Skip to content

URL Encode and Decode

Make text safe to put in a web address, or turn an encoded address back into plain text.

  • Free, no account
  • Nothing uploaded
  • 13 tools
Input
Output
working…in 38 B · 1 linesProcessed in this tab, no request made

Nothing you paste is uploaded. The server sends connect-src 'self', so your browser blocks this page from contacting any other host. Check it yourself

Percent-encode text for a query value, a whole URL or a form body, and decode it back. A malformed escape is pointed out by position. Runs in your browser tab.

Three ways to percent-encode

ModeUse it fora b&c/d becomes
ComponentOne value going into a URL (query value, path segment)a%20b%26c%2Fd
Full URLA whole address whose separators must survivea%20b&c/d
Form (+)An application/x-www-form-urlencoded bodya+b%26c%2Fd

The usual bug is using the full-URL mode on a value: an & inside the value is left alone and splits the parameter in two. Encode each value as a component, then join the pieces.

Decoding

Decoding turns each %XX back into a byte and reads the bytes as UTF-8. A % that is not followed by two hex digits is reported with its position. Text that was encoded twice (%2520) needs two passes: decode, put the result back in the input and decode again.

To see a complete address split into its parts, use the URL parser.

Questions

Short answers to what people ask most.

Which mode should I use?

Component for a single value you are placing inside a URL (a query value, a path segment): it encodes / ? & = and #. Full URL for an entire address: it leaves those separators alone. Form for an application/x-www-form-urlencoded body, where a space is written as +.

Why did + not turn into a space when decoding?

In a URL path and in plain percent-encoding, + is a literal plus. Only in form-encoded data (and in query strings by convention) does it mean a space. Turn on "+ as space" when your text comes from a query string or a form body.

What does "A % is not followed by two hex digits" mean?

A percent sign starts an escape such as %20. A lone % or one followed by other characters is malformed. If you meant a literal percent sign, it must be written as %25.

Are non-ASCII characters handled?

Yes. They are converted to UTF-8 bytes and each byte is percent-encoded, which is what RFC 3986 and the browsers do: é becomes %C3%A9.