Your Base64 data stays in your browser. Client-side only

Base64 URL Decoder

Decode URL-safe Base64 strings (- and _) without padding issues. Built for web tokens, JWTs, and URL parameters.

154 chars
Uses hyphens (-) and underscores (_)
Decoded JWT Claims
HEADER: Algorithm & Token Type
{
  "alg": "HS256",
  "typ": "JWT"
}
PAYLOAD: Data Claims
{
  "sub": "1234567890",
  "name": "Alice Developer",
  "admin": true,
  "iat": 1516239022
}
Parsed 3-segment JWTPadding auto-resolved

What is Base64URL Encoding?

Standard Base64 encoding uses the + and / symbols and appends = characters as padding. When these characters appear in URL paths or query strings, they can interfere with URI syntax: + is often parsed as a space, and / divides directories.

To solve this, RFC 4648 Section 5 defines the "Base64URL" encoding alphabet:

  • The plus character (+) is replaced with a minus sign (-).
  • The forward slash (/) is replaced with an underscore (_).
  • Trailing equal sign (=) padding is typically stripped to prevent URL query parameter conflicts.

Base64URL is NOT Encryption

Just like standard Base64, Base64URL provides zero secrecy. In JSON Web Tokens (JWT), although the payload may be digitally signed, the claims themselves are in plain Base64URL text and can be read by anyone inspecting the token.

Frequently Asked Questions

Clear, concise answers to common questions about Base64 decoding, encoding, and specifications.

Base64URL is defined in RFC 4648 § 5 for safe usage in URLs and query strings. It replaces the plus sign (+) with a hyphen (-) and the slash (/) with an underscore (_), and omits trailing equal sign (=) padding.