Developer

Base64URL Encoder & Decoder

Encode and decode Base64URL, the URL safe variant used by JWT, WebAuthn, OAuth PKCE and JOSE. Handles missing padding and shows the difference from standard Base64 byte by byte.

Last reviewed by the Radiatus Cloud team

Need this built for your product?

We design, build & host secure software & APIs.

Talk to an engineer

Two alphabets, one name

Standard Base64 uses plus and slash as its final two characters and pads with equals signs. All three are problematic in a URL: plus means a space in a query string, slash is a path separator, and the equals sign has to be percent encoded. Base64URL swaps plus for hyphen and slash for underscore and drops the padding entirely. It is defined in RFC 4648 section 5 and is the encoding used by JWT, JWS, JWE, WebAuthn credential IDs, OAuth PKCE code challenges and most modern token formats.

The padding question

Base64URL omits trailing equals signs, which is why a JWT segment often has a length that is not a multiple of four. Many decoders reject that input outright. The fix is to add back one or two equals signs so the length becomes a multiple of four, which this tool does automatically. Going the other way, leaving padding on a value that will travel in a URL is the mistake that produces a token which works locally and breaks behind a proxy.

Encoding is not encryption

Base64URL is reversible with no key, so a JWT payload is readable by anyone holding the token. That is by design: the signature protects integrity, not confidentiality. Decoding a token you were given is a legitimate debugging step, but treat everything you find in it as public, and never put a secret in a claim.

Related tools

  • JSON Formatter — Format and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.
  • JSON Validator — Validate JSON syntax with precise line and column errors, and check documents against a JSON Schema. Runs locally in your browser, nothing uploaded.
  • Regex Tester — Test regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.
  • HTML Minifier — Minify HTML by removing comments and redundant whitespace, without breaking inline elements or pre blocks. Runs entirely in your browser.

Frequently Asked Questions

How is this different from ordinary Base64?

Two characters and the padding. Base64URL uses hyphen instead of plus and underscore instead of slash, and omits the trailing equals signs. The underlying bytes are identical, which is why converting between the two is a character substitution rather than a re-encode.

Why does my JWT segment fail to decode elsewhere?

Almost always missing padding. A segment whose length is not a multiple of four needs one or two equals signs appended before a strict decoder will accept it. This tool restores them for you.

Can I decode a whole JWT here?

Yes. Paste the full token and the decoder splits it on the dots and decodes the header and payload segments separately. The signature is binary, so it is shown as hex rather than mangled text.

Does it handle non ASCII text?

Yes. Text is encoded as UTF-8 before Base64URL, which is what every token implementation does, so accented characters and emoji round trip correctly rather than becoming question marks.

Is any of this sent to a server?

No. Encoding and decoding happen in your browser. That matters here more than for most tools, because the values people paste into a Base64URL decoder are usually live session tokens.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste text or Base64URL and pick a direction. Padding is added or removed automatically.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.