Call the free base64url decode API endpoint
curl -X POST https://aisenseapi.com/services/v1/base64url_decode \
-H "Content-Type: application/json" \
-H "Accept: text/plain" \
-d '{"data": "aGVsbG8_"}'hello?The other way is the base64url encode API endpoint.
Reading a JWT payload
The middle part of a JWT is base64url JSON. Ask for JSON and it comes back parsed:
curl -X POST https://aisenseapi.com/services/v1/base64url_decode \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{"data": "eyJzdWIiOiIxMjMiLCJuYW1lIjoiQWRhIn0"}'{"type":"json","decoded_data":{"sub":"123","name":"Ada"}}That reads the claims and checks nothing. To check the signature as well, use the JWT decode API endpoint.
Three response shapes, one Accept header
As on the Base64 decode API endpoint:
| Accept header sent | Response |
|---|---|
| text/plain | text/plain; charset=utf-8, the decoded text as the whole body |
| application/json | {"type": "json", "decoded_data": ...} when the bytes are JSON, otherwise {"type": "binary", "encoding": "base64", "decoded_data": "..."} |
| application/octet-stream, the wildcard or no header | application/octet-stream, an attachment named decoded_data.bin |
| anything else | HTTP 406 with a fix |
Send the data as {"data": "..."} with Content-Type: application/json, or as the raw request body with any other content type. The raw body takes binary data as it is: curl --data-binary @file.bin -H "Content-Type: application/octet-stream".
Errors
| Status | error | When |
|---|---|---|
| 400 | No data to decode. | No data string and no body |
| 400 | Invalid base64url input. | A + or /, which belong to Base64, a space, or a length one past a block of four |
| 406 | Unsupported Accept header. | An Accept header the endpoint cannot answer |
| 413 | Data over 1 MiB. | More than 1 MiB in one request |
Each refusal also carries fix; for + and / it points at /base64_decode.
Common uses
Inspect a token
Read the header or the claims of a JWT, or the client data of a WebAuthn response.
IDs from URLs
Turn a base64url ID taken from a path or a query value back into its bytes.
Check a PKCE challenge
Decode a code challenge to the 32 bytes of the SHA-256 digest it carries.
Privacy and limits
Nothing is stored. The base64url decode answer is worked out while the request is open and the data is gone with it. The access log records the path and the status, not the body.
The base URL is https://aisenseapi.com/services/v1. There is no key, no account and no sign-up step. One request carries at most 1 MiB of data, and the service-wide limit is 5000 requests per IP address per day. Every endpoint in the collection is listed on the Free public REST APIs reference, and the encodings side by side on Encoding APIs.