Encoding Tools
Encode and decode Base64 and URL components in your browser.
Tools
Base64 vs. URL encoding
These solve different problems, even though both turn data into an ASCII-safe string. Base64 re-encodes the entire input, binary or text, into a compact form built for embedding: a data: URI, a JSON field, an Authorization header. It expands and obscures the original text rather than keeping it readable. URL encoding (percent-encoding) only escapes the specific characters that aren't safe in a URL, leaving everything else as-is, which is why it's what query strings and path segments use, not Base64.
Standard vs. URL-safe Base64
Standard Base64's alphabet includes + and /, both of which already mean something inside a URL, so a standard Base64 string often needs to be percent-encoded on top before it's safe to put in one. URL-safe Base64 avoids that by swapping those two characters for - and _ instead. The two alphabets aren't interchangeable: feeding URL-safe output into a standard decoder, or the reverse, produces garbage or an outright decode error.
Padding, and why decoding sometimes fails
Base64 groups input into 4-character blocks; the trailing = characters pad the last block out to that length when the input doesn't divide evenly. Some decoders require that padding, others (many URL-safe implementations included) accept unpadded input and infer the length from context. If a string that looks correct still won't decode, check for exactly this: padding that's missing where a strict decoder expects it, an extra character or line break from a copy-paste, or a stray +// vs. -/_ mismatch between the two alphabets.
Frequently asked questions
- Should I use Base64 or URL encoding?
- It depends on where the data is going. Base64 turns arbitrary binary or text into a compact ASCII string, useful for embedding data in JSON, a data: URI, or an auth header. URL encoding (percent-encoding) escapes only the specific characters that aren't safe in a URL, like spaces and &, and leaves the rest readable. Use URL encoding for query strings and path segments, Base64 for embedding binary or opaque data.
- Is Base64 encryption?
- No. Base64 is a reversible encoding, not encryption: anyone can decode it instantly with no key. Don't use it to protect passwords, tokens, or any data that needs to stay confidential.
- What's the difference between standard and URL-safe Base64?
- Standard Base64 uses + and / in its alphabet, both of which have special meaning inside a URL. URL-safe Base64 swaps them for - and _ so the output can go directly into a query string or path without additional escaping. The two aren't interchangeable, decoding standard Base64 with a URL-safe decoder (or vice versa) will fail or produce wrong output.
- Why does Base64 sometimes end in = signs, and can I remove them?
- = is padding, added so the output length is a multiple of 4 characters, which some decoders require. Whether it's needed depends on the decoder: many, including URL-safe variants, accept unpadded input, but a strict decoder will reject it. If a decode is failing on a string that looks otherwise valid, missing or extra padding is a likely cause.
- Why does my Base64 string fail to decode?
- The most common causes: a character outside the Base64 alphabet (often + or / in a URL-safe context, or vice versa), incorrect or missing padding, or the string being truncated, for example if it was copied from a place that wrapped or trimmed long lines.