URL Parser

Split any URL into scheme, host, port, path, query and fragment with your browser's parser. See what it normalizes, where RFC 3986 differs, and edit params.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
Paste a URL to parse it as you type. A complete URL needs a scheme such as https://; relative links need a base URL. Parsing does not open the address or save the input.
Base URL (for relative links) Enter the full URL of the page that contains a relative link. The result follows new URL(link, base). Changes to either input update the result immediately.

The normalized URL, fields and decoded query parameters appear here as you type.

Read the full guide Parts of a URL: Scheme, Host, Port, Path, Query and Fragment
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

What the parser changes

Browsers do not take a URL literally. The WHATWG URL Standard strips spaces, deletes tabs and newlines, lowercases the host, converts international domains to Punycode, resolves . and .., removes default ports and percent-encodes some characters. The tool lists each change.

Paste https://user:pass@example.com:443/a/./b/../c?q=a+b&q=2&flag&x=%zz#frag and the normalized URL becomes https://user:pass@example.com/a/c?q=a+b&q=2&flag&x=%zz#frag. The notes say that port 443 was dropped because it is the default, that /a/./b/../c resolved to /a/c, and that the % at position 63 is not followed by two hex digits. Browsers keep that % as it is; decodeURIComponent() throws on it. The URL also carries a password. RFC 3986 §3.2.1 deprecates the user:password form and says applications should not show what follows the colon in clear text, so the password field is masked until you press Show.

The query table shows four parameters: q twice (a b, then 2), flag with no =, and x whose value stays %zz. The + is decoded as a space because query strings follow the application/x-www-form-urlencoded rules, the same rules as URLSearchParams.

When the browser and your server disagree

Libraries on the server often follow RFC 3986 instead of the URL Standard, and a few inputs split differently. The tool compares the host it gets with the host from the RFC 3986 Appendix B regular expression and warns when they differ.

http://evil.example\@good.example/login is the classic case. For http, https, ws, wss, ftp and file URLs, the browser reads the backslash as a slash, so the host is evil.example and the path is /@good.example/login. RFC 3986 does not allow a backslash in a URI at all, and a parser that splits by Appendix B takes everything before the last @ as user info and reads the host as good.example. On 2026-10-01, Python 3.12’s urllib.parse.urlsplit() returned the hostname good.example, curl 8.7.1 sent Host: good.example, and Go 1.27’s net/url refused the URL with invalid userinfo. If one component checks the host and another fetches the URL, the request can reach a host that was never approved.

The same applies to IPv4 shorthand. http://0x7f.1/admin is http://127.0.0.1/admin to a browser, because the URL Standard’s IPv4 parser accepts hexadecimal, octal and shortened forms. RFC 3986 treats 0x7f.1 as a host name.

Two more cases come up often. localhost:3000/api parses without an error, but as the scheme localhost: with the path 3000/api and no host, so a fetch built from it fails in a confusing way; the tool offers to parse it as https://localhost:3000/api. And https://раураl.com/signin looks like a familiar brand, but the browser sends xn--l-7sba6dbr.com, and the tool reports that the label раураl mixes Cyrillic and Latin letters, the pattern Unicode UTS #39 and Chrome’s IDN policy treat as a look-alike.

Editing without side effects

A tool that rebuilds the query with URLSearchParams.toString() re-encodes every pair, so the URL changes even when you edit nothing: flag becomes flag=, %zz becomes %25zz, and an invalid UTF-8 escape such as %E4%B8 becomes %EF%BF%BD. This tool keeps each untouched pair as it was and encodes only the pair you change. Field edits go through the browser’s own setters (url.port = …), so you get the result the browser accepts, with a note when it rejects or trims a value.

How it compares

On 2026-10-01 we pasted the same eight URLs into the tools at the top of Bing’s results for “url parser”. codeshack.io showed evil.example for the backslash URL, 127.0.0.1 for 0x7f.1 and localhost: as a protocol without any remark, and showed empty fields for example.com/path without an error. Tooltada (Korean) offers query editing, but its rebuilt URL turned flag into flag= and %E4%B8 into %EF%BF%BD before any edit. Web ToolBox (Japanese) reported example.com/path only as “無効なURLです” (invalid URL). Their fields match the browser’s URL parser, as this tool’s do; the difference is that this tool explains what the parser did and where an RFC 3986 parser would read the URL differently.

Limits

  • The result is your browser’s. Node.js 24 passes 888 of the 896 parsing cases in the web-platform-tests URL suite (the 8 others are xn-- edge cases), and browser results are published on wpt.fyi; an older browser may differ on edge cases.
  • Chromium (Chrome 152 in our test) accepts some hosts the URL Standard forbids: http://exa mple.com/ is read as the host exa%20mple.com, while Node.js rejects the URL. The tool then says the URL is not valid under the standard, names the character, and still shows the browser’s reading.
  • The RFC 3986 reading is a regular-expression split plus a character check, not a model of any one library; test your server-side library with the URL itself.
  • There is no Public Suffix List, so the tool does not split shop.example.co.uk into subdomain and registrable domain.
  • Look-alike warnings cover mixed scripts and Cyrillic or Greek labels made of Latin look-alikes. A domain that only swaps rn for m gets no warning.
  • The query table shows the first 500 parameters.

To encode or decode a single value, use URL Encode / Decode. To check the host of a parsed URL, look it up with DNS Lookup; for OAuth redirect URLs, the PKCE Generator builds the authorization request, and the HAR File Analyzer shows the URLs a page really requested.

FAQ

Which parser does this tool use?

Your browser's own URL parser, the same one behind new URL() in JavaScript. It follows the WHATWG URL Standard, so the parts you see are the parts the browser uses when it opens the link or sends a fetch request. A second reading splits the text with the RFC 3986 Appendix B regular expression, and the tool warns when that reading finds a different host.

Why does example.com/path show an error?

A URL needs a scheme such as https://. Without one, new URL() throws, so the tool says why and offers a button that parses the text as https://example.com/path. Relative links such as /api/users or ../img/logo.png need a base URL instead; type one under Base URL. Watch for localhost:3000/api: it does parse, but as the scheme localhost: with no host, and the tool points that out.

Why is the port empty when my URL says :443?

443 is the default port for https, so the URL Standard drops it from the URL. The request still goes to port 443. The same applies to 80 for http and ws, 443 for wss and 21 for ftp. The tool shows the default port as a placeholder and adds a note when it removed one.

Does editing a parameter re-encode the rest of my URL?

No. Parameters you do not touch keep their original text byte for byte, including a key without '=', an invalid escape such as %zz and bytes that are not UTF-8. Only the pair you edit or add is encoded, the way URLSearchParams encodes it (a space becomes +).

Is my URL sent or stored anywhere?

No. Parsing runs in this tab with the browser's URL and TextDecoder APIs. The page makes no request with your URL and does not save it. A password in the URL is masked until you press Show.