Base64URL Encoder / Decoder (URL-Safe Base64)

URL-safe Base64 encode and decode online — the variant used in JWTs and URL tokens (+ becomes -, / becomes _, no padding). UTF-8 safe.

—

How it works

Standard Base64 uses + and / — both break URLs. Base64URL (RFC 4648 section 5) swaps them for - and _ and drops the = padding, making the result safe inside URLs, filenames and JWT segments. Decoding restores the swaps and re-pads to a multiple of 4 before standard Base64 decoding.

Examples

InputOutput
hello worldaGVsbG8gd29ybGQ
eyJhbGciOiJIUzI1NiJ9decodes to: {"alg":"HS256"}
bytes with +/ in standard Base64become -_ in Base64URL

Frequently Asked Questions

What is the difference between Base64 and Base64URL?

Only three characters: standard Base64 uses +, / and = padding; Base64URL uses -, _ and no padding. The underlying 6-bit encoding is identical, so converting between them is a string substitution, not a re-encode.

Why do JWTs use Base64URL?

A JWT is placed in URLs and HTTP headers where +, / and = have special meaning or get mangled by proxies. Base64URL avoids all escaping issues, which is why the header, payload and signature of every JWT use it.

Is Base64URL a form of encryption?

No — it is an encoding, not encryption. Anyone can decode it instantly (this page proves it). Never put secrets in a JWT payload or a Base64 token expecting them to stay hidden.

Why does my input fail to decode?

The decode direction expects valid Base64URL: only A–Z, a–z, 0–9, - and _. If your string contains +, / or = it is standard Base64 — decode it with the Base64 decode tool instead.

Related Tools

JSON Formatter & ValidatorRandom Password Generator (Bulk)Unix Timestamp Converter (Epoch)CSV to JSON ConverterJSON to YAML ConverterMarkdown to HTML ConverterText to Unicode Converter (Code Points)MD5 Hash GeneratorHTML Encoder / Decoder (Entities)Base64 to PDF ConverterHTML to Markdown Converter