Base64 Validator

Paste a string to find out whether it is valid Base64. The validator names the variant, points to invalid characters and padding problems, and tells you what the data decodes to.

Runs entirely in your browser. Nothing is uploaded.

How to use

  1. Paste the string you want to check into the input field.
  2. Read the verdict: valid or invalid, the detected variant (standard or URL-safe) and the decoded size.
  3. If problems are listed, use the reported positions to find invalid characters, whitespace or misplaced padding.
  4. Look at the detected content type to see whether the data is text or a file such as PNG, PDF or ZIP.

What makes Base64 valid

  • Alphabet. Only A-Z, a-z, 0-9 and two more characters are allowed: + and / in standard Base64, - and _ in Base64URL. A string that mixes both pairs has usually been damaged or pieced together from two sources.
  • Padding. The = sign may appear only at the end, at most twice. Padding in the middle usually means two encoded values were concatenated.
  • Length. With padding, the length is a multiple of 4. Without padding, any length works except 4n + 1: one leftover character holds only 6 bits, not enough for a byte.

Strict decoders add one more rule: the unused low bits of the last character must be zero. Many decoders ignore those bits, but some, such as Go's base64.StdEncoding.Strict(), reject the string.

Common errors and how to fix them

ProblemTypical causeFix
Invalid characterQuotes, backslashes or %2B and %3D escapes copied along with the valueRemove the extra characters or URL-decode first
Spaces in the middle+ turned into spaces when the value passed through a URL or formPut the + back, or use Base64URL for URLs
Length of 4n + 1Value truncated by a column limit, log line or partial copyCopy the complete value again
Padding in the middleTwo Base64 strings joined togetherSplit and decode each part separately
Line breaksMIME or PEM wrappingUsually harmless; remove them where one line is required

Valid does not mean meaningful

Base64 has no header and no checksum, so validity only says that a string can be decoded. Many ordinary words pass: any four letters form a valid group. That is why the validator also decodes the data and reports its size and content type. Readable text or a known file signature such as PNG, PDF or ZIP is good evidence that the string really is Base64; a handful of random bytes is not. To test other encodings as well, try the encoding detector.

Validating Base64 in code

// JavaScript: padded standard Base64 (also matches an empty string)
/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$/

# Python: raise an error instead of skipping invalid characters
import base64, binascii
try:
    base64.b64decode(s, validate=True)
except binascii.Error:
    print('invalid')

Frequently asked questions

Why is an ordinary word reported as valid Base64?
Because it is valid. Any run of alphabet characters with a suitable length decodes to some bytes; the word test, for example, decodes to three bytes. Check the detected content type: if the result is neither readable text nor a known file type, the input was probably never Base64.
Is Base64 with spaces or line breaks valid?

MIME and PEM wrap Base64 into lines, and most decoders skip whitespace. JSON fields, HTTP headers, JWTs and data URIs expect one unbroken string, though. The validator lists whitespace separately so you can decide whether it matters where the string will be used.

Is Base64 without = padding valid?
Often, yes. Base64URL normally leaves padding out, and RFC 4648 allows dropping it when the length is known from context. Some strict decoders still require it; add = signs until the length is a multiple of 4 if a system rejects the string. Unpadded strings of 4n + 1 characters are never valid.
How can I check if a string is Base64 in JavaScript?
For strict padded Base64, test it against a regular expression that allows groups of four alphabet characters followed by optional padding. A quicker check is to call atob() inside try/catch. Note that atob() throws an InvalidCharacterError for bad input but silently accepts whitespace and missing padding, and it does not accept the URL-safe characters.