Encode & Decode tools
Eight encodings, in both directions.
-
Base64 encode or decode text online
Convert text to and from Base64 instantly in your browser, with full Unicode support.
-
Convert text to binary or hex and back
Convert text to binary or hexadecimal UTF-8 bytes and decode them back to text, instantly in your browser.
-
Inspect every Unicode character in your text
See code points, UTF-8 bytes, UTF-16 units, HTML entities, escapes and categories for each character, and find hidden invisible characters.
-
URL encode or decode a string online
Percent-encode or decode a URL or query string component instantly in your browser.
-
Decode a JWT online
Paste a JSON Web Token to instantly view its decoded header and payload in your browser.
-
Encode or decode HTML entities online
Convert text to and from HTML entities instantly in your browser.
-
Escape or unescape a string online
Escape or unescape a string for JS/JSON string literals instantly in your browser.
-
Encode or decode ROT13 and Caesar cipher text
Shift letters by any amount, including the classic ROT13, instantly in your browser.
-
Encode or decode a Punycode domain
Convert an internationalized domain name to and from its Punycode (xn--) form, in your browser.
-
Build and sign a JWT online
Build and HMAC-SHA256-sign a JWT from a header, payload, and secret, instantly in your browser.
About Encode & Decode tools
Base64 and URL encoding cover most daily needs — inspecting an Authorization header, untangling a query string that has been escaped twice. HTML entity encoding is the one to reach for when text renders as literal markup, and string escaping handles the quoting rules for embedding text in code. ROT13 and Caesar are classical ciphers, useful for puzzles and not for anything else.
Two are worth singling out. Punycode is how non-ASCII domains are represented, and decoding one reveals homograph domains that look identical to a legitimate name in a browser bar. And decoding a JWT is not verifying it: the payload is Base64, readable by anyone, and only the signature proves the claims were not edited. Decode to inspect, verify on the server, and never trust a claim just because you could read it.