How to encode or decode a URL
- Choose Encode or Decode.
- Choose what you have. Use Component for one piece of a URL, such as a search term or a parameter value. Use Full URL for a whole address that you want to keep working.
- Tick "Space as +" for HTML form data (
application/x-www-form-urlencoded), where a space is written as+. - Copy the result, or click Swap to check it decodes back to your original.
The tool runs locally in your browser. URLs often carry session tokens and personal data, and nothing you paste is sent anywhere or saved.
What is percent-encoding?
A URL may contain only a limited set of ASCII characters. Any other character is first converted to UTF-8 bytes, and each byte is written as % followed by two hex digits. A space becomes %20. The letter "é" is two bytes in UTF-8, so it becomes %C3%A9. The rupee sign "₹" is three bytes: %E2%82%B9.
Worked example
To search for chai & samosa, the value is encoded as a component:
chai & samosa → chai%20%26%20samosa https://example.com/search?q=chai%20%26%20samosa
Without encoding, the & would end the q parameter and start a new one called samosa.
encodeURIComponent vs encodeURI
| Component mode (encodeURIComponent) | Full URL mode (encodeURI) | |
|---|---|---|
| Use for | One value: a query parameter, a path segment | A complete URL that is already structured |
| Leaves alone | A–Z a–z 0–9 - _ . ! ~ * ' ( ) | The same, plus ; , / ? : @ & = + $ # |
a/b?c=d&e becomes | a%2Fb%3Fc%3Dd%26e | a/b?c=d&e |
The common mistake is to use full-URL mode on a value. A value that contains & or = then breaks the query string. When in doubt, encode each value as a component and then join the pieces.
Common percent-encodings
| Character | Encoded | Character | Encoded |
|---|---|---|---|
| Space | %20 (or + in forms) | & | %26 |
! | %21 | ' | %27 |
" | %22 | + | %2B |
# | %23 | , | %2C |
$ | %24 | / | %2F |
% | %25 | : | %3A |
= | %3D | ; | %3B |
? | %3F | @ | %40 |
[ ] | %5B %5D | { } | %7B %7D |
| Line feed | %0A | é | %C3%A9 |
Decoding errors
Decoding fails in two cases, and the tool tells you which one and where:
- A stray %.
100%or%G1is not a valid escape. A literal percent sign must be written%25. - Bytes that aren't UTF-8.
%E9on its own was "é" in the old Latin-1 character set, but it is not valid UTF-8. Some old systems still produce it.
Tips
- Don't encode twice. If you see
%2520, a%20was encoded again. Decode twice to recover the text. - Plus or %20? In a query string from an HTML form,
+means a space. In a path,+is a literal plus. Use the "Space as +" option only for form data. - Base64 in URLs should use the URL-safe alphabet. See the Base64 encoder.
Frequently asked questions
What does %20 mean in a URL?
+.When should I use encodeURIComponent instead of encodeURI?
encodeURIComponent for any single value you put into a URL, such as a query parameter. Use encodeURI only on a complete URL, because it leaves / ? & = # unencoded.Why do I get "URI malformed" when decoding?
% that isn't followed by two hex digits, or the bytes aren't valid UTF-8. This tool shows the position of the problem. Replace a literal % with %25.Does the URL parser decode parameter values?
+ treated as a space, as browsers do for query strings. Repeated keys are listed once per occurrence.Is my URL sent to a server?
Last updated . How we check our tools.