Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A “Base64 URL” usually means base64url: the URL- and filename-safe variant of Base64 defined in RFC 4648. It represents binary data as text, changes + to - and / to _, and may omit trailing = padding when the protocol can infer the original length.
Base64url is encoding, not encryption. Anyone who obtains the string can decode it, so it provides no confidentiality.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
EXVIST H.265 1080P WiFi HDMI Video Encoder/Decoder, USB2.0 Webcam Input, RTSP/RTMP/TS Stream... | $245.00 | Buy on Amazon |
Base64 versus base64url
Standard Base64 converts each 24-bit input group into four printable characters. Each character carries 6 bits, using a 64-character alphabet plus = as a padding character. The URL-safe form keeps the same bit conversion and almost the same alphabet.
| Value | Standard Base64 | Base64url |
|---|---|---|
| 62 | + |
- |
| 63 | / |
_ |
| Padding | Normally includes trailing = |
Often omits trailing = when length is implicit |
| Typical use | Email attachments, general binary-to-text fields, data URLs | URL paths, query values, filenames and identifier-like tokens |
RFC 4648 Section 5 calls the URL-safe encoding “base64url” and says it should not be regarded as the same encoding as ordinary “base64.” The distinction matters because + and / have special meanings in many URL and form-processing contexts.
#1 Best Overall
- Encoding & Decoding - Avaiable not only for 1ch HDMI encoding input up to 1080p, but also 3ch RTSP streams decoding input or 2ch USB Webcam, compatible with EXVIST, HK, DH and A-xis's IP camera and works with HK, Logitech's USB2.0 web camera.
- Multiple Broadcasting - Suitable not only for pulling stream to your own server via TS (H.265/H.264) like IPTV, but also for pushing stream via RTMP (H.264 only) to Wowza Streaming Engine, YouTube, Twitch, Ustream, Facebook Live, Livestream, Wirecast, vMix etc. to do broadcasting. It also supports stream pushing at least 4 addresses.
- Multiple Applications - Applicable not only for basic CCTV surveillance, NVR, recording system, but also for live broadcasting like IPTV, video conference, video game, telemedicine, remote teaching, major events, WeMedia etc. With HLS(H.264 Only), you can also view live video on your smartphone directly with picture in picture.
- Multiple Protocols - TCP/IP, DHCP, DNS, DDNS(3322, Oray), HLS, HTTP, HTTPS, RTP, RTSP, RTMP, SRT, TS, UDP, Multicast etc protocols supported. It's compatible with ONV/HK private prococol which allows it work with iVMS-4200/8700 and video recorded at H.265 with HK's NVR.
- Recording & Download - Pretty easy to record real-time videos if you'd like to save them into the inserted USB flash drive(128G) in MP4, just pressing the reset/record button for one second. Just press it again and it will stop recording. Easy to preview and download the recorded videos by accessing the encoder.
Why the two-character change matters in URLs
A query parser can treat + as a space, while / is a path separator. A Base64 value containing either character can therefore be changed or split when copied into a URL without proper escaping. Base64url avoids those two characters by using - and _, which are safe in common path, query and filename contexts.
Standard Base64 can still be correct in a data: URL, where the encoded payload is not being used as a path segment or ordinary query parameter. The right choice is determined by the protocol, not by the appearance of the string.
What the equals sign means
Base64 works in groups of three input bytes and four output characters. If the final group has fewer than three bytes, = fills the unused output positions so the encoded length remains a multiple of four.
- One leftover byte normally produces two meaningful characters followed by
==. - Two leftover bytes normally produce three meaningful characters followed by
=. - An input whose length is divisible by three needs no padding.
Many base64url profiles remove only the trailing padding. A decoder then infers the missing characters from the encoded length. Do not remove padding merely because a string is going into a URL: RFC 4648 says implementations normally include appropriate padding unless the referring specification says it may be omitted. Follow the exact protocol. If a profile requires padded output, send =; if it defines unpadded base64url, omit it.
How a decoder restores padding
For an unpadded value, the encoded length modulo four tells a decoder how much padding would have been present:
- Remainder 0: no padding is needed.
- Remainder 2: append
==. - Remainder 3: append
=. - Remainder 1: the length is invalid for ordinary Base64 and should be rejected.
This is a decoding rule, not permission to accept malformed input. A strict implementation should reject characters outside the selected alphabet and reject impossible lengths.
Encoding and decoding in common languages
Python
Python’s URL-safe functions use the -/_ alphabet. The standard library retains padding by default, so remove it only when your protocol specifies unpadded base64url.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →import base64
message = "Hello, URL-safe Base64!".encode("utf-8")
encoded = base64.urlsafe_b64encode(message).decode("ascii")
print(encoded) # padded base64url
unpadded = encoded.rstrip("=")
print(unpadded)
# Restore padding before decoding an unpadded value.
restored = unpadded + "=" * (-len(unpadded) % 4)
decoded = base64.urlsafe_b64decode(restored)
print(decoded.decode("utf-8"))
For strict validation, use an explicit alphabet check before decoding and reject a length remainder of one. The standard decoder’s tolerance for ignored characters should not be mistaken for protocol validation.
