About EncodeLens
EncodeLens is a set of browser-only tools for the encodings and formats developers meet every day: Base64, percent-encoding in URLs, JSON Web Tokens, hashes and HMACs, and JSON and YAML.
Why it exists
These formats look simple and fail in confusing ways. A Base64 string can be valid in one alphabet and invalid in the other. encodeURI leaves an & that encodeURIComponent escapes.
A JWT decodes happily while proving nothing. A SHA-256 differs because of one trailing newline. The country code NO becomes false in a YAML file.
EncodeLens does the conversion, then explains the failure cases with real inputs and the exact output, and cites the specification for each rule.
Everything runs in your browser
The encoders, decoders, parsers and converters are TypeScript running on your device; hashes and HMACs use your browser's built-in Web Crypto API. What you type, paste or choose as a file is not sent to a server. Pages are static files; there is no back end that receives your input. The details, including the one setting key the site stores in your browser's local storage, are in the Privacy Policy.
How the results were checked
- Specification vectors. Base64 is tested against every test vector in RFC 4648 section 10; the JWT decoder against the examples in RFC 7515 appendix A.1 and RFC 7519; hashes against the NIST example values and the RFC 1321 suite; HMAC against RFC 4231 and RFC 2202. The hash page lists the vectors and has a button that runs them in your browser.
- Hand-derived expectations. Expected values in the tests were worked out from the specification text first (bit groups for Base64, byte values for percent-encoding, octal and base-60 arithmetic for YAML 1.1) and only then compared with the code, so a bug in the code cannot quietly become the expected answer.
- Independent implementations. The Base64 and MD5 code was compared with Node.js on thousands of random inputs, the percent-encoder with the browser's own
encodeURIComponent,encodeURIandURLSearchParams, and HMAC withnode:crypto. The JSON and YAML converter uses the open-sourceyamlpackage rather than our own YAML parser, and every behaviour described on that page was tested against it. - Real browser test. The built site was loaded in headless Chrome and each tool was run with a known input, because tests of the code alone cannot show a button that is not wired up.
Where it is unsure
Each page has a section on limits, and behaviour that comes from observing software rather than from a specification is labelled as observed. Examples: what Node's Buffer does with a stray character in Base64, how the YAML library reads 08 under YAML 1.1,
and that a %YAML directive overrides the version selector. Every page ends with the specifications it relied on, with links and the date they were read. If a result disagrees with your own software, please
tell us with the input, the options and what you saw; that is the most useful kind of correction. Do not send secrets.
Who runs it
EncodeLens, an independent project operated from Indonesia. You can reach us by email at joe@zona13.net.
Cost and advertising
The site is free. It currently shows no advertising, uses no analytics and sets no cookies. If any of that ever changes, the Privacy Policy and this page will be updated before it does.
What it is not
It is not a security tool, a password manager or a validator for your production systems. Base64, percent-encoding and YAML conversion hide nothing, decoding a JWT does not verify it, and MD5 and SHA-1 are offered for compatibility only. Treat the output as a well-checked second opinion, and do not paste production secrets into any web page you cannot audit. See the terms and disclaimer.