Encode · Decode · Parse

URL Encoder / Decoder

Encode URLs for safe transmission, decode percent-encoded strings, or parse query parameters: instantly, no signup required.

Last updated

URL Encoding & Decoding
Query String Parser
Component & Full URL Modes
No Signup
Our networkLegalCost.usWhat will your legal case cost?Official formulas for all 50 states. Free, no signup.Check your state
%20
URL Encoder / Decoder
Percent-Encoding · Query String Parser
Output will appear here...

What is URL Encoding?

URL encoding replaces each unsafe character with % and the two hex digits of its UTF-8 bytes: a space becomes %20, & becomes %26 and é becomes %C3%A9. Encode mode here works like JavaScript's encodeURIComponent, Decode reverses it (reading + as a space), and Parse splits a full URL into its parts. It all runs in your browser.

URL encoding (percent-encoding) converts characters that aren't safe in URLs into a percent sign followed by two hexadecimal digits. URLs can only safely contain a limited set of ASCII characters: anything else must be encoded.

For example, a space becomes %20, an ampersand becomes %26, and the question mark becomes %3F.

Three Modes Explained

URL Encode

Converts special characters into percent-encoded format safe for URLs. Uses encodeURIComponent(), which encodes everything except A-Z, a-z, 0-9 and the marks - _ . ! ~ * ' ( ).

URL Decode

Converts percent-encoded strings back to readable text. Also handles + signs as spaces (used in form submissions). Paste any encoded URL to see the original content.

Query String Parser

Breaks a full URL into its components: protocol, host, path, and each query parameter as a separate key-value pair. Essential for debugging API calls and web analytics URLs.

%20 vs + for Spaces

%20 works everywhere in a URL. The + sign represents a space only in query strings (HTML form format). In the path portion of a URL, + is a literal plus sign. Use %20 when in doubt.

encodeURIComponent vs encodeURI Side by Side

Three encoders, three different results. Form encoding is what HTML forms and URLSearchParams produce for query strings.

InputencodeURIComponentencodeURIForm encoding
hello worldhello%20worldhello%20worldhello+world
a+b=ca%2Bb%3Dca+b=ca%2Bb%3Dc
C++ & C#C%2B%2B%20%26%20C%23C++%20&%20C#C%2B%2B+%26+C%23
50% off50%25%20off50%25%20off50%25+off
café?caf%C3%A9%3Fcaf%C3%A9?caf%C3%A9%3F
/path/to file.pdf%2Fpath%2Fto%20file.pdf/path/to%20file.pdf%2Fpath%2Fto+file.pdf
!'()*!'()*!'()*%21%27%28%29*

The rule of thumb: use encodeURIComponent for a single value you are putting into a query string or path segment, and encodeURI only to clean up a complete URL whose structure (/ ? & = #) must survive. The last row shows that encodeURIComponent leaves ! ' ( ) and * alone; a few strict APIs, such as OAuth 1.0 signatures, need them as %21 %27 %28 %29 %2A.

Common Characters and Their Percent Codes

CharacterEncodedWhy it needs encoding in a value
space%20 (or + in a query string)Not allowed anywhere in a URL
&%26Separates query parameters
=%3DSeparates a key from its value
?%3FStarts the query string
#%23Starts the fragment; the browser never sends what follows
+%2BRead as a space in form-encoded queries
/%2FSeparates path segments
%%25Starts every escape, so a literal % must be escaped too
é%C3%A9Non-ASCII: two UTF-8 bytes
€%E2%82%ACNon-ASCII: three UTF-8 bytes
😀 (emoji)%F0%9F%98%80Non-ASCII: four UTF-8 bytes

Common URL Encoding Mistakes

Encoding twice

Encoding an already encoded string escapes the % signs: %20 becomes %2520. If you see %25 followed by two hex digits in a URL, something encoded it twice. Decode once, then encode once at the point where the value enters the URL.

Leaving + in a value

A search for "a+b" sent as ?q=a+b arrives on the server as "a b", because form decoding reads + as a space. Encode the value and it travels as a%2Bb.

Using encodeURIComponent on a whole URL

It turns https:// into https%3A%2F%2F and the link stops working. Encode only the parts you insert, or use encodeURI for the whole address.

A stray percent sign

"100%" on its own is not valid encoding, and neither is a UTF-8 sequence cut in half such as %E4%BD. Both make decodeURIComponent throw "URI malformed", and the Decode tab shows an error. Write a literal percent sign as %25.

Encoding binary data for a URL is a different job; for that, URL-safe Base64 is usually shorter than percent-encoding every byte.

