URL encode and decode
Percent-encode text so it's safe in a URL, decode %20-style escapes back to text, and break a full URL into a table of its query parameters.
- 100% free
- Runs in your browser
- No uploads
Like encodeURIComponent: escapes everything except letters, digits and - _ . ~, so the text is safe as one query value or path segment.
Break down a URL and its query string
- Runs on your deviceEvery tool works directly in your browser. No files are uploaded.
- Your privacy mattersYour files never leave your device, so there's nothing for us to store.
- No limitsUse any tool as much as you need. No daily caps, no waiting.
- Completely freeNo signup and no trial to cancel. Ads keep the tools free.
How to URL encode or decode
- Choose Encode or Decode. The result updates as you type.
- Pick how to encode. Value for a query value or path segment, Full URL for a whole address, Form (+) for + instead of %20.
- Copy the result. Decode this or Encode this sends the result back to the input to go the other way.
- Break down a URL. Paste any address below the tool to see its host, path and each query parameter decoded, including repeated keys.
How percent-encoding works
URLs may only contain a limited set of ASCII characters. Anything else is turned into UTF-8 bytes, and each byte is written as % plus two hex digits. A space is byte 20 in hex, so it becomes %20; é is the two bytes C3 A9, so it becomes %C3%A9; an emoji takes four bytes and twelve characters.
Letters, digits and - _ . ~ are never encoded. Characters with a job in URLs, such as ? & = / #, are encoded only when they are part of a value. The Value mode here also encodes ! ' ( ) *, which encodeURIComponent leaves alone but some servers and email clients mishandle.
Common URL encodings
| Character | Encoded | Note |
|---|---|---|
space | %20 or + | + only in form-encoded query strings |
& | %26 | Otherwise starts a new parameter |
= | %3D | Otherwise splits key and value |
? | %3F | Otherwise starts the query string |
# | %23 | Otherwise starts the fragment |
/ | %2F | Only inside a value |
+ | %2B | So it isn't read as a space |
% | %25 | The escape character itself |
é | %C3%A9 | Two UTF-8 bytes |
€ | %E2%82%AC | Three UTF-8 bytes |
Tips and common mistakes
- Encode values, not the whole URL. Build the address from parts and encode each value on its own. In JavaScript,
new URLSearchParams({ q: "a&b" })does it for you. - Don't encode twice. If a library already encodes parameters, passing it an encoded string gives %2520 instead of %20.
- Repeated keys are allowed.
color=red&color=blackis valid; how a server reads it varies, so check your framework.
Frequently asked questions
What's the difference between encodeURI and encodeURIComponent?
encodeURI is for a whole address: it leaves the characters that give a URL its structure, such as : / ? # & and =, alone. encodeURIComponent is for one piece, such as a search term or a value inside a query string, and escapes those characters too. Using encodeURI on a value is a common bug: an & in the value then splits it into two parameters.
Should a space be %20 or +?
Both are seen. %20 works everywhere in a URL. + means a space only in the query string of HTML form submissions (application/x-www-form-urlencoded); in a path, + is a literal plus sign. When decoding, tick Treat + as a space for query strings, and untick it for paths or values where + is real.
Why do I see %25 in my URL?
%25 is an encoded % sign. Seeing %2520 means text was encoded twice: the % of %20 was encoded again. Decode it twice, or better, find the place in your code that encodes an already-encoded value.
What does "isn't valid UTF-8" mean when decoding?
The % escapes describe bytes that don't form valid UTF-8 text, such as %E9 on its own. That usually means the text was encoded by an old system using Latin-1, where é is %E9; in UTF-8 it is %C3%A9.
Is my URL sent anywhere?
No. Encoding, decoding and the breakdown all run in your browser. That matters because URLs often carry tokens, email addresses and session ids.