Base64 URL Decoder Parser
Decode and encode Base64, parse URL-encoded strings, preview Base64 images, and decode JWT header or payload segments
Output will appear here.
How To Use
Choose Parser Mode
Switch between Base64, URL, or JWT segment parsing.
Paste Encoded Value
Input encoded text, image data URL, or full JWT token.
Decode and Inspect
Read decoded output, preview images, and copy results.
FAQ
Yes. Paste a data URL or raw Base64 image string and the tool renders an image preview with detected MIME type and size.
Yes. In decode mode, plus signs are interpreted as spaces before URI decoding, matching common form encoding behavior.
Yes. The JWT mode lets you choose and decode header, payload, or signature-related segments independently.
Standard Base64 (RFC 4648 section 4) uses + and /, which collide with URL reserved characters. The URL-safe alphabet (section 5) swaps them for - and _. JWTs always use the URL-safe alphabet - that is why token signatures never contain + or /. This tool auto-detects either alphabet.
Base64 encodes 3 bytes into 4 characters, so inputs that are not a multiple of 3 are padded with = to keep the length a multiple of 4. One = means 2 leftover bytes, two = means 1. The padding can be safely omitted when the length is known out-of-band - JWT segments do exactly that - and decoders restore it automatically.
Base64 itself is lossless, but the common JavaScript btoa() function only accepts Latin-1 characters and throws on anything else. The correct approach is to UTF-8 encode first (TextEncoder), then Base64 the bytes. This tool handles that pipeline automatically, so Chinese, Arabic, or emoji text round-trips without corruption.
Check three signals: the character set is only A-Z, a-z, 0-9, +, / (or the URL-safe - and _); the length is a multiple of 4 once padding is restored; and decoding produces sensible bytes. No method is 100% certain because many plain strings (like abcd) are also valid Base64 - context matters.
No. Base64 is a reversible encoding that anyone can decode without any secret - it provides zero confidentiality. Never use it to protect passwords or API keys. For protection, use TLS in transit and a real cipher such as AES-256-GCM; Base64's only job is making binary data safe for text channels.
Related Tools
Authoritative References
Primary sources behind this tool - official standards and specifications, not secondhand summaries.
RFC 4648 - Base Encodings of Data Specifications
The IETF base encodings standard covering Base16, Base32, and Base64 (and the URL-safe alphabet).
MDN Web Docs - Base64
Mozilla guide to Base64 in the web platform: btoa/atob and the Unicode pitfalls.
Base64 - Wikipedia
Base64 history, alphabet variants, and padding rules.