URL Encoder & Decoder
Percent-encode text for a URL or decode it back, choosing between a single component, a whole URL, and form data where a space is a plus.
search%3Fq%3Dcoffee%20%26%20cake
Output is valid and updates as you type.
Fix the highlighted fields to update the output.
Percent-encode text for a URL, or decode it back. Pick the scope that matches where the value is going: one parameter, a whole URL, or a form body.
How to use
- Use “component” for a single value, such as a query parameter or a path segment. It encodes everything that has meaning in a URL, including
&,=,?and/. - Use “full URL” when the input is already a URL and you only want the unsafe characters fixed. It leaves the structure alone.
- Use “form data” for a
application/x-www-form-urlencodedbody, where a space is+rather than%20. - Turn on the strict option when the value goes somewhere old or fussy:
!,',(,)and*are reserved in RFC 3986 but left alone by the browser’s own function. - Decoding uses the same scope, so form data decodes
+back to a space.
Example
The same string in each scope:
Input: https://example.com/a b?q=1&r=2
Component: https%3A%2F%2Fexample.com%2Fa%20b%3Fq%3D1%26r%3D2
Full URL: https://example.com/a%20b?q=1&r=2
Encoding a whole URL as a component is right when you are putting it inside another URL, such as a redirect parameter, and wrong everywhere else.
Pitfalls
- Encoding a full URL with the component scope by mistake gives you a link that no longer works, because the slashes and the question mark are gone.
- A space is
%20in a URL and+in form data. Mixing them up is the usual cause of a stray plus sign in a search term. - Encoding twice turns
%20into%2520. Once decoded you get%20back as literal text, which is where double encoded URLs come from. encodeURIComponentleaves!,',(,)and*alone. That is legal but not what every parser expects.- A
%not followed by two hex digits is not valid percent encoding, and decoding it fails rather than passing it through. - Non-ASCII is encoded as UTF-8 bytes, so one accented character becomes two escapes. Older systems that assumed Latin-1 produce different, incompatible output.
- The fragment after
#is never sent to the server. Encoding it does not make it private. - Decoding untrusted input can reveal characters your code assumed were escaped. Validate after decoding, not before.
Compatibility
The output follows RFC 3986 for URLs and the WHATWG URL Standard for form data. Encoding uses UTF-8, which every browser has used since IE 6 was current. The tool runs entirely in your browser and handles inputs up to about a megabyte.
Frequently asked questions
When do I use component and when do I use full URL?
Why is my space a plus sign?
%20 is correct outside a form body.What is double encoding?
%20 becomes %2520, and the consumer sees the literal text %20 instead of a space.