Skip to content

Runs entirely in your browser. Nothing you paste leaves this page.

Free / No sign-up

URL encoder and decoder: percent-encoding online.

Percent-encode text or whole URLs, decode them back with clear errors, and break any query string into a clean table of parameters.

Direction
What you are encoding

Encoded

https%3A%2F%2Fnexzem.com%2Fsearch%3Fq%3Dnext.js%20%26%20react%26page%3D2

Query string parameters

https://nexzem.com/search

q
next.js
Raw: q=next.js%20
react
(empty)
Raw: %20react
page
2
Raw: page=2

Component mode (encodeURIComponent) also escapes / ? & = #: use it for a single query value or path segment.

How to use it.

  1. 01

    Choose Encode or Decode, then Component for a single value or Full URL for a whole address.

  2. 02

    Type or paste. The result updates as you go and can be copied in one click.

  3. 03

    Read every query parameter, decoded, in the table underneath, or copy them as JSON.

What it does.

Everything this tool handles, all of it inside your browser tab.

  • Encode and decode in one place, updating as you type
  • Component mode (encodeURIComponent) and Full URL mode (encodeURI)
  • UTF-8 percent-encoding for any language and emoji
  • Treats + as a space when decoding, as form-encoded query strings expect
  • Clear error that points at a malformed % sequence
  • Query string table with each key, decoded value and raw value, repeated keys kept in order
  • Base URL and fragment shown separately
  • Copy the result, or copy all parameters as JSON
  • Runs locally in your browser

Worked examples.

  • URL encode spaces and an ampersand

    Input:      app cost & more
    Component:  app%20cost%20%26%20more

    Spaces become %20 and & becomes %26, so the value cannot be mistaken for the start of another parameter.

  • encodeURI vs encodeURIComponent on the same URL

    Input:               https://example.com/a?b=c
    encodeURI:           https://example.com/a?b=c
    encodeURIComponent:  https%3A%2F%2Fexample.com%2Fa%3Fb%3Dc

    Use the second form only when the whole URL is itself a value, for example ?redirect=https%3A%2F%2Fexample.com%2Fa%3Fb%3Dc.

  • Encode non-English text as UTF-8

    café menu      → caf%C3%A9%20menu
    ₹500 / नमस्ते  → %E2%82%B9500%20%2F%20%E0%A4%A8%E0%A4%AE%E0%A4%B8%E0%A5%8D%E0%A4%A4%E0%A5%87

    Each non-ASCII character becomes two to four bytes of UTF-8, each written as %XX. Arabic, Devanagari, Chinese and emoji all work the same way.

  • Encode a plus sign and a percent sign

    a+b=c     → a%2Bb%3Dc
    50% off   → 50%25%20off

    A raw + in a query string is read as a space, and a raw % starts an escape. Encode them as %2B and %25.

  • Parse a query string into parameters

    https://example.com/search?q=caf%C3%A9+menu&city=Dubai&tag=ai&tag=web
    
    q     café menu
    city  Dubai
    tag   ai
    tag   web

    The + in the query decodes to a space, %C3%A9 to é, and the repeated tag key is kept twice, in order.

  • Fix double URL encoding

    Encoded once:   caf%C3%A9%20menu
    Encoded twice:  caf%25C3%25A9%2520menu
    Decode twice →  café menu

    %25 is an encoded percent sign. Seeing %25 followed by two hex digits is the giveaway that a value was encoded twice.

What is URL encoding?

URL encoding, properly called percent-encoding, is how characters that are not allowed in a URL, or that have a special meaning there, are written safely. Each byte of the character's UTF-8 form becomes a percent sign followed by two hexadecimal digits: a space becomes %20, & becomes %26, é becomes %C3%A9 and the rupee sign ₹ becomes %E2%82%B9.

RFC 3986, the URI standard, defines unreserved characters that never need encoding: the letters A to Z and a to z, the digits 0 to 9, and - . _ ~. Reserved characters such as : / ? # [ ] @ ! $ & ' ( ) * + , ; = separate the parts of a URL, so they must be encoded whenever they appear inside a value rather than as structure. Everything else, including spaces, quotes, % itself and all non-ASCII text, is always encoded. Browsers follow the WHATWG URL Standard, which describes the same encoding in terms of how real browsers parse URLs.

encodeURI vs encodeURIComponent: which one should I use?

encodeURIComponent, the Component mode here, escapes everything except letters, digits and - _ . ! ~ * ' ( ). Because it also escapes / ? & = # and +, it is the right choice for one value you are placing into a URL: a search term, a path segment, a redirect URL passed as a parameter.

encodeURI, the Full URL mode, leaves the characters that give a URL its structure alone and escapes spaces, non-ASCII text and a few unsafe characters such as double quotes, angle brackets and %. Use it on a complete URL that you know is otherwise well formed.

Mixing them up causes two classic bugs. Encoding a whole URL with encodeURIComponent turns https:// into https%3A%2F%2F and breaks it. Encoding a value with encodeURI leaves its & and # unescaped, so a search for 'salt & pepper' silently becomes a parameter called pepper. In JavaScript, the URL and URLSearchParams APIs handle this for you and are usually the best way to build URLs.

How do you URL encode a space: %20 or +?

Both appear in the wild. In a URL path and in RFC 3986 a space is always %20. HTML form submissions use a separate format, application/x-www-form-urlencoded, in which spaces in the query string are written as +. URLSearchParams, PHP's urlencode, Python's quote_plus and Java's URLEncoder all produce that form style.

