Base64URL Encoder
Encode, decode, normalize and verify Base64URL as bytes—not just text—with strict RFC 4648 validation, UTF-8/hex/file inputs, padding control, size budgets, batch processing and byte-exact round-trip proof.
Base64URL encoder, decoder & byte verifier
Work with UTF-8 text, raw hex, existing Base64/Base64URL or a local file. See the same bytes in every representation, validate padding/alphabet rules, prove a byte-exact round trip and keep sensitive payloads in this tab.
1. Source bytes
Base64URL represents bytes. Text is first converted to UTF-8; hex and file modes let you work with arbitrary bytes without pretending they are text.
File bytes stay in this tab. Wave190 caps this mode at 12 MB to avoid freezing low-memory devices.
2. Same bytes, every useful representation
Compare the URL-safe and standard alphabets instead of guessing whether a token was merely transformed or actually changed.
3. Encoded-size budget checks
These are reference budgets, not universal protocol limits. The exact usable space depends on the full URL, cookie attributes, server/proxy configuration and surrounding request data.
4. Batch one value per line
Process up to 100 text lines without leaving the page. Decode mode reports per-row errors instead of discarding the whole batch.
| # | Input | Output | Status |
|---|
5. Session-only snapshots
Save up to eight runs for quick A/B debugging. They exist only in JavaScript memory and disappear when the tab closes; nothing is written to localStorage.
6. Correct implementation snippets
Copy a standards-aligned starting point that handles UTF-8 and raw URL-safe encoding. The snippet never embeds your current payload.
Base64URL correctness that survives real developer workflows
Base64URL is a byte encoding
UTF-8 text is only one source of bytes. Hex and local-file modes make binary data explicit and avoid corrupting arbitrary bytes by forcing them through a text decoder.
The alphabet change is small but important
RFC 4648 URL-safe Base64 replaces + with - and / with _. Padding can be omitted when the receiving protocol allows the length to imply it.
Unicode must become UTF-8 first
Passing emoji or non-ASCII text directly to JavaScript's single-byte btoa() is a common bug. The workbench converts text with TextEncoder before encoding.
Strict decoding catches real mistakes
Mixed standard and URL-safe alphabets, invalid lengths, misplaced padding and non-canonical padding bits should produce clear errors instead of silently returning questionable bytes.
Round-trip proof is stronger than a green button
Wave190 decodes the unpadded Base64URL result and compares every recovered byte with the source bytes. A byte-exact verdict is a direct correctness check.
JWT reading is not JWT verification
JWT header and payload segments use Base64URL, but decoding a JSON segment says nothing about the signature. Authentication requires cryptographic verification with the correct key and algorithm.