JavaScript in a browser
btoa and atob operate on bytes represented as Latin-1 strings, not arbitrary Unicode text. Convert UTF-8 through TextEncoder and TextDecoder, then translate the two alphabet characters.
const bytesToBase64 = bytes => {
let binary = "";
for (const byte of bytes) binary += String.fromCharCode(byte);
return btoa(binary);
};
const base64ToBytes = value => {
const padded = value.replace(/-/g, "+").replace(/_/g, "/")
+ "=".repeat((-value.length) % 4);
const binary = atob(padded);
return Uint8Array.from(binary, ch => ch.charCodeAt(0));
};
const input = new TextEncoder().encode("Hello, URL-safe Base64!");
const standard = bytesToBase64(input);
const base64url = standard.replace(/+/g, "-").replace(///g, "_").replace(/=+$/, "");
console.log(base64url);
console.log(new TextDecoder().decode(base64ToBytes(base64url)));
In server-side JavaScript, use the platform’s Buffer API:
const value = "Hello, URL-safe Base64!";
const base64url = Buffer.from(value, "utf8").toString("base64url");
console.log(base64url);
console.log(Buffer.from(base64url, "base64url").toString("utf8"));
Command line with OpenSSL
OpenSSL emits standard Base64. To make base64url, translate the two characters and remove only trailing padding when the consuming protocol calls for unpadded output.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteprintf 'Hello, URL-safe Base64!'
| openssl base64 -A
| tr '+/' '-_'
| sed 's/=*$//'
When decoding, reverse the translation and restore padding:
value='SGVsbG8sIFVSTC1zYWZlIEJhc2U2NCE'
padded="$value$(printf '%*s' $(( (4 - ${#value} % 4) % 4 )) '' | tr ' ' '=')"
printf '%s' "$padded" | tr '-_' '+/' | openssl base64 -d -A
Is Base64 URL encryption?
No. Encoding changes representation; it does not hide content from a reader. A token such as a JSON Web Token often has base64url-encoded header and payload sections. Decoding those sections can reveal claims immediately. A signature can detect tampering, but it does not make the payload secret. Confidential data needs encryption, and authentication or authorization must be enforced separately.
Do not put passwords, private keys or personal data into a base64url string expecting protection. Treat decoded content as readable by anyone who obtains the URL, filename or token.
Where base64url is the right choice
- URL path segments: binary identifiers can travel without becoming slash-separated paths.
- Query parameters: the value avoids the common
+-as-space problem. - Filenames: the alphabet avoids characters that are awkward or reserved on many systems.
- Identifier-like tokens: compact text can represent bytes while remaining easy to transport.
- OpenAPI schemas: OpenAPI 3.1 can describe binary data with
contentEncoding: base64url.
Use standard Base64 when the surrounding format explicitly expects it, including contexts such as a data URL that accepts the standard alphabet. Do not choose based solely on whether the value “looks” URL-safe.
Free tools Windows power users keep installed
One-click scans. No signup required.
Validation and interoperability checklist
- Identify the protocol’s required alphabet: standard Base64 or base64url.
- Confirm whether padding is required, optional or forbidden.
- Validate the complete input before decoding. Reject unexpected characters rather than silently deleting them.
- Reject an encoded length whose remainder modulo four is one.
- Decode bytes first; interpret them as UTF-8 only if the protocol says the original data is UTF-8 text.
- Keep URL encoding separate from Base64 encoding. If a protocol uses standard Base64 in a query parameter, percent-encode the parameter value instead of substituting characters.
- Test empty input, one-byte input, two-byte input, non-ASCII text and arbitrary binary data.
Common failures and fixes
“Invalid character” or “Illegal base64”
The producer and consumer are using different alphabets, or the value contains whitespace, punctuation or a truncated character. For base64url, accept only letters, digits, - and _, plus = if the profile permits padding.
“Incorrect padding”
The decoder expects a multiple-of-four length but received unpadded base64url. Restore the required trailing = characters, or select a decoder that explicitly supports the protocol’s unpadded profile. Never append padding to a length with remainder one.
Spaces appear where plus signs belonged
A standard Base64 value was placed in a form-style query without percent-encoding. Prefer base64url for a URL-safe protocol, or percent-encode standard Base64 before constructing the URL.
Decoded text contains replacement characters
The original bytes may be binary or may use an encoding other than UTF-8. Preserve the decoded bytes and apply the character encoding specified by the producer; do not force arbitrary bytes through a text decoder.
The decoded payload is readable
That is expected. Base64url is reversible encoding. Use authenticated encryption when the contents must remain confidential or tamper-resistant.
Size, performance and caching considerations
Base64 expands data because every three input bytes become four output characters, before any padding. The encoded representation is therefore roughly one-third larger. This can increase URL length, header size, database storage and log volume. Large binary payloads generally belong in object storage or a body upload rather than a query string.
Encoding and decoding are computationally inexpensive compared with network transfer and cryptography, but allocating a second copy of a large value can matter in memory-constrained applications. Stream or chunk data when the language and protocol support it, and set explicit maximum lengths before decoding untrusted input.
Or skip the browser setup
If you need a clean screenshot of a page while testing URL parameters or encoded identifiers, ScreenshotNeo provides a one-request screenshot API. It accepts consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.
See the ScreenshotNeo documentation for all options. A direct call looks like this:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Frequently Asked Questions
Can I use standard Base64 in a URL?
Yes, if the protocol percent-encodes the value correctly or explicitly permits the standard alphabet. Base64url is usually simpler for path and query values because it avoids + and /.
Does every base64url string omit padding?
No. Padding depends on the protocol. Some profiles require =; others define unpadded output and require the decoder to infer it.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsIs a Base64 URL the same as a URL-encoded URL?
No. Base64url represents bytes using a particular alphabet. URL percent-encoding represents reserved characters as percent-and-hex sequences. They solve different transport problems.
Why does my token contain hyphens and underscores?
Those characters usually indicate the base64url alphabet, where standard Base64’s + and / are replaced with - and _.
The Bottom Line
Base64url is a transport-safe encoding, not security: use the correct alphabet and padding policy for the protocol, validate strictly, and encrypt separately when confidentiality is required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

