n + 1 | Value truncated by a column limit, log line or partial copy | Copy the complete value again |
| Padding in the middle | Two Base64 strings joined together | Split and decode each part separately |
| Line breaks | MIME or PEM wrapping | Usually harmless; remove them where one line is required |
Valid does not mean meaningful
Base64 has no header and no checksum, so validity only says that a string can be decoded. Many ordinary words pass: any four letters form a valid group. That is why the validator also decodes the data and reports its size and content type. Readable text or a known file signature such as PNG, PDF or ZIP is good evidence that the string really is Base64; a handful of random bytes is not. To test other encodings as well, try the encoding detector.
Validating Base64 in code
// JavaScript: padded standard Base64 (also matches an empty string)
/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$/
# Python: raise an error instead of skipping invalid characters
import base64, binascii
try:
base64.b64decode(s, validate=True)
except binascii.Error:
print('invalid')
Frequently asked questions
Why is an ordinary word reported as valid Base64?
test, for example, decodes to three bytes. Check the detected content type: if the result is neither readable text nor a known file type, the input was probably never Base64.Is Base64 with spaces or line breaks valid?
MIME and PEM wrap Base64 into lines, and most decoders skip whitespace. JSON fields, HTTP headers, JWTs and data URIs expect one unbroken string, though. The validator lists whitespace separately so you can decide whether it matters where the string will be used.
Is Base64 without = padding valid?
= signs until the length is a multiple of 4 if a system rejects the string. Unpadded strings of 4n + 1 characters are never valid.How can I check if a string is Base64 in JavaScript?
atob() inside try/catch. Note that atob() throws an InvalidCharacterError for bad input but silently accepts whitespace and missing padding, and it does not accept the URL-safe characters.