Base64url
Also called base64url encoding, URL-safe base64
Base64url is a URL-safe variant of base64 that uses - and _ instead of + and /, and usually drops the = padding. The output works in URLs and filenames without escaping. JWTs encode their header, payload and signature with base64url, and some decoders need the padding added back first.
In more detail
Base64url is the URL- and filename-safe variant of Base64, defined in RFC 4648 section 5. It uses the same 64-character alphabet except that + becomes - and / becomes _, so the result can sit in a URL path, a query string or a file name without escaping.
The = padding at the end is usually dropped, because the decoder can work out the length. Some decoders need it back: add = until the length is a multiple of 4.
JSON Web Tokens use Base64url for all three parts, which is why a JWT header always starts with eyJ: that is {" encoded. Base64url is an encoding, not encryption, so anyone can decode a JWT payload.
Example
const b64url = "eyJhbGciOiJIUzI1NiJ9"
const b64 = b64url.replace(/-/g, "+").replace(/_/g, "/")
const padded = b64 + "=".repeat((4 - (b64.length % 4)) % 4)
atob(padded) // '{"alg":"HS256"}'Try it
Learn more in the guide Base64 encoding explained: format, examples and URL-safe Base64.
← Back to Base64url in the JSON glossaryUpdated 2026-10-01