Skip to content
Browser tool Runs locally

Encoding Tools

Encode and decode Base64 and URL components in your browser.

Tools

Base64 vs. URL encoding

These solve different problems, even though both turn data into an ASCII-safe string. Base64 re-encodes the entire input, binary or text, into a compact form built for embedding: a data: URI, a JSON field, an Authorization header. It expands and obscures the original text rather than keeping it readable. URL encoding (percent-encoding) only escapes the specific characters that aren't safe in a URL, leaving everything else as-is, which is why it's what query strings and path segments use, not Base64.

Standard vs. URL-safe Base64

Standard Base64's alphabet includes + and /, both of which already mean something inside a URL, so a standard Base64 string often needs to be percent-encoded on top before it's safe to put in one. URL-safe Base64 avoids that by swapping those two characters for - and _ instead. The two alphabets aren't interchangeable: feeding URL-safe output into a standard decoder, or the reverse, produces garbage or an outright decode error.

Padding, and why decoding sometimes fails

Base64 groups input into 4-character blocks; the trailing = characters pad the last block out to that length when the input doesn't divide evenly. Some decoders require that padding, others (many URL-safe implementations included) accept unpadded input and infer the length from context. If a string that looks correct still won't decode, check for exactly this: padding that's missing where a strict decoder expects it, an extra character or line break from a copy-paste, or a stray +// vs. -/_ mismatch between the two alphabets.

Frequently asked questions

Should I use Base64 or URL encoding?
It depends on where the data is going. Base64 turns arbitrary binary or text into a compact ASCII string, useful for embedding data in JSON, a data: URI, or an auth header. URL encoding (percent-encoding) escapes only the specific characters that aren't safe in a URL, like spaces and &, and leaves the rest readable. Use URL encoding for query strings and path segments, Base64 for embedding binary or opaque data.
Is Base64 encryption?
No. Base64 is a reversible encoding, not encryption: anyone can decode it instantly with no key. Don't use it to protect passwords, tokens, or any data that needs to stay confidential.
What's the difference between standard and URL-safe Base64?
Standard Base64 uses + and / in its alphabet, both of which have special meaning inside a URL. URL-safe Base64 swaps them for - and _ so the output can go directly into a query string or path without additional escaping. The two aren't interchangeable, decoding standard Base64 with a URL-safe decoder (or vice versa) will fail or produce wrong output.
Why does Base64 sometimes end in = signs, and can I remove them?
= is padding, added so the output length is a multiple of 4 characters, which some decoders require. Whether it's needed depends on the decoder: many, including URL-safe variants, accept unpadded input, but a strict decoder will reject it. If a decode is failing on a string that looks otherwise valid, missing or extra padding is a likely cause.
Why does my Base64 string fail to decode?
The most common causes: a character outside the Base64 alphabet (often + or / in a URL-safe context, or vice versa), incorrect or missing padding, or the string being truncated, for example if it was copied from a place that wrapped or trimmed long lines.