Home / Base64 Tools / Base64URL Encoder
Base64 Tools

Base64URL Encoder

Encode, decode, normalize and verify Base64URL as bytes—not just text—with strict RFC 4648 validation, UTF-8/hex/file inputs, padding control, size budgets, batch processing and byte-exact round-trip proof.

Wave190 · RFC 4648 byte workbench

Base64URL encoder, decoder & byte verifier

Work with UTF-8 text, raw hex, existing Base64/Base64URL or a local file. See the same bytes in every representation, validate padding/alphabet rules, prove a byte-exact round trip and keep sensitive payloads in this tab.

Browser-local · no payload upload

1. Source bytes

Base64URL represents bytes. Text is first converted to UTF-8; hex and file modes let you work with arbitrary bytes without pretending they are text.

Ready.
—Input characters
—Decoded/source bytes
—Visible output chars
—Encoded length overhead
—= padding chars
—Chars saved vs percent-encoded standard Base64
—Round-trip verification

2. Same bytes, every useful representation

Compare the URL-safe and standard alphabets instead of guessing whether a token was merely transformed or actually changed.

3. Encoded-size budget checks

These are reference budgets, not universal protocol limits. The exact usable space depends on the full URL, cookie attributes, server/proxy configuration and surrounding request data.

Conservative URL reference—
Single-cookie reference—
Apache request-line reference—
—

4. Batch one value per line

Process up to 100 text lines without leaving the page. Decode mode reports per-row errors instead of discarding the whole batch.

0 rows
#InputOutputStatus

5. Session-only snapshots

Save up to eight runs for quick A/B debugging. They exist only in JavaScript memory and disappear when the tab closes; nothing is written to localStorage.

6. Correct implementation snippets

Copy a standards-aligned starting point that handles UTF-8 and raw URL-safe encoding. The snippet never embeds your current payload.

Security boundary: Base64URL is encoding, not encryption, hashing or signature verification. Anyone with the value can decode it. A JWT payload can be read without proving the token is authentic; use a dedicated verifier and the issuer's keys for trust decisions. This page performs its conversions locally and does not intentionally persist your payload.

Base64URL correctness that survives real developer workflows

Base64URL is a byte encoding

UTF-8 text is only one source of bytes. Hex and local-file modes make binary data explicit and avoid corrupting arbitrary bytes by forcing them through a text decoder.

The alphabet change is small but important

RFC 4648 URL-safe Base64 replaces + with - and / with _. Padding can be omitted when the receiving protocol allows the length to imply it.

Unicode must become UTF-8 first

Passing emoji or non-ASCII text directly to JavaScript's single-byte btoa() is a common bug. The workbench converts text with TextEncoder before encoding.

Strict decoding catches real mistakes

Mixed standard and URL-safe alphabets, invalid lengths, misplaced padding and non-canonical padding bits should produce clear errors instead of silently returning questionable bytes.

Round-trip proof is stronger than a green button

Wave190 decodes the unpadded Base64URL result and compares every recovered byte with the source bytes. A byte-exact verdict is a direct correctness check.

JWT reading is not JWT verification

JWT header and payload segments use Base64URL, but decoding a JSON segment says nothing about the signature. Authentication requires cryptographic verification with the correct key and algorithm.

Search by task, tool name, or category. Press Esc to close.
Start typing to find a tool.