The Encoding and Escaping Kit
Move data through text without surprises: size Base64 in bytes before it hits a cookie, header or URL limit, decide when not to use it, pick the alphabet a URL survives, escape each value once for the place it lands, and stop trusting an encoding or a fast hash to keep a secret
AskMeCode's Base64 Converter encodes and decodes one value, the JSON Formatter lays out one payload and the Hash Generator fingerprints one string. A system asks different questions: how big a value is once it is encoded, whether it still fits the cookie, header or URL it has to pass through, which alphabet survives a query string, what it must become when it lands in HTML, JSON, SQL or a shell, and whether the thing protecting it is protection at all. The Encoding and Escaping Kit works those questions with the same code the tools run. A JWT whose claims are 107 bytes of JSON is 224 characters long, and a 4,048-character cookie value holds claims of 2,975 bytes, not 4,048. A random 18-byte token in standard Base64 put in a query string comes back from the parser with a space where its + was, and decodes, without an error, to 17 bytes. Gzip takes a data URI's overhead on the wire back to 1.7%, but a Base64 column keeps all 33%. One string is escaped for HTML text, an HTML attribute, JSON, a URL and a regex side by side, and the kit shows why SQL and shell commands take bound parameters and argument arrays instead. Every figure is computed by code and every limit and rule is quoted from its source: RFC 4648, 2045, 7515, 8259, 6265 and 9110, the URL Standard, the nginx documentation and the OWASP cheat sheets on password storage, SQL injection and cross-site scripting. Tokens, secrets and traffic numbers are examples; it is not a security review. Included: 7 steps, a payload size sheet, a boundary map, a test vector card for your own test suite, a protection audit, a size reference and a quickstart, plus a personalised sheet worked from the sizes the Base64 Converter and JSON Formatter publish (never your text).
Look inside
Two full pages from the kit, exactly as printed. Click either to read it at full size before you decide.
What is in it
- The Byte Rule: characters, string length and UTF-8 bytes, and where btoa throws or silently encodes Latin-1
- Four for Three: exact Base64 lengths padded, unpadded and with 76-character MIME lines, and why small values grow most
- The Ceiling Rule: cookie, URI and header limits from their sources, worked back to the largest input and the largest JWT claims
- The Inline Test: data URI against file, what gzip takes back on the wire, and what Base64 storage keeps
- The Alphabet Rule: base64url, and the + that a query string turns into a space
- Escape Once, at the Boundary: one string escaped for HTML, attributes, JSON, URLs and regex; bound parameters for SQL; argument arrays for the shell; JSON's number limit
- Encoding Hides Nothing: encoding, hashing, signing, encryption and password hashing side by side, with OWASP's password guidance
- Working pages: a payload size sheet, a boundary map, a test vector card and a protection audit
- Size reference: encoded length by input size and the largest input for a length limit
- A quickstart, and a personalised sheet worked from your own tool sizes
- ✓ 24 printable pages
- ✓ 10 sections, worksheets and templates
- ✓ A second PDF worked out from the numbers you enter
- ✓ No account needed, just an email address
- ✓ Instant download; link valid 7 days
Price includes any taxes. Sold by GrabURL, who handle checkout and support. The charge appears on your statement as GrabURL.
The kit picks up where the free Base64 Converter leaves off. The converter encodes and decodes one value and tells you its size in bytes and characters. The kit works out what that size means for a system: the cookie, header and URL limits a token has to pass, when a data URI or a Base64 column costs more than the file, which alphabet survives a query string, and how one value is escaped for HTML, JSON, URLs, regex, SQL and the shell. It uses the JSON Formatter for the number boundary and the Hash Generator to show why encoding and fast hashes protect nothing. Every token, secret and traffic figure in it is an example; the limits are quoted from the RFCs and documentation they come from, and your own stack's documentation is the final word. It is not a security review, and no outcome is promised.

