URL Encode / Decode

Encode or decode URL components and query strings online. Handles percent-encoding instantly in your browser. Free, no sign-up.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
Encode percent-encodes one URL component with encodeURIComponent. It also encodes URL separators such as : / ? & = #. Decode reads UTF-8 percent-encoded bytes. Changing direction converts the current input immediately.
With Space as + on, encoding uses URLSearchParams form encoding: a b+c becomes a+b%2Bc, and ! apostrophe ( ) ~ are encoded too. Decoding reads + as a space. With it off, spaces become %20 and a literal + stays + when decoded.
Swap exchanges the two boxes and switches direction. It cancels a queued conversion and leaves the exchanged values in place. Editing the input or changing an option converts again.
Clear empties both boxes and the status, cancels queued conversion and saving, and removes the saved input. Ctrl/⌘+L does the same while focus is in the tool. Direction and the form-data option stay selected.
Results update 300 ms after typing stops. A lone UTF-16 surrogate cannot be encoded. Decoding reports the position of a malformed % escape or invalid UTF-8 bytes; GBK, Shift_JIS and EUC-KR are not supported. The last input is saved in this browser after 500 ms.
Copy copies the current output in full. If copying fails, select the output and copy it manually.
Read the full guide URL Encode / Decode Online: Percent Encoding Explained
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

Examples

All outputs below come from the tool’s encode and decode functions, which give the same results as the browser built-ins encodeURIComponent and decodeURIComponent.

ModeInputOutput
Encodehttps://example.com/search?q=café & tea#tophttps%3A%2F%2Fexample.com%2Fsearch%3Fq%3Dcaf%C3%A9%20%26%20tea%23top
Encode東京 2026%E6%9D%B1%E4%BA%AC%202026
Encode😀%F0%9F%98%80
EncodeZoë O'Brien (admin)!*~Zo%C3%AB%20O'Brien%20(admin)!*~
Decodea%2Bba+b
Decodea+b%20ca+b c

The first row shows what this tool is for: the whole address becomes one opaque value. That is what you want when a URL is itself a parameter, for example ?redirect=https%3A%2F%2Fexample.com%2Fsearch%3Fq%3D…. If you encode a complete address that you plan to open, the : and / separators are encoded too and the result is no longer a working link. To clean up a full URL instead, encode each query value on its own and join them with &, or use the URL Parser, which shows every part of an address and lets you edit query values.

Non-ASCII text is converted to UTF-8 first, so one character can become two to four %XX groups: é is two bytes, 東 three, and the emoji four. Encoding twice turns each % into %25 (a b → a%20b → a%2520b). If you see %25 in a link, a value was encoded one time too many.

Differences from Other Encoders

  • Characters left as they are. RFC 3986 section 2.3 lists only letters, digits and - . _ ~ as unreserved. encodeURIComponent also leaves ! ’ ( ) * unencoded (fourth example). Most servers accept them, but some request-signing schemes (OAuth 1.0 signatures, AWS Signature Version 4) require them as %21 %27 %28 %29 %2A. Encode those five by hand when a signature check fails.
  • Spaces become %20, not +, unless you choose form data. HTML forms and URLSearchParams write a space as + (WHATWG URL Standard, application/x-www-form-urlencoded). By default this tool’s decoder only reverses %XX, so a + stays a plus sign (last example). With Space as + (form data) on, encoding follows URLSearchParams: a b+c becomes a+b%2Bc, and ! ’ ( ) ~ are encoded too. Decoding then reads + as a space: a+b%20c becomes a b c.

Limitations

  • Decoding stops at the first problem and names its position: 100% gives Position 4: "%" must be followed by two hexadecimal digits ("%")., and %C4%E3 (GBK bytes) gives Position 1: %C4%E3 is not valid UTF-8. Text saved in GBK, Shift_JIS or EUC-KR cannot be decoded here. Only UTF-8 is supported, as in RFC 3986 section 2.5 for new URI schemes. A few legacy byte runs happen to be valid UTF-8 and decode to other characters without a warning: GBK %C4%A3 (模) decodes to ģ.
  • Encoding stops at a lone UTF-16 surrogate, which can appear when a string is cut in the middle of an emoji.
  • There is no encodeURI mode, which leaves ; , / ? : @ & = + $ # unencoded for a whole URL.

FAQ

What is URL encoding?

URL encoding (percent-encoding, RFC 3986 section 2.1) writes a character as '%' followed by two hex digits for each of its UTF-8 bytes. A space becomes %20, '&' becomes %26 and 'é' becomes %C3%A9.

What is the difference between encodeURI and encodeURIComponent?

encodeURI is meant for a whole URL and leaves the separators ; , / ? : @ & = + $ # unencoded. encodeURIComponent is meant for one part, such as a query value, and encodes those separators too. Both leave letters, digits and - _ . ! ~ * ' ( ) unencoded. This tool uses encodeURIComponent.

Why does decoding leave + signs in the output?

decodeURIComponent only reverses %XX sequences. The + for space comes from HTML form encoding (application/x-www-form-urlencoded), not from percent-encoding, so a+b decodes to a+b by default. Turn on Space as + (form data) to read + as a space, as URLSearchParams does.

Why does decoding fail?

Either a % is not followed by two hex digits (100%, %zz), or the bytes are not valid UTF-8: a cut-off sequence such as %E4%B8, or GBK or Shift_JIS bytes such as %C4%E3. The error message gives the position and the part that failed.

Why does my link contain %25?

%25 is an encoded % sign. It appears when a value that was already percent-encoded is encoded again: a b becomes a%20b, and a second pass turns that into a%2520b. A server that decodes once then gets a%20b instead of a b. Paste the value into Decode once to see the previous step, and find where the extra encoding happens.

Is my data sent to any server?

No. The conversion runs in your browser with JavaScript's built-in encodeURIComponent and decodeURIComponent. The last input is kept in this browser's local storage so it is still there when you come back; Clear removes it.