How to Use the ValidBase64 Rule in Laravel Validation

The ValidBase64 rule from the milwad-dev/laravel-validate package validates that a string is properly Base64-encoded by performing a strict round-trip decode and encode operation.

The milwad-dev/laravel-validate package provides a collection of advanced validation rules for Laravel applications, including the ValidBase64 rule for verifying Base64-encoded data. This rule is essential when handling image uploads, API tokens, or encrypted payloads sent as Base64 strings. In this guide, you'll learn how to implement the ValidBase64 rule in Laravel validation using both direct instantiation and container-based approaches.

How the ValidBase64 Rule Works

According to the source code in src/Rules/ValidBase64.php, the rule implements Illuminate\Contracts\Validation\Rule and validates input using a strict round-trip check:

public function passes($attribute, $value): bool
{
    return base64_encode(base64_decode($value, true)) === $value;
}

The logic uses base64_decode($value, true) with strict mode enabled (second parameter set to true), which returns false for malformed strings rather than attempting to guess corrections. The method then re-encodes the decoded bytes and compares the result to the original value. If the round-trip produces an exact match, the string is valid Base64.

When validation fails, the message() method returns the translation key validate.base64, which resolves to "The :attribute is not valid." via the language files located in lang/en/validate.php.

Implementing the ValidBase64 Rule

There are two primary methods for using the ValidBase64 rule in Laravel validation, depending on your configuration preferences.

The most reliable approach instantiates the rule class directly in your validation logic. This method works immediately without additional configuration.

use Milwad\LaravelValidate\Rules\ValidBase64;
use Illuminate\Support\Facades\Validator;

$data = [
    'image_data' => 'iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAADUlEQVR42mP8z8BQDwAEhQGAhKmMIQAAAABJRU5ErkJggg=='
];

$validator = Validator::make($data, [
    'image_data' => ['required', new ValidBase64],
]);

if ($validator->fails()) {
    return $validator->errors()->first('image_data');
}

Method 2: Container-Registered Short Name

Alternatively, you can use the string alias ValidBase64 if you enable container registration. First, publish the configuration file:

php artisan vendor:publish --tag=laravel-validate-config

Then set using_container to true in config/laravel-validate.php:

'using_container' => true,

The LaravelValidateServiceProvider (located in src/LaravelValidateServiceProvider.php) automatically registers all rules from the src/Rules directory when this flag is enabled. Now you can use the short syntax:

use Illuminate\Support\Facades\Validator;

$validator = Validator::make($request->all(), [
    'token' => 'required|ValidBase64',
]);

Customizing Validation Messages

You can override the default error message from lang/en/validate.php by providing a custom message in your validator:

$validator = Validator::make($input, [
    'payload' => ['required', new ValidBase64],
], [
    'payload.base64' => 'The provided payload must be valid Base64 data.',
]);

Alternatively, publish the package language files using php artisan vendor:publish --tag=laravel-validate-lang and modify the base64 entry in the resulting translation files.

Summary

  • The ValidBase64 rule validates Base64 strings via strict round-trip encoding checks in src/Rules/ValidBase64.php.
  • Use direct instantiation with new ValidBase64 for immediate implementation without configuration.
  • Enable using_container in the config to use the short string syntax ValidBase64 in validation rules.
  • Customize messages by overriding the validate.base64 translation key or passing custom messages directly to the validator.

Frequently Asked Questions

What is the difference between using new ValidBase64 and the string ValidBase64?

Using new ValidBase64 instantiates the rule class directly and works regardless of configuration. The string alias ValidBase64 requires the using_container config option to be set to true, which allows the LaravelValidateServiceProvider to register the rule automatically in Laravel's validation container.

How does the ValidBase64 rule detect invalid Base64 strings?

The rule uses PHP's base64_decode($value, true) with strict mode enabled. If decoding fails or the re-encoded result does not match the original input exactly, the validation fails. This prevents acceptance of malformed strings or strings with invalid characters.

Can I use ValidBase64 to validate Base64 images specifically?

While ValidBase64 validates that a string is properly Base64-encoded, it does not verify content type. For image-specific validation, combine ValidBase64 with additional rules that check the decoded content's MIME type or file headers, or use the package's ValidBase64Image rule if available.

Where are the default error messages stored?

Default messages are stored in the package's lang/en/validate.php file under the base64 key. You can publish these files using php artisan vendor:publish --tag=laravel-validate-lang and modify them, or override specific messages directly in your validator's third argument array.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →