Base64 ↔ JSON

Encode JSON to Base64 or decode Base64 back to pretty-printed JSON

Shortcuts: Ctrl+Enter run · Ctrl+L clear · Ctrl+D download

About Base64 ↔ JSON

This tool encodes JSON to Base64 and decodes Base64 back to formatted JSON. Base64-encoded JSON appears in JWT tokens, HTTP Authorization headers, binary data URIs, and some API authentication schemes. Being able to quickly decode or encode these values is a common day-to-day task for developers.

  • ✓Encodes any valid JSON object or array to a Base64 string
  • ✓Decodes Base64 strings back to pretty-printed JSON
  • ✓Handles standard Base64 and URL-safe Base64 (using - and _ instead of + and /)
  • ✓Useful for inspecting JWT payloads and Base64-encoded API tokens

Base64 and JSON — Encoding, Decoding, and JWTs

Base64 turns arbitrary bytes — including the text of a JSON document — into a string made up only of letters, digits, `+`, `/`, and `=`. That restricted character set is the whole point: it can pass safely through systems that were only designed to handle plain text, like HTTP headers, URLs, and older text-based protocols that might choke on raw binary data or special characters.

How the encoding works

Base64 takes input 3 bytes (24 bits) at a time and re-groups those bits into four 6-bit chunks, each mapped to one of 64 printable characters (A–Z, a–z, 0–9, +, /). If the input length isn't a multiple of 3, `=` padding characters are appended to the end so the output length is always a multiple of 4.

JSON:    {"id":1}
Base64:  eyJpZCI6MX0=

Every 3 input bytes → 4 output characters.
The trailing "=" is padding, not part of the data.

Standard vs. URL-safe Base64

  • ·Standard Base64 uses `+` and `/` as two of its 64 characters — both have special meaning inside a URL (`+` can mean "space", `/` separates path segments)
  • ·URL-safe Base64 replaces `+` with `-` and `/` with `_`, so the encoded string can be placed directly into a URL or filename without additional percent-encoding
  • ·Padding (`=`) is sometimes stripped entirely in URL-safe contexts, since `=` also has meaning in query strings — if you're decoding a string and it errors on length, try re-adding `=` padding until the length is a multiple of 4

Where this shows up: JWTs

A JSON Web Token is three Base64 URL-safe segments separated by dots: a header, a payload, and a signature. The header and payload are each just JSON objects that have been Base64 URL-encoded — decode either segment and you get back readable JSON.

eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkFsaWNlIn0.signature
└────── header ──────┘└──────────── payload ────────────┘└─sig─┘

Decoded header:  {"alg":"HS256"}
Decoded payload: {"sub":"1234","name":"Alice"}

Tip: If you're working specifically with JWTs, the JWT Decoder tool does this split-and-decode automatically and also reads expiry and issuer claims — use this Base64 ↔ JSON tool for one-off encoding/decoding of arbitrary values, and the JWT Decoder when the input is specifically a token.

A reminder about security

Because decoding Base64 requires no key or secret, anyone who can see a Base64 string can read what's inside it instantly — this is true for JWT payloads too, which is why JWTs should never contain passwords, secrets, or sensitive personal data in their payload. Base64 provides safe transport through text-only systems, not confidentiality.

Frequently Asked Questions

Ad