How this calculator works
Base64 turns any data into text using 64 characters: A–Z, a–z, 0–9, + and /, with = for padding. It is used for email attachments, data URLs and API payloads. Encoded data is about a third larger than the original.
Base64URL is the same idea with URL-safe characters: - and _ replace + and /, and the padding is dropped. JSON Web Tokens (JWTs) use it, so decoding the middle part of a JWT shows its claims.
URL encoding (percent-encoding) replaces characters that have special meaning in web addresses, such as spaces, ?, & and =, with % codes. A space becomes %20 and é becomes %C3%A9.
Text is converted to UTF-8 bytes before encoding, so non-English text round-trips correctly. When decoding URLs, + is read as a space, as in submitted web forms.
Encoding is not encryption. Anyone can decode Base64, so never use it to hide passwords or secrets.
Worked example
Encoding “héllo wörld?”
- Base64: aMOpbGxvIHfDtnJsZD8=
- URL encoding: h%C3%A9llo%20w%C3%B6rld%3F
- “Use output as input” switches to decoding and gives back the original text.
Questions people ask
Is Base64 secure?
No. Base64 is a way of representing data as text, not a way of protecting it. Anyone can decode it instantly.
How do I decode a JWT?
Copy the middle part, between the two dots, and decode it as Base64URL. You will see the token’s claims as JSON. Decoding doesn’t check the signature.
Why does my decoded text show strange characters?
The data may not be UTF-8 text, for example an image or a file. Decoding binary data as text produces unreadable characters.
Is my data sent anywhere?
No. Encoding and decoding happen in your browser, so tokens and private data never leave your device.
Sources
Last reviewed October 2, 2026