How to use
- Choose Encode or Decode. The URL-safe variant is preselected with padding switched off.
- Type or paste text, enter hex bytes, or open a file. The result updates as you type.
- Turn padding on only if the receiving system requires = signs at the end.
- Copy the result or download it.
What is Base64URL?
Base64URL is defined in section 5 of RFC 4648 as "Base 64 Encoding with URL and Filename Safe Alphabet". It works exactly like standard Base64, 6 bits per character, but swaps the two characters that cause trouble in URLs and file paths:
| Standard Base64 | Base64URL | |
|---|---|---|
| Value 62 | + | - |
| Value 63 | / | _ |
| Padding | =, required | usually omitted |
In a URL, + can be read as a space, / separates path segments and = separates query keys from values, so standard Base64 has to be percent-encoded before it goes into a link. Base64URL needs no escaping. RFC 4648 allows the padding to be dropped when the length is known from context, and most specifications built on Base64URL do exactly that.
Where Base64URL is used
- JSON Web Tokens. The header, payload and signature of a JWT are each Base64URL without padding (RFC 7515). Read one with the JWT Decoder.
- OAuth 2.0 PKCE. The
code_challengeis the unpadded Base64URL form of the SHA-256 hash of the code verifier (RFC 7636), so it is always 43 characters long. - JSON Web Keys and WebAuthn. Key parameters such as
n,e,xandy, as well as WebAuthn challenges and credential IDs, are exchanged as Base64URL. - Tokens, IDs and file names. Reset links, signed URLs and cache keys carry Base64URL without escaping; a 16-byte random ID becomes 22 characters. On case-insensitive file systems, prefer Base32, because Base64URL depends on letter case.
Converting between Base64 and Base64URL
Both variants encode the same bytes, so converting is a character swap: replace + with - and / with _, then remove trailing =. To go back, swap the characters again and add = until the length is a multiple of 4. The decoder on this page accepts both alphabets, with or without padding.
// Node.js 16+
Buffer.from(data).toString('base64url')
Buffer.from(str, 'base64url')
# Python (urlsafe_b64encode keeps the padding)
base64.urlsafe_b64encode(data).rstrip(b'=')
// Go
base64.RawURLEncoding.EncodeToString(data)
// Java
Base64.getUrlEncoder().withoutPadding().encodeToString(bytes)
Specification
| Alphabet | A-Z a-z 0-9 - _ |
|---|---|
| Output size | 4 characters per 3 bytes (about 133%) |
| Padding | Optional, usually omitted |
| Standard | RFC 4648 section 5 |
| Case sensitive | Yes |
Examples
| Input (UTF-8) | Output |
|---|---|
Hello, World! | SGVsbG8sIFdvcmxkIQ |
Base64.is | QmFzZTY0Lmlz |
你好 | 5L2g5aW9 |
Frequently asked questions
Is Base64URL the same as URL-encoding a Base64 string?
+, / and = into %2B, %2F and %3D, which makes the string longer. Base64URL uses a different alphabet, so no escaping is needed at all. The two forms are not interchangeable without converting.Should Base64URL have padding?
urlsafe_b64encode and Java's default URL encoder add it. When in doubt, omit it; this decoder accepts both forms.Why does a standard Base64 decoder reject my Base64URL string?
- and _, and some require padding. Swap the characters and add = signs to make the length a multiple of 4, or decode the string here.How do I check a PKCE code challenge?
BASE64URL(SHA256(code_verifier)) without padding. Decode it here with hex output: a correct value gives exactly 32 bytes, which you can compare with the SHA-256 hash of the verifier.