URL-safe Base64 encode and decode online — the variant used in JWTs and URL tokens (+ becomes -, / becomes _, no padding). UTF-8 safe.
| Input | Output |
|---|---|
| hello world | aGVsbG8gd29ybGQ |
| eyJhbGciOiJIUzI1NiJ9 | decodes to: {"alg":"HS256"} |
| bytes with +/ in standard Base64 | become -_ in Base64URL |
Only three characters: standard Base64 uses +, / and = padding; Base64URL uses -, _ and no padding. The underlying 6-bit encoding is identical, so converting between them is a string substitution, not a re-encode.
A JWT is placed in URLs and HTTP headers where +, / and = have special meaning or get mangled by proxies. Base64URL avoids all escaping issues, which is why the header, payload and signature of every JWT use it.
No — it is an encoding, not encryption. Anyone can decode it instantly (this page proves it). Never put secrets in a JWT payload or a Base64 token expecting them to stay hidden.
The decode direction expects valid Base64URL: only A–Z, a–z, 0–9, - and _. If your string contains +, / or = it is standard Base64 — decode it with the Base64 decode tool instead.