URL encoder / decoder
Percent-encode text for a query string or a path, decode it back, and see the difference between encoding one component and encoding a whole URL.
Plain text
Whatever you paste stays in this tab. The work is done by JavaScript in your browser. None of it is uploaded, logged or saved, and the tool keeps working with the network off.
Which rules?
Picking the wrong one is quiet: the output looks plausible either way and only breaks once a value happens to contain an ampersand, a slash or a plus.
Encoded
The result appears here as you type.
Three jobs, one name
“URL encoding” covers three different sets of rules, and choosing the wrong one produces output that looks right and breaks later, when a value happens to contain a character that matters.
- A single value. One parameter, one path segment, one cookie value. Escapes
/ ? & = #as well, because inside a value those are data, not structure. This isencodeURIComponent. - A whole URL. An address that is already assembled. Leaves the structural characters alone and escapes only what cannot appear literally, such as spaces. This is
encodeURI. - A form field. What a browser posts and what most HTTP libraries build for a form body. Almost the same as a single value, except a space becomes
+.
The plus sign, which costs people hours
In form encoding a space is written + and a real plus is written %2B. Everywhere else, + is just a plus. Decode a value with the wrong rules and a phone number like +44 7700 900000 arrives as 44 7700 900000, the leading plus silently gone.
It is worth knowing which end produced the value. A query string built by a browser form will use +; one built by hand or by most APIs will use %20. Both decoders here are exact about it rather than guessing.
Double encoding
If a decoded result still has %20 visible in it, the value was encoded twice, a percent sign became %25, so a%20b became a%2520b. Decode it again. This happens whenever a value passes through two layers that each helpfully encode it, and the symptom is unmistakable once you know it.
It runs in your browser
Both directions use the platform’s own functions, on this page, with no request made. That matters here because query strings are where session tokens, signed parameters, email addresses and redirect targets live, the sort of thing that should not be pasted into somebody else’s server to be tidied up.
Paste a complete URL and it is also taken apart: scheme, host, path and every query parameter with its value already decoded. A parameter carrying an encoded URL of its own becomes readable, which is usually the thing you wanted in the first place.
Questions
What is the difference between encoding a value and encoding a whole URL?
Why is a space sometimes %20 and sometimes +?
Why did the plus sign in my data turn into a space?
Is anything I paste here sent to a server?
What does "URI malformed" mean?
Why can it decode the escapes but still refuse?
What is double encoding?
Why does it show me the query parameters?
More tools
JSON formatter & validator
Indent it, shrink it, or find out what is wrong with it
Base64 encoder / decoder
Both directions, both alphabets, Unicode included
Robots.txt tester
See which rule a crawler actually applies