$ SudoStuff

URL Encoder / Decoder

Percent-encode URLs and query strings correctly.

Direction

Processed locally in your browser. Nothing you type here is sent to our servers.

What is URL encoding?

URLs may only contain a limited set of ASCII characters. Everything else — spaces, accented letters, emoji, and the characters that give a URL its structure like ?, &, / and # — must be percent-encoded when it appears inside a value rather than as syntax.

Each byte becomes a % followed by two hexadecimal digits. A space becomes %20; é is two UTF-8 bytes and becomes %C3%A9.

Component or full URI: pick the right one

This is the distinction that causes most URL-encoding bugs.

  • Component escapes everything reserved, including /, ?, &, = and :. Use it for a single piece of a URL — one query parameter value, one path segment. This is what you want almost every time.
  • Full URI leaves the structural characters alone and escapes only what is never legal, such as spaces. Use it to clean up a complete URL you want to remain a working URL.

Encoding a whole URL with component rules produces a string that is safe to embed as a value — for a redirect_uri, say — but is no longer a usable link. That is correct behaviour, and usually the intent.

How to use it

  1. Choose Encode or Decode.
  2. Pick the rules to apply.
  3. Type or paste — the result updates live.
  4. When the input parses as a URL, a breakdown of its parts and query parameters appears below.

Common use cases

  • Building a query string by hand and getting the escaping right.
  • Reading an OAuth redirect_uri that has been encoded twice.
  • Working out which parameters a long tracking URL actually carries.
  • Decoding a percent-encoded path from a server log.

Limitations

  • A space in a query string may legitimately be either %20 or +, depending on whether the form-encoding rules apply. This tool produces %20, which is valid everywhere; decoding treats a literal + as a plus sign, not a space.
  • Double-encoded text needs to be decoded twice. Use Use output as input and decode again.
  • Internationalised domain names are not converted to Punycode; only the parts of the URL that require percent-encoding are touched.
  • The URL breakdown masks any password in the URL rather than displaying it.
↑↓ navigate ↵ open esc close