Checking a token
Confirm an encoded token is valid Base64 before debugging why a decode step fails downstream.
Converts base64 to result in this tab, with nothing sent anywhere.
Find related browser-local tools for nearby tasks without starting another search.
Browse all developer and data toolsA Base64 validator confirms whether a string is genuinely valid Base64 before you try to decode it. Base64 turns binary - an image, a key, a token - into text made only of letters, digits and a few symbols, padded to a length that is a multiple of four. A string that contains a stray character, the wrong padding, or a length that does not divide evenly is not valid Base64 and will fail to decode, often silently. This tool checks the alphabet, the padding and the length in your browser and tells you whether the string is valid, and how many bytes it decodes to. Running locally means a token or an encoded secret is checked without being sent anywhere.
Confirm an encoded token is valid Base64 before debugging why a decode step fails downstream.
A string that will not decode turns out to be missing its '=' padding; the validator says so.
A valid Base64 string can decode to arbitrary bytes, including a damaged file. For example, SGVsbG8= represents Hello, but accepting that alphabet and padding does not verify a file signature or authenticate the sender. After validation, decode into the expected format and check its structure. Do not paste an access token merely to see whether its encoding is valid; use a harmless sample with the same structural problem.
A character outside A–Z, a–z, 0–9, + and /; a length that is not a multiple of four; or wrong '=' padding. The tool says which.
This validates standard Base64. URL-safe variants use '-' and '_', which are flagged as outside the standard alphabet.
Encode UTF-8 text to standard Base64 or decode Base64 back to Unicode text locally in your browser, with strict malformed and non-text error handling.
JSON Validator in your browser. Instant, accurate, and nothing is uploaded.
Decode a JSON Web Token and inspect claims and expiry in your browser. Your token is never transmitted.