Paste a data URL or a raw Base64 string and see the image. Decoding happens here in the page — the string is never uploaded and never stored.
Up to 6 MB of decoded image, and no more than 8,388,672 characters of Base64.
Used only when the string is raw Base64. A
data: URL carries its own format, and that one wins.
Decoded image —
- Detected
- —
- MIME type
- —
- Dimensions
- —
- Image size
- —
- Base64 length
- —
The string is decoded in this browser and never uploaded. The image reaches your device only if you choose to download it.
Base64 turns up everywhere a binary file has to travel through something that only carries text: a JSON payload, a database column, an email body, a log line. Getting the picture back out is usually a job for a script — unless you only need to see what is in there, which is exactly what this page is for.
Paste the string, or the whole data URL, and the image appears with what it actually is: format, MIME type, dimensions and size. Raw Base64 needs a format chosen from the list, because a bare string of characters does not say what it is; a data URL carries its own type and overrides the selection.
How to use this tool
- Paste a data URL or a raw Base64 string into the box.
- If it is raw Base64, choose the format from the list — a data URL carries its own type and ignores that choice.
- Press Decode image to preview it, then download it or copy the rebuilt data URL.
The string is checked before it is trusted
Base64 is not proof that the payload is an image, so the decoded bytes are tested against the real signatures — the PNG magic number, the JPEG marker, the GIF and WEBP headers, the BMP marker — or, for SVG, for an actual `<svg>` root after any XML declaration or comment. Something that decodes to other bytes is reported as not an image rather than shown as a broken picture.
Malformed Base64 is refused with the reason. Padding in the wrong place, a character that is not part of the alphabet, and a length that cannot be a whole number of bytes are three different faults, and each one is named. URL-safe Base64 — the `-` and `_` variant — is recognised and converted rather than treated as broken.
When the label and the bytes disagree
A data URL can say one thing and contain another: `data:image/png;base64,` in front of JPEG bytes is a small copy-paste error with a confusing symptom, because some tools believe the label and some believe the bytes.
This page believes the bytes and says so. If the declared type does not match what is actually there, the result is flagged and the preview shows the real format. The rebuilt data URL is generated from the bytes as well, so the wrong prefix is corrected rather than repeated.
Why this stays in the browser
Base64 that needs decoding is often a credential, a signature, a screenshot of something private or a file from a system that is not public. Sending it to a server to be decoded would mean a copy of it exists somewhere it does not need to.
Everything here — the decoding, the signature check, the preview and the data URL — happens in the page. There is no request, so there is nothing to log, and the only thing that reaches your device is the file if you choose to download it.
Frequently asked questions
Why does it say my Base64 is not an image?
Because the bytes it decodes to do not match any of the image formats this page handles. A string can be perfectly valid Base64 and still hold a PDF, a ZIP archive or a fragment of text. The check reads the actual file signatures rather than trusting the label.
Do I need a data URL or can I paste raw Base64?
Both work. Raw Base64 needs the format chosen from the list, because a bare string of characters carries no type. A data URL states its own type, and that takes precedence over the selection.
The string is cut off — how can I tell?
Base64 encodes three bytes as four characters, so a valid string leaves a remainder of 0, 2 or 3 — never 1. A truncation usually shows up as an invalid length or a decoding failure, both of which are reported rather than guessed at.
Is the image uploaded anywhere?
No. The decoding and the preview happen in your browser, and the deflated string is not sent to this site or to anyone else.
Can it decode an SVG?
Yes. An SVG is shown as a static image through an `<img>` element, so anything scripted inside it does not run, and it is only written to your device if you choose Download.