RFC 4648 §5 URL-Safe Encoding

Base64 URL Encoder Online & Decoder

A dedicated base64 url encoder online and base64url decode utility. Easily url safe base64 encode text, parse base64 url encoded payloads, and convert url base64 strings for JWT, OAuth, and web APIs.

0 chars
0
Hyphens (-) replaced from (+)
0
Underscores (_) replaced from (/)
0
Padding characters (=) stripped
0
Encoded String Length

Standard Base64 vs. URL-Safe Base64 Format

Standard Base64 (RFC 4648 §4)
-
Base64URL Safe (RFC 4648 §5)
-
Percent-Encoded Standard URL
-

Complete Guide to Base64URL Encoding and URL-Safe Conversions

When transmitting binary data, security hashes, or JSON objects through HTTP GET requests, URI paths, and query parameters, standard Base64 encoding presents significant risks of corruption. Using our base64 url encoder online and base64url string converter, developers can effortlessly convert data into a base64 url safe format.

Whether you need to perform a base64url decode operation on an incoming webhook payload, analyze base64 url encoded parameters, or implement base64url encoding in your software architecture, this comprehensive reference provides the specifications, mathematical underpinnings, and production code snippets across major programming languages.

Why Standard Base64 Breaks URLs and Web Requests

Standard Base64 (defined in RFC 4648 Section 4) was engineered for MIME email transport (RFC 2045). It uses 64 ASCII characters to represent 6-bit chunks of binary information:

Character Standard Base64 Issue in URLs Base64URL Safe Replacement RFC 4648 §5 Rule
+ (Plus) HTTP servers and browsers decode + in query strings as an empty space (%20). - (Hyphen / Minus) Replace ASCII 43 (+) with ASCII 45 (-).
/ (Slash) Interpreted as a URI path segment separator by web servers and reverse proxies (Nginx, Apache). _ (Underscore) Replace ASCII 47 (/) with ASCII 95 (_).
= (Equals) Interpreted as a query parameter key-value delimiter (e.g. ?key=val). Requires percent-encoding to %3D. Omitted / Stripped Padding is removed; string length modulo 4 deterministically restores it during decode.

How Base64URL Encoding Works Step-by-Step

To transform any string or binary stream into url safe base64 encode text:

  1. UTF-8 Byte Encoding: Convert the input text into a sequence of 8-bit bytes using UTF-8.
  2. Standard Base64 Conversion: Pack groups of three 8-bit bytes (24 bits) into four 6-bit values, mapping each to the standard Base64 character index table.
  3. Character Substitution: Search the resulting string for any plus signs (+) and replace them with hyphens (-). Search for any forward slashes (/) and replace them with underscores (_).
  4. Padding Stripping: Strip all trailing equal signs (=). Because the receiver can determine the original byte count by calculating len % 4, transmitting padding over the wire is redundant.

Reversing the Process: How to Perform base64 url decode

When receiving a url base64 token, your application must reconstruct the original bytes through base64 url decode:

  1. Replace all hyphens (-) with plus signs (+).
  2. Replace all underscores (_) with forward slashes (/).
  3. Calculate missing padding:
    • If str.length % 4 === 2, append ==.
    • If str.length % 4 === 3, append =.
    • If str.length % 4 === 0, no padding was stripped.
    • If str.length % 4 === 1, the token is corrupt (an illegal Base64 length).
  4. Decode the resulting standard Base64 string into UTF-8 bytes and text.

Real-World Production Implementation Snippets

1. JavaScript (Browser & Node.js)

// Fast URL-safe base64 encoding and decoding in modern JavaScript function base64UrlEncode(str) { const bytes = new TextEncoder().encode(str); const binString = Array.from(bytes, (byte) => String.fromCharCode(byte)).join(''); return btoa(binString) .replace(/\+/g, '-') .replace(/\//g, '_') .replace(/=+$/, ''); } function base64UrlDecode(str) { let base64 = str.replace(/-/g, '+').replace(/_/g, '/'); while (base64.length % 4) { base64 += '='; } const binString = atob(base64); const bytes = Uint8Array.from(binString, (m) => m.charCodeAt(0)); return new TextDecoder().decode(bytes); }

2. Python 3 (`base64.urlsafe_b64encode`)

import base64 def urlsafe_encode(text: str) -> str: encoded_bytes = base64.urlsafe_b64encode(text.encode('utf-8')) return encoded_bytes.decode('ascii').rstrip('=') def urlsafe_decode(encoded_str: str) -> str: padding = 4 - (len(encoded_str) % 4) if padding < 4: encoded_str += '=' * padding return base64.urlsafe_b64decode(encoded_str.encode('ascii')).decode('utf-8')

3. PHP (`rtrim`, `strtr`)

// Idiomatic PHP implementation used by Laravel and Symfony function base64url_encode($data) { return rtrim(strtr(base64_encode($data), '+/', '-_'), '='); } function base64url_decode($data) { return base64_decode(strtr($data, '-_', '+/') . str_repeat('=', (4 - strlen($data) % 4) % 4)); }

Why JSON Web Tokens (JWT) Exclusively Mandate Base64URL

The Internet Engineering Task Force (IETF) RFC 7519 specification governing JSON Web Tokens states that the Header, Payload, and Signature parts of a compact JWT must be joined by period characters (.) and must be encoded using Base64URL without padding.

If standard Base64 were used in a JWT, a token containing a plus sign passed in a URL parameter like https://api.example.com/verify?token=eyJhbG... would have its + converted into a space by the web framework. The signature verification would fail instantly with an invalid cryptographic digest. Base64URL completely eliminates this vulnerability.

Frequently Asked Questions (FAQ)

No. Base64URL is an encoding format, not an encryption cipher. Anyone who intercepts a Base64URL string can instantly decode it back to plaintext using this online tool or any programming language decoder. Never store sensitive passwords or secret keys in Base64URL without encrypting them first with AES or ChaCha20.
Standard browser atob() will throw an error (DOMException: The string to be decoded is not correctly encoded) if it encounters hyphens, underscores, or missing padding. You must always replace characters and restore padding before invoking atob().
Standard Base64 encoded with encodeURIComponent converts + to %2B, / to %2F, and = to %3D, inflating URL size significantly. Base64URL provides a cleaner, fixed-size representation without percentage escape triplets.