URL Encoder / Decoder
Percent-encode URLs and query strings correctly.
Something went wrong
| Key | Value |
|---|
Processed locally in your browser. Nothing you type here is sent to our servers.
What is URL encoding?
URLs may only contain a limited set of ASCII characters. Everything else — spaces,
accented letters, emoji, and the characters that give a URL its structure like
?, &, / and # — must be
percent-encoded when it appears inside a value rather than as syntax.
Each byte becomes a % followed by two hexadecimal digits. A space
becomes %20; é is two UTF-8 bytes and becomes
%C3%A9.
Component or full URI: pick the right one
This is the distinction that causes most URL-encoding bugs.
-
Component escapes everything reserved, including
/,?,&,=and:. Use it for a single piece of a URL — one query parameter value, one path segment. This is what you want almost every time. - Full URI leaves the structural characters alone and escapes only what is never legal, such as spaces. Use it to clean up a complete URL you want to remain a working URL.
Encoding a whole URL with component rules produces a string that is safe to embed as
a value — for a redirect_uri, say — but is no longer a usable link.
That is correct behaviour, and usually the intent.
How to use it
- Choose Encode or Decode.
- Pick the rules to apply.
- Type or paste — the result updates live.
- When the input parses as a URL, a breakdown of its parts and query parameters appears below.
Common use cases
- Building a query string by hand and getting the escaping right.
- Reading an OAuth
redirect_urithat has been encoded twice. - Working out which parameters a long tracking URL actually carries.
- Decoding a percent-encoded path from a server log.
Limitations
-
A space in a query string may legitimately be either
%20or+, depending on whether the form-encoding rules apply. This tool produces%20, which is valid everywhere; decoding treats a literal+as a plus sign, not a space. - Double-encoded text needs to be decoded twice. Use Use output as input and decode again.
- Internationalised domain names are not converted to Punycode; only the parts of the URL that require percent-encoding are touched.
- The URL breakdown masks any password in the URL rather than displaying it.