๐Ÿ”— Base64URL Encoder/Decoder

JWT header/payload segments are encoded in this format.

Base64URL textSGVsbG8sIFdvcmxkPw

Convert text to and from Base64URL (RFC 4648 Section 5), the URL-safe variant of Base64 used in JWTs and URL parameters. Unlike standard Base64, it uses "-" and "_" instead of "+" and "/", and omits "=" padding, so it can be used directly in URLs and filenames.

How to use

  1. Choose encode or decode mode.
  2. Enter the text you want to convert.
  3. The result is shown automatically.

How the calculation works

Base64URL, defined in section 5 of RFC 4648, is a variant of Base64 that is safe to use in URLs and file names. It is used in JWTs (JSON Web Tokens), OAuth PKCE, WebAuthn and elsewhere. It differs from standard Base64 in three ways: โ€ข "+" becomes "-" (hyphen) โ€ข "/" becomes "_" (underscore) โ€ข trailing "=" padding is omitted "+", "/" and "=" have special meanings in URLs and would otherwise need escaping; Base64URL avoids that. This tool encodes the text as UTF-8 bytes first, and when decoding it restores any missing padding before converting back.

Worked example

Encode Input: Hello, World? Standard Base64: SGVsbG8sIFdvcmxkPw== Base64URL: SGVsbG8sIFdvcmxkPw (no padding) An example where standard Base64 contains "/" and "+" Bytes C3 BF C3 BE 3E 3F โ†’ w7/Dvj4/ โ†’ Base64URL: w7_Dvj4_ Decode Input: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 Output: {"alg":"HS256","typ":"JWT"} (a JWT header)

Things to be aware of

  • A JWT has three Base64URL parts: header.payload.signature. Split at the dots and decode each part separately.
  • Base64URL is not encryption. Anyone can read a JWT payload, so never put secrets in it.
  • If the decoded bytes are not valid UTF-8 (binary data such as images), they cannot be shown as text.

FAQ

How is Base64URL different from standard Base64?

It replaces "+" and "/" with "-" and "_" respectively, and omits the trailing "=" padding, so it can be used in URLs and filenames without escaping.

Where is it used in JWTs?

A JWT's header, payload, and signature are each Base64URL-encoded segments joined by periods.

Can it handle multi-byte characters?

Yes โ€” input text is encoded as UTF-8 bytes before Base64URL encoding, so any text, including non-ASCII characters, is supported.