Developer Tools

Encoder / Decoder

Encode and decode the formats developers meet every day, in your browser.

  • Runs in your browser
  • No upload required
  • Free, no signup

Pick a conversion, type or paste your input, and the result appears as you go. Everything runs here in the page — nothing is uploaded.

Your data is processed locally in your browser and is not uploaded to our server.

Encoding is not encryption, and mixing the two up causes real mistakes. Everything on this page turns readable text into a different representation of the same bytes — and back again. Anyone with the output can recover the input, which is exactly what makes encoding useful for transporting data and useless for hiding it.

The panel is deliberately the same for every conversion: choose an operation, type your input, read the result. Conversion happens as you type for anything under 100 KB, and Unicode is handled properly throughout, so emoji, accents and non-Latin scripts survive a round trip instead of turning into mojibake.

How to use this tool

  1. Choose an operation from the dropdown, or leave it on Base64 encode. The list is grouped by format: Base64, Base64URL, URL, HTML, Hex, binary, ASCII, Unicode escapes, Base32 and JWT.
  2. Type or paste your input in the left pane. The result appears on the right as you type; press Convert to force it if the input is very large.
  3. Use Swap to push the output back into the input and select the opposite operation — the quickest way to check that something round-trips.
  4. Copy the output, or download it as a text file.

Base64 Encoder & Decoder

Base64 represents arbitrary bytes using 64 printable ASCII characters, so binary data can travel through channels that only carry text — email bodies, JSON fields, data URLs, HTTP headers. Every 3 bytes become 4 characters, so the encoded form is about a third larger.

The decoding here is strict: input that is not valid Base64 or does not decode to valid UTF-8 is reported as an error rather than silently replaced with question marks. That matters because a corrupted decode that looks plausible is far harder to notice than one that fails loudly.

Base64 is not encryption and not compression. It obscures nothing and makes data larger, not smaller.

Base64URL Encoder & Decoder

Base64URL is Base64 with two characters changed so the result is safe inside a URL and a filename: + becomes - and / becomes _, and the trailing = padding is dropped. RFC 4648 §5 defines it.

You meet it constantly without noticing — it is the encoding used for the segments of a JWT, for the state parameter in an OAuth redirect, and in many API keys. If you have Base64 output containing + or / and you are about to put it in a query string, you want this variant instead.

URL Encoder & Decoder

Percent-encoding replaces characters that are not allowed, or are ambiguous, inside a URL with a % followed by their hexadecimal byte value. A space becomes %20, an ampersand becomes %26, and a non-ASCII character becomes a run of escapes for its UTF-8 bytes.

This operation encodes a single component — a query value, a path segment, a cookie value — rather than a whole URL. That distinction is deliberate: encoding a complete URL would escape the / and ? separators and destroy its structure. If you need to build a URL, encode the parts and then join them.

HTML Encoder & Decoder

HTML encoding replaces the characters that carry meaning in markup — &, <, >, " and ' — with their entity forms, so text is displayed literally instead of being parsed as tags.

Decoding converts entities back, and understands named entities such as &amp; and &hellip; as well as numeric ones like &#169; and &#x2603;. Decoding is deliberately done with an explicit lookup table rather than by handing the input to the browser to parse. Assigning untrusted text to innerHTML is a well-worn route to cross-site scripting, and a decoder has no reason to take that risk.

Hex Encoder & Decoder

Hexadecimal shows each byte as two characters from 0-9 and a-f, which makes it the clearest way to look at raw binary. It is what you see in a hash digest, a colour value, a memory dump and a packet capture.

The decoder accepts uppercase, lowercase, and the common separators — spaces, colons, dashes and underscores — so a hash copied out of a tool or a certificate pastes in cleanly. An odd number of digits is rejected, because it cannot form whole bytes.

Binary Encoder & Decoder

Binary encoding writes each byte as eight 0s and 1s, which is the most direct view of what a computer actually stores. It is long-winded — a 1 KB file becomes over 8 000 characters — but it is the fastest way to see bit patterns, flags and masks clearly.

Decoding requires a multiple of eight bits. Anything shorter cannot form a whole byte, so it is reported as an error rather than padded silently.

Unicode Encoder & Decoder

Unicode escapes write a character as \u followed by four hexadecimal digits, which is how non-ASCII text survives in source code, JSON string literals and configuration files that must stay plain ASCII. Characters outside the Basic Multilingual Plane — most emoji, for instance — are written as a surrogate pair of two escapes, exactly as JavaScript and JSON do it.

Decoding turns escapes back into characters, and also understands the newer \u{1F600} brace syntax. ASCII-only text is left alone by the encoder, so the output stays readable unless a character genuinely needs escaping.

Base32 Encoder & Decoder

Base32 uses 32 characters — the letters A to Z and the digits 2 to 7 — to represent data. It produces longer output than Base64, about 60% overhead instead of 33%, and that is precisely the point: the alphabet contains no digits that can be confused with letters, and it is case-insensitive.

That makes it the right choice where a human might have to read or type the value: one-time codes for two-factor authentication, licence keys, and anything dictated over the phone. It is also common in systems that need a case-insensitive identifier.

JWT Encoder & Decoder

A JSON Web Token is three Base64URL segments separated by dots: a header describing the algorithm, a payload of claims, and a signature. This operation decodes the first two into readable JSON so you can see what a token actually says.

It does not verify the signature, and it cannot. Verification needs the secret or public key, which this page never asks for and never sends anywhere. Treat every decoded claim as unproven until your own server has validated the token — that is the whole difference between reading a token and trusting it.

JWT encoding here produces an unsigned token with "alg":"none". It exercises tooling that reads claims; a service that verifies signatures will reject it. For the full picture, including expiry checks, use the JWT tools page.

Frequently asked questions

What is Base64 encoding?

Base64 converts arbitrary binary data into 64 printable characters so it can pass through systems that only handle text. Every 3 bytes become 4 characters, which is why the output is roughly a third larger than the input. It is a transport format, not a security measure — the original data is trivially recoverable by anyone who has the encoded text.

What is the difference between Base64 and Base64URL?

They use different alphabets. Standard Base64 uses + and /, which have special meanings in URLs and are awkward in filenames. Base64URL replaces them with - and _ and drops the = padding. If the encoded value is going into a query string, a URL path, a filename or a JWT, use Base64URL; otherwise standard Base64 produces shorter, softer output.

What does URL encoding do?

It replaces characters that are not permitted or are ambiguous in a URL with a percent sign followed by the hexadecimal value of their bytes. A space becomes %20, & becomes %26, and é becomes %C3%A9. It applies to one component at a time — a query value or a path segment — because encoding a whole URL would escape the separators that give it its structure.

What is HTML encoding?

HTML encoding swaps the five characters that have syntactic meaning in markup — ampersand, less-than, greater-than, double quote and apostrophe — for their entity forms, so the text renders literally instead of being interpreted as tags. It is what stops a username containing <script> from becoming executable markup when it is displayed.

Is encoded data encrypted?

No, and this is the mistake worth avoiding. Encoded data is reversible by design, with no key required — Base64, Base64URL, Hex, Base32 and URL encoding are all just different ways of writing the same bytes down. If you need confidentiality, you need encryption, which is a different operation entirely. Encoding protects data from being mangled in transit; it does not protect it from being read.