Base64 URL Decoder Parser

Decode and encode Base64, parse URL-encoded strings, preview Base64 images, and decode JWT header or payload segments

Output will appear here.
Image Preview
No image detected.
Decoded images will be shown here.

How To Use

Step 1

Choose Parser Mode

Switch between Base64, URL, or JWT segment parsing.

Step 2

Paste Encoded Value

Input encoded text, image data URL, or full JWT token.

Step 3

Decode and Inspect

Read decoded output, preview images, and copy results.

FAQ

Can I decode Base64 images directly in browser?

Yes. Paste a data URL or raw Base64 image string and the tool renders an image preview with detected MIME type and size.

Does URL decoding handle plus signs correctly?

Yes. In decode mode, plus signs are interpreted as spaces before URI decoding, matching common form encoding behavior.

Can I decode only JWT header or payload?

Yes. The JWT mode lets you choose and decode header, payload, or signature-related segments independently.

What is the difference between standard and URL-safe Base64?

Standard Base64 (RFC 4648 section 4) uses + and /, which collide with URL reserved characters. The URL-safe alphabet (section 5) swaps them for - and _. JWTs always use the URL-safe alphabet - that is why token signatures never contain + or /. This tool auto-detects either alphabet.

Why does Base64 end with = signs, and can I remove them?

Base64 encodes 3 bytes into 4 characters, so inputs that are not a multiple of 3 are padded with = to keep the length a multiple of 4. One = means 2 leftover bytes, two = means 1. The padding can be safely omitted when the length is known out-of-band - JWT segments do exactly that - and decoders restore it automatically.

Can Base64 encoding corrupt non-English text?

Base64 itself is lossless, but the common JavaScript btoa() function only accepts Latin-1 characters and throws on anything else. The correct approach is to UTF-8 encode first (TextEncoder), then Base64 the bytes. This tool handles that pipeline automatically, so Chinese, Arabic, or emoji text round-trips without corruption.

How can I tell whether a string is actually Base64?

Check three signals: the character set is only A-Z, a-z, 0-9, +, / (or the URL-safe - and _); the length is a multiple of 4 once padding is restored; and decoding produces sensible bytes. No method is 100% certain because many plain strings (like abcd) are also valid Base64 - context matters.

Is Base64 a form of encryption?

No. Base64 is a reversible encoding that anyone can decode without any secret - it provides zero confidentiality. Never use it to protect passwords or API keys. For protection, use TLS in transit and a real cipher such as AES-256-GCM; Base64's only job is making binary data safe for text channels.

{-- * External Resources Component(#18 Phase 3b 内容佐证工程) * 工具页「权威引用」区块:RFC / W3C / WHATWG / ECMA / IANA / 官方规范站 / Wikipedia。 * * - 接受 :slug 属性 → 经 config/tool-sources.php 家族矩阵渲染该工具的权威引用 * - slug 未命中映射时不渲染(无权威来源的工具静默跳过) * - 链接 title 保持英文(引用源专名);description 经 * common.resources.descriptions.{key} 本地化,lang 未命中回退英文(线上不裸奔) * - 链接保持 dofollow(rel="noopener noreferrer") * * @param string|null $slug --}}