URL Encode / Decode
Encode or decode URL components and query strings online. Handles percent-encoding instantly in your browser. Free, no sign-up.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Examples
All outputs below come from the tool’s encode and decode functions, which give the same results as the browser built-ins encodeURIComponent and decodeURIComponent.
| Mode | Input | Output |
|---|---|---|
| Encode | https://example.com/search?q=café & tea#top | https%3A%2F%2Fexample.com%2Fsearch%3Fq%3Dcaf%C3%A9%20%26%20tea%23top |
| Encode | 東京 2026 | %E6%9D%B1%E4%BA%AC%202026 |
| Encode | 😀 | %F0%9F%98%80 |
| Encode | Zoë O'Brien (admin)!*~ | Zo%C3%AB%20O'Brien%20(admin)!*~ |
| Decode | a%2Bb | a+b |
| Decode | a+b%20c | a+b c |
The first row shows what this tool is for: the whole address becomes one opaque value. That is what you want when a URL is itself
a parameter, for example ?redirect=https%3A%2F%2Fexample.com%2Fsearch%3Fq%3D…. If you encode a complete address
that you plan to open, the : and / separators are encoded too and the result is no longer a working link.
To clean up a full URL instead, encode each query value on its own and join them with &, or use the
URL Parser, which shows every part of an address and lets you edit query values.
Non-ASCII text is converted to UTF-8 first, so one character can become two to four %XX groups: é is
two bytes, 東 three, and the emoji four. Encoding twice turns each % into %25
(a b → a%20b → a%2520b). If you see %25 in a link, a value was encoded one
time too many.
Differences from Other Encoders
- Characters left as they are. RFC 3986 section 2.3 lists only letters, digits and
- . _ ~as unreserved.encodeURIComponentalso leaves! ’ ( ) *unencoded (fourth example). Most servers accept them, but some request-signing schemes (OAuth 1.0 signatures, AWS Signature Version 4) require them as%21 %27 %28 %29 %2A. Encode those five by hand when a signature check fails. - Spaces become
%20, not+, unless you choose form data. HTML forms andURLSearchParamswrite a space as+(WHATWG URL Standard, application/x-www-form-urlencoded). By default this tool’s decoder only reverses%XX, so a+stays a plus sign (last example). With Space as + (form data) on, encoding followsURLSearchParams:a b+cbecomesa+b%2Bc, and! ’ ( ) ~are encoded too. Decoding then reads+as a space:a+b%20cbecomesa b c.
Limitations
- Decoding stops at the first problem and names its position:
100%givesPosition 4: "%" must be followed by two hexadecimal digits ("%")., and%C4%E3(GBK bytes) givesPosition 1: %C4%E3 is not valid UTF-8. Text saved in GBK, Shift_JIS or EUC-KR cannot be decoded here.Only UTF-8 is supported, as in RFC 3986 section 2.5 for new URI schemes. A few legacy byte runs happen to be valid UTF-8 and decode to other characters without a warning: GBK%C4%A3(模) decodes toģ. - Encoding stops at a lone UTF-16 surrogate, which can appear when a string is cut in the middle of an emoji.
- There is no
encodeURImode, which leaves; , / ? : @ & = + $ #unencoded for a whole URL.
FAQ
What is URL encoding?
URL encoding (percent-encoding, RFC 3986 section 2.1) writes a character as '%' followed by two hex digits for each of its UTF-8 bytes. A space becomes %20, '&' becomes %26 and 'é' becomes %C3%A9.
What is the difference between encodeURI and encodeURIComponent?
encodeURI is meant for a whole URL and leaves the separators ; , / ? : @ & = + $ # unencoded. encodeURIComponent is meant for one part, such as a query value, and encodes those separators too. Both leave letters, digits and - _ . ! ~ * ' ( ) unencoded. This tool uses encodeURIComponent.
Why does decoding leave + signs in the output?
decodeURIComponent only reverses %XX sequences. The + for space comes from HTML form encoding (application/x-www-form-urlencoded), not from percent-encoding, so a+b decodes to a+b by default. Turn on Space as + (form data) to read + as a space, as URLSearchParams does.
Why does decoding fail?
Either a % is not followed by two hex digits (100%, %zz), or the bytes are not valid UTF-8: a cut-off sequence such as %E4%B8, or GBK or Shift_JIS bytes such as %C4%E3. The error message gives the position and the part that failed.
Why does my link contain %25?
%25 is an encoded % sign. It appears when a value that was already percent-encoded is encoded again: a b becomes a%20b, and a second pass turns that into a%2520b. A server that decodes once then gets a%20b instead of a b. Paste the value into Decode once to see the previous step, and find where the extra encoding happens.
Is my data sent to any server?
No. The conversion runs in your browser with JavaScript's built-in encodeURIComponent and decodeURIComponent. The last input is kept in this browser's local storage so it is still there when you come back; Clear removes it.