URL encode and decode

Percent-encode text so it's safe in a URL, decode %20-style escapes back to text, and break a full URL into a table of its query parameters.

  • 100% free
  • Runs in your browser
  • No uploads
Direction
Encode as

Like encodeURIComponent: escapes everything except letters, digits and - _ . ~, so the text is safe as one query value or path segment.

Break down a URL and its query string

How to URL encode or decode

  1. Choose Encode or Decode. The result updates as you type.
  2. Pick how to encode. Value for a query value or path segment, Full URL for a whole address, Form (+) for + instead of %20.
  3. Copy the result. Decode this or Encode this sends the result back to the input to go the other way.
  4. Break down a URL. Paste any address below the tool to see its host, path and each query parameter decoded, including repeated keys.

How percent-encoding works

URLs may only contain a limited set of ASCII characters. Anything else is turned into UTF-8 bytes, and each byte is written as % plus two hex digits. A space is byte 20 in hex, so it becomes %20; é is the two bytes C3 A9, so it becomes %C3%A9; an emoji takes four bytes and twelve characters.

Letters, digits and - _ . ~ are never encoded. Characters with a job in URLs, such as ? & = / #, are encoded only when they are part of a value. The Value mode here also encodes ! ' ( ) *, which encodeURIComponent leaves alone but some servers and email clients mishandle.

Common URL encodings

CharacterEncodedNote
space%20 or ++ only in form-encoded query strings
&%26Otherwise starts a new parameter
=%3DOtherwise splits key and value
?%3FOtherwise starts the query string
#%23Otherwise starts the fragment
/%2FOnly inside a value
+%2BSo it isn't read as a space
%%25The escape character itself
é%C3%A9Two UTF-8 bytes
€%E2%82%ACThree UTF-8 bytes

Tips and common mistakes

  • Encode values, not the whole URL. Build the address from parts and encode each value on its own. In JavaScript, new URLSearchParams({ q: "a&b" }) does it for you.
  • Don't encode twice. If a library already encodes parameters, passing it an encoded string gives %2520 instead of %20.
  • Repeated keys are allowed. color=red&color=black is valid; how a server reads it varies, so check your framework.

Frequently asked questions

What's the difference between encodeURI and encodeURIComponent?

encodeURI is for a whole address: it leaves the characters that give a URL its structure, such as : / ? # & and =, alone. encodeURIComponent is for one piece, such as a search term or a value inside a query string, and escapes those characters too. Using encodeURI on a value is a common bug: an & in the value then splits it into two parameters.

Should a space be %20 or +?

Both are seen. %20 works everywhere in a URL. + means a space only in the query string of HTML form submissions (application/x-www-form-urlencoded); in a path, + is a literal plus sign. When decoding, tick Treat + as a space for query strings, and untick it for paths or values where + is real.

Why do I see %25 in my URL?

%25 is an encoded % sign. Seeing %2520 means text was encoded twice: the % of %20 was encoded again. Decode it twice, or better, find the place in your code that encodes an already-encoded value.

What does "isn't valid UTF-8" mean when decoding?

The % escapes describe bytes that don't form valid UTF-8 text, such as %E9 on its own. That usually means the text was encoded by an old system using Latin-1, where é is %E9; in UTF-8 it is %C3%A9.

Is my URL sent anywhere?

No. Encoding, decoding and the breakdown all run in your browser. That matters because URLs often carry tokens, email addresses and session ids.

Learn more