{ }jsonkitOpen
Encoding, numbers and dates

Base64url

Also called base64url encoding, URL-safe base64

Base64url is a URL-safe variant of base64 that uses - and _ instead of + and /, and usually drops the = padding. The output works in URLs and filenames without escaping. JWTs encode their header, payload and signature with base64url, and some decoders need the padding added back first.

In more detail

Base64url is the URL- and filename-safe variant of Base64, defined in RFC 4648 section 5. It uses the same 64-character alphabet except that + becomes - and / becomes _, so the result can sit in a URL path, a query string or a file name without escaping.

The = padding at the end is usually dropped, because the decoder can work out the length. Some decoders need it back: add = until the length is a multiple of 4.

JSON Web Tokens use Base64url for all three parts, which is why a JWT header always starts with eyJ: that is {" encoded. Base64url is an encoding, not encryption, so anyone can decode a JWT payload.

Example

Decoding Base64url in the browserjs
const b64url = "eyJhbGciOiJIUzI1NiJ9"
const b64 = b64url.replace(/-/g, "+").replace(/_/g, "/")
const padded = b64 + "=".repeat((4 - (b64.length % 4)) % 4)
atob(padded)   // '{"alg":"HS256"}'

Try it

Learn more in the guide Base64 encoding explained: format, examples and URL-safe Base64.

← Back to Base64url in the JSON glossaryUpdated 2026-10-01