Advertisement
Advertisement

URL Encoder & Decoder

Encode text for web addresses, decode %-codes back to text, and see exactly what a URL contains.

🔒 Everything is converted in your browser. Nothing you paste is uploaded, and the tool never opens the URLs you enter.

How to use the URL Encoder & Decoder

  1. On the Encode / Decode tab, choose a mode: Encode component for one value (a search term, a file name, a query parameter), Encode full URL for a whole address, or Decode.
  2. Type or paste your text. The result appears instantly below.
  3. Use the options if you need them: spaces as + for HTML-form style, strict RFC 3986 encoding, or treating + as a space when decoding.
  4. If the decoder finds a broken % code, it leaves that part unchanged and tells you where it is.
  5. Open the URL parser tab and paste a link to see its protocol, host, path, query parameters and fragment in a table.

How it works

URLs can only contain a limited set of characters. Everything else, including spaces, accented letters and symbols like & or ? inside a value, is written as percent-encoding: each UTF-8 byte becomes % plus two hex digits. A space becomes %20, é (two bytes in UTF-8) becomes %C3%A9, and the emoji 👍 becomes %F0%9F%91%8D.

The two encode modes match the browser's standard functions. Component mode (encodeURIComponent) encodes everything that has a special meaning in a URL, including / ? & = #, so it's right for a single value you're placing inside a URL. Full URL mode (encodeURI) leaves those structural characters alone and only encodes what can't appear in a URL at all, so https://example.com/a b?q=1 becomes https://example.com/a%20b?q=1. The strict option also encodes ! ' ( ) *, which RFC 3986 reserves.

Decoding is where things often go wrong. A lone %, a code like %G1, or bytes that aren't valid UTF-8 make the standard decoder fail completely. This tool decodes everything it can, keeps the broken pieces as they were, and lists their positions so you can fix the source. The parser uses the browser's built-in URL standard (WHATWG URL) and shows each query parameter decoded, including repeated names.

Frequently asked questions

Should I use "Encode component" or "Encode full URL"?
Use component for a piece that goes inside a URL, like a search term or a parameter value; it makes sure characters such as & and = can't break the URL. Use full URL only when you have a complete address with a few unsafe characters, like spaces, that you want to fix without touching its structure.

Why do some URLs use + for spaces?
HTML forms submitted with GET send spaces as + (the application/x-www-form-urlencoded format). In other parts of a URL, a + is just a plus sign. Tick the matching option when encoding or decoding form data.

What does "malformed sequence" mean?
A % must be followed by two hex digits, and the bytes together must form valid UTF-8 text. Something like 100% or %E9 on its own breaks that rule. The tool shows where it happened and leaves that text as it was.

Is it safe to paste a URL with a token or password in it?
The tool runs entirely in your browser and never visits or sends the URL. Even so, treat links with tokens like passwords and avoid sharing them.

Why does the parser show my domain as xn--…?
Domain names with non-English letters are stored in an ASCII form called Punycode, which starts with xn--. Browsers show the readable version in the address bar, but this is the form actually used on the network.

Advertisement

You might also need