The catch is the literal plus sign. In form-encoded data + means space, so a phone number like +971 or an email address like name+tag@example.com is corrupted unless the plus is encoded as %2B. This decoder treats + as a space, matching how query strings are normally produced; encode real plus signs as %2B and they come back correctly.

Common URL encoding errors and how to fix them

Double encoding happens when already-encoded text is encoded again: %20 becomes %2520, because the % itself is encoded as %25. It usually means two layers of code each encoded the value. Decode until the text stops changing, then make sure only one layer encodes.

'URIError: URI malformed' or 'Malformed percent-encoding' means a % is not followed by two hex digits, or the bytes do not form valid UTF-8, such as a truncated %E0%A4. This tool points to the bad sequence. A literal percent sign must be written %25, so '50% off' encodes to 50%25%20off.

Full URL mode decodes with decodeURI, which deliberately leaves escapes for structural characters such as %2F, %3F, %23 and %26 untouched, because decoding them would change what the URL means. Use Component mode when you want everything decoded. International domain names are not percent-encoded at all: they use Punycode, so café.com is sent as xn--caf-dma.com.

URL encoding in Python, PHP, Java, Go and C#

Every language has its own functions, and they disagree about spaces. Python's urllib.parse.quote gives %20 and keeps / by default, while quote_plus gives + and is meant for form data. PHP's rawurlencode follows RFC 3986 with %20, and urlencode uses +. Java's URLEncoder.encode produces form encoding with +. Go has url.PathEscape for %20 and url.QueryEscape for +. In .NET, Uri.EscapeDataString is the equivalent of encodeURIComponent.

When two systems disagree about a value, compare their outputs here: Component mode shows the %20 style and the parameter table shows how a form-style query string is read by browsers and most servers. If you are moving binary data or tokens rather than text, Base64, usually its URL-safe variant, is the better fit.

Reading query strings, safely

Paste any URL and the table lists each parameter's key, its decoded value and the raw text exactly as it appeared. Repeated keys such as tag=ai&tag=web are kept in order, which is how frameworks build arrays. The base URL and the #fragment are shown separately; the fragment is never sent to the server. 'Copy as JSON' gives you an object to paste into a test, where a repeated key keeps its last value.

Encoding is not a security control. It makes text safe to place in a URL, but it does not stop cross-site scripting when the decoded value is later written into a page: that needs output escaping for HTML, attributes or JavaScript, plus validation on the server. Clean, readable URLs also help technical SEO, so prefer simple lowercase slugs with hyphens over long encoded strings. Everything on this page runs in your browser, so internal URLs and tokens stay on your device.

Where URL encoding goes wrong: redirects, signed URLs and UTM tags

OAuth redirect_uri values, signed URLs and campaign links are where encoding causes the most support tickets. A redirect_uri passed as a parameter of the authorisation URL must be encoded in Component mode, and after decoding it must match the registered value exactly, or the authorisation server rejects the request.

Signed URLs, such as pre-signed cloud storage links or webhook signatures computed over a query string, break if a proxy or library re-encodes a single character after signing, for example turning %7E back into ~ or a space from %20 into +. Sign the exact string you send and avoid re-encoding it later. For UTM tags, use lowercase values with hyphens so they never need encoding: analytics tools treat Spring%20Sale and spring-sale as different campaigns.

Questions, answered

Something else on your mind? Ask a consultant and get a reply within one business day.

What is URL encoding?

Also called percent-encoding: characters that are not allowed or have special meaning in a URL are replaced by % followed by two hex digits for each of their UTF-8 bytes. A space becomes %20 and é becomes %C3%A9.

How do I URL encode a space: %20 or +?

Use %20 in paths and whenever you follow RFC 3986. A + means space only in form-encoded query strings (application/x-www-form-urlencoded). Both decode to a space in a query string, but only %20 is safe everywhere.

Should I use encodeURI or encodeURIComponent?

encodeURIComponent for a single value inside a URL, encodeURI for a whole URL. When in doubt, build URLs with the URL and URLSearchParams APIs, which encode each part correctly for you.

Which characters need to be URL encoded?

Everything except letters, digits and - . _ ~ when it appears inside a value. Reserved characters such as / ? # & = + are left as they are only when they act as URL structure, and spaces, % and non-ASCII characters are always encoded.

Why does decoding fail with a malformed error?

A % must be followed by two hex digits that form valid UTF-8. A stray % or a truncated sequence such as %E0%A4 cannot be decoded. Encode a literal percent sign as %25.

What is double encoding and how do I fix it?

It is when encoded text is encoded again, turning %20 into %2520. Decode repeatedly until the text stops changing, then find the layer of code that encodes a second time and remove it.

Why does %2F stay encoded in Full URL mode?

Full URL mode uses decodeURI, which keeps escapes for structural characters such as %2F, %3F, %23 and %26, because decoding them would change the URL's meaning. Switch to Component mode to decode everything.

Is URL encoding the same as Base64 or encryption?

No. URL encoding only makes text safe to put in a URL and anyone can reverse it. Base64 turns bytes into text, and neither one hides or protects data; use encryption for that.

Does URL encoding prevent XSS or injection attacks?

Not on its own. It stops a value breaking the URL, but once the value is decoded and written into HTML or SQL it needs the right escaping or parameterised queries for that context.

Is my URL sent anywhere?

No. Encoding, decoding and parsing use your browser's built-in functions in this tab, so internal URLs, tokens and query strings stay on your device.

More free tools.

All tools

Need tooling like this inside your product?

We build internal tools, developer platforms and APIs. Tell us what your team keeps doing by hand.