All tools run in your browser — your files never leave your device.
All tools154

Developer & Security

URL Encoder & Decoder

Percent-encode and decode URLs and query strings.

What it does. URL encoding, also called percent-encoding, replaces characters that have a reserved meaning in a URL with a percent sign and their hexadecimal byte value — a space becomes %20, an ampersand becomes %26. This tool encodes and decodes both whole URLs and individual components, and parses query strings into a readable table.
Runs in your browserNothing uploadsNo signupWorks offline

How to use URL Encoder & Decoder

  1. Paste a URL or a value to encode, or paste an encoded string to decode.
  2. Choose component encoding for a single parameter value, or full-URI encoding for a complete URL.
  3. Use the query parser to break a URL into its parameters, edit them, and rebuild it.

What is the difference between encodeURI and encodeURIComponent?

This is the distinction that causes most URL bugs, and it comes down to which characters are treated as structural.

encodeURI assumes you are handing it a complete, valid URL and preserves the characters that give a URL its structure: : / ? # [ ] @ ! $ & ' ( ) * + , ; =. Use it on an entire URL you want to make safe for transport.

encodeURIComponent assumes you are handing it a single value that must survive being embedded inside a URL, and escapes everything except A-Z a-z 0-9 - _ . ! ~ * ' ( ). Use it on each parameter name and value individually.

Getting it backwards is how a redirect URL passed as a query parameter breaks: encode it with encodeURI and its own ? and & survive, so the outer URL now appears to have extra parameters.

What is the difference between encodeURI and encodeURIComponent?
CharacterencodeURIencodeURIComponent
space%20%20
&& (kept)%26
== (kept)%3D
?? (kept)%3F
// (kept)%2F
## (kept)%23
++ (kept)%2B

Why is my plus sign turning into a space?

Because two different encodings share the same syntax and disagree about the plus character.

In application/x-www-form-urlencoded — the format HTML forms submit and the format most query strings follow — a space is encoded as +, and a literal plus must be written %2B.

In RFC 3986 percent-encoding, a space is %20 and a plus is a literal plus.

So a URL containing ?q=C+++ means "C " to a form parser and "C+++" to a strict URI parser. When you are passing values that may contain a plus — phone numbers, math expressions, C++ — always encode it as %2B and the ambiguity disappears.

Do I need to encode non-English characters?

Technically yes, practically the browser handles it. RFC 3986 restricts URLs to a subset of ASCII, so any other character must be percent-encoded as its UTF-8 bytes. The word café becomes caf%C3%A9.

Modern browsers display the decoded form in the address bar, which makes it look as though non-ASCII URLs work natively. They do work, but the wire format is still percent-encoded, and that encoded form is what appears when a link is copied into an email, an analytics report, or a spreadsheet.

Domain names use a different mechanism entirely. Internationalized domains are encoded with Punycode, so münchen.de travels as xn--mnchen-3ya.de. This is also why homograph attacks are possible — Cyrillic and Latin letters that look identical produce different Punycode.

What is double encoding, and why does it break things?

Double encoding happens when an already-encoded string is encoded again. The percent sign is itself a character that needs encoding, so %20 becomes %2520.

The symptom is a URL that visibly contains %2520, %253A or %2526, and a server that returns a 404 for a path that clearly exists. It usually comes from a value being encoded by application code and then encoded again by a framework or an HTTP client.

This tool detects the pattern and warns when the input appears to be already encoded, so you can decode once before re-encoding.

Frequently asked questions

When should I use encodeURIComponent?

On every individual query parameter name and value, and on any path segment built from user input. Use encodeURI only on a complete URL.

What characters must always be encoded?

Space, and the reserved delimiters : / ? # [ ] @ ! $ & ' ( ) * + , ; = when they appear inside a value rather than as structure. Also the percent sign itself.

Why does my URL have %20 instead of spaces?

That is correct behavior — a raw space is not legal in a URL. Browsers display it as a space but transmit %20.

Is + the same as %20?

Only in form-encoded query strings. In a path, + is a literal plus character. Encode a literal plus as %2B to avoid the ambiguity entirely.

Should I encode the whole URL or just the parameters?

Just the parameters, individually, before assembling the URL. Encoding the whole thing escapes the structural characters you need.

Does URL encoding hide data?

No. It is a transport encoding, fully readable and trivially reversible. It provides no privacy.

Is my URL sent anywhere?

No. Encoding uses the native encodeURIComponent in this page.

Guides for URL Encoder & Decoder