---
title: "Handles requests to the `/base64/:encoded` endpoint."
url: "https://developer.rucho.org/apis/rucho/versions/5bdf1bcb-8db4-40f1-a293-72c7198e26c8/operations/base64_handler"
---

> Full API specification: https://developer.rucho.org/apis/rucho/versions/5bdf1bcb-8db4-40f1-a293-72c7198e26c8.md

# Handles requests to the `/base64/:encoded` endpoint.

`GET` `/base64/{encoded}`

Operation ID: `base64_handler`

Decodes the URL-path base64 string and returns a JSON payload with the decoded content, a UTF-8 validity flag, and the decoded byte length. # Security Input is capped at `MAX_BASE64_INPUT_BYTES` (4096 bytes) to prevent denial-of-service attacks from oversized decode operations. # Path Parameters - `encoded`: The base64-encoded string to decode. URL-safe alphabet is preferred; padding is optional. # Responses - `200 OK`: JSON object with `encoded`, `decoded`, `is_utf8`, `byte_length`, and `timing.duration_ms`. - `400 Bad Request`: Invalid base64 input or input exceeds the size limit.

## Path parameters

- `encoded` (string, required) - URL-safe base64-encoded string to decode (max 4096 bytes)

## Responses

- `200` - Returns decoded content with metadata
- `400` - Invalid base64 input or input exceeds size limit

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: rucho
  version: 1.6.0
servers:
  - url: https://rucho.org
    description: Production (EKS us-east-2, behind Kong)
paths:
  /base64/{encoded}:
    get:
      tags:
        - crate::routes::base64
      summary: Handles requests to the `/base64/:encoded` endpoint.
      description: >-
        Decodes the URL-path base64 string and returns a JSON payload with the

        decoded content, a UTF-8 validity flag, and the decoded byte length.


        # Security


        Input is capped at `MAX_BASE64_INPUT_BYTES` (4096 bytes) to prevent

        denial-of-service attacks from oversized decode operations.


        # Path Parameters


        - `encoded`: The base64-encoded string to decode. URL-safe alphabet is

        preferred; padding is optional.


        # Responses


        - `200 OK`: JSON object with `encoded`, `decoded`, `is_utf8`,
        `byte_length`,

        and `timing.duration_ms`.

        - `400 Bad Request`: Invalid base64 input or input exceeds the size
        limit.
      operationId: base64_handler
      parameters:
        - name: encoded
          in: path
          description: URL-safe base64-encoded string to decode (max 4096 bytes)
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Returns decoded content with metadata
          content:
            application/json:
              schema: {}
        "400":
          description: Invalid base64 input or input exceeds size limit
```