Method and sources. Percent-encoding and the reserved and unreserved character sets follow RFC 3986 (URI Generic Syntax). The + for space rule comes from the application/x-www-form-urlencoded format in the WHATWG URL Standard. JavaScript behavior follows ECMAScript encodeURIComponent and encodeURI. Every value in the tables was produced with those functions in Node.js.

Frequently Asked Questions

URL encoding (percent-encoding) converts characters that aren't allowed or have special meaning in URLs into a safe format. A URL can only contain a limited ASCII character set. Characters like spaces, accented letters, or symbols (&, ?, =, #) must be encoded as a percent sign followed by two hex digits representing the character's byte value. For example, a space becomes %20, and & becomes %26. This ensures URLs are transmitted correctly across the internet.

encodeURI() encodes a complete URL, it leaves characters that have structural meaning in URLs (/, :, ?, #, &, =) unencoded. encodeURIComponent() encodes a URL segment (like a parameter value): it encodes nearly everything including /, ?, &, and =. Use encodeURIComponent() when encoding individual query parameter values, and encodeURI() when encoding an entire URL. This tool uses encodeURIComponent() for the Encode mode.

Both represent spaces, but in different contexts. %20 is the standard percent-encoding for a space and works everywhere in a URL. The + sign represents a space only in query strings (the part after the ?), as per the application/x-www-form-urlencoded format used by HTML forms. In the path portion of a URL, + is a literal plus sign, not a space. When in doubt, use %20: it is unambiguous and works universally.

In Python 3, use the urllib.parse module: from urllib.parse import quote, urlencode. To encode a string: quote('hello world') returns 'hello%20world'. quote() keeps slashes by default (safe='/'); use quote(string, safe='') to encode them as %2F too. To encode query parameters: urlencode({'q': 'hello world', 'page': 1}) returns 'q=hello+world&page=1'. For decoding: unquote('hello%20world') returns 'hello world'.

RFC 3986 defines unreserved characters that are safe in URLs without encoding: letters A-Z and a-z, digits 0-9, hyphen (-), underscore (_), period (.), and tilde (~). Reserved characters like /, ?, #, &, =, :, @, !, $, (, ), *, +, and ; have special meaning in URL structure and must be encoded if used as data values. Any character outside ASCII must be UTF-8 encoded first, then percent-encoded.

The modern way is new URLSearchParams(window.location.search). To get a specific parameter: params.get('q'). To iterate all parameters: for(const [key, val] of params). For a full URL: const url = new URL('https://example.com?q=test'); url.searchParams.get('q'). In older code you may see manual splitting on & and =, but URLSearchParams handles encoding/decoding automatically and is the recommended approach.

Non-ASCII characters must first be encoded as UTF-8 bytes, then each byte is percent-encoded. The Chinese character 你 (U+4F60) encodes to UTF-8 bytes E4 BD A0, resulting in %E4%BD%A0. Modern browsers and encodeURIComponent() handle this automatically. International domain names (IDN) use Punycode: 例え.jp becomes xn--r8jz45g.jp. This tool correctly handles Unicode characters in both encode and decode modes.

Use encodeURI() (not encodeURIComponent) to encode an entire URL. It leaves the structural characters, scheme (https://), path slashes, ?, &, and =, intact, while encoding any spaces or special characters within values. If you need to embed one URL as a parameter inside another URL, encode the inner URL with encodeURIComponent() so its ? and & characters don't interfere with the outer URL's structure.

Differences arise because there are multiple encoding standards. encodeURIComponent() encodes everything except letters, digits and - _ . ! ~ * ' ( ), which is slightly less than RFC 3986 reserves (it treats ! ' ( ) * as reserved). Older tools may encode more characters. The case of hex digits (uppercase %2F vs lowercase %2f) varies: both are valid. Using + vs %20 for spaces depends on the encoding standard (form encoding vs standard URI encoding). This tool uses JavaScript's encodeURIComponent() for maximum compatibility with modern APIs and browsers.

A query string is the part of a URL after the ? character, containing key=value pairs separated by &. UTM parameters are standardized query parameters used by Google Analytics to track marketing campaigns: utm_source (where traffic comes from), utm_medium (marketing channel), utm_campaign (campaign name), utm_content (specific ad), and utm_term (paid keyword). Use the Parse tab above to break down any URL containing UTM parameters into its individual tracking components.

The string was encoded twice. The first pass turns a space into %20; the second pass encodes the % sign itself as %25, giving %2520. Find where the value is encoded a second time, often a framework or HTTP library that encodes query values for you, and remove your own encoding step.

decodeURIComponent throws that error when a % is not followed by two hex digits, as in "100%", or when the decoded bytes are not valid UTF-8, as with a cut sequence like %E4%BD. Fix the source: a literal percent sign must be written as %25, and multi-byte characters must keep all their bytes.