LocalDevTools

URL Encode / Decode

Percent-encode text for safe use in URLs and query strings, decode encoded links back to readable text, and inspect every part of a URL including its query parameters.

Runs entirely in your browser. Your input is never uploaded or stored on a server.

How to URL-encode or decode

  1. Paste text or a URL into the input box.
  2. Choose a mode. Component encodes everything except letters, digits and - _ . ! ~ * ' ( ). Use it for a single query value or path segment. Full URL leaves URL structure characters like : / ? # & = alone and only encodes spaces and non-ASCII characters.
  3. Tick Spaces as + when building or reading application/x-www-form-urlencoded data, as sent by HTML forms.
  4. Click Parse URL to see the protocol, host, port, path, hash and a decoded table of query parameters.

encodeURIComponent vs encodeURI

This is the most common source of broken links. Suppose you put a search term into a query string:

const term = "rock & roll";
"https://example.com/?q=" + encodeURI(term)
// https://example.com/?q=rock%20&%20roll   ✗  "&" starts a new parameter
"https://example.com/?q=" + encodeURIComponent(term)
// https://example.com/?q=rock%20%26%20roll   ✓

Rule of thumb: encode each value with encodeURIComponent, then join them. Only use encodeURI for a complete URL that someone typed with spaces or accents in it. In modern code, URLSearchParams and new URL() handle this for you.

Examples

Hello World!        →  Hello%20World!
café                →  caf%C3%A9          (UTF-8 bytes C3 A9)
a+b=c&d             →  a%2Bb%3Dc%26d
https://x.io/a b    →  https://x.io/a%20b   (Full URL mode)

%20 or +?

Both can mean a space, but in different places. In the query string of form submissions, + means space. In a path, + is a literal plus sign and a space must be %20. If a decoded value shows plus signs where there should be spaces, tick Spaces as + and decode again.

Frequently asked questions

What is percent-encoding?

A way to represent characters that are not allowed in URLs. Each byte becomes % followed by two hex digits. Non-ASCII characters are first converted to UTF-8, so é becomes %C3%A9.

Why do I get "URI malformed" when decoding?

The input contains a % that is not followed by valid hex digits, or a byte sequence that is not valid UTF-8. A literal percent sign must be encoded as %25. The tool shows where the problem is.

Should I encode the whole URL or just parts of it?

Just the parts. Encode each path segment and each query value separately with component mode. Encoding a full URL in component mode would also encode the :// and /, breaking it.

Is my URL sent anywhere?

No. Encoding, decoding and parsing all use built-in browser functions on your device.

Does it decode URLs that were encoded twice?

Click Decode again. Double-encoded text contains %25, which decodes to % on the first pass.

Related tools

Last updated: