URL Encoder / Decoder
Percent-encode or decode URLs, and inspect every part of a query string.
Percent-encode text so it's safe to use inside a URL, or decode an already-encoded URL back to readable text — and break down every part of a query string (parameters, values, fragment) into its individual pieces for inspection.
Essential when building links with special characters, spaces, or non-ASCII text that would otherwise break a URL if left unencoded.
Characters you'll see encoded most often
| Character | Encoded | Why it matters |
|---|---|---|
| space | %20 (or + in form data) | Breaks the URL if left raw |
| & | %26 | Separates query parameters |
| = | %3D | Separates a key from its value |
| ? | %3F | Starts the query string |
| # | %23 | Starts the fragment — everything after is never sent to the server |
| / | %2F | Separates path segments |
| + | %2B | Means a space in form encoding, so a literal + must be escaped |
| % | %25 | Starts an escape sequence |
The double-encoding trap
Encoding an already-encoded string turns %20 into %2520, because the % itself gets escaped. The URL still looks plausible but resolves to literal text containing a percent sign, and the resulting bug is maddening to trace because the string looks almost right.
It usually happens when a value passes through two layers that each helpfully encode it — a framework helper and then a manual encodeURIComponent call, say. The rule: encode exactly once, at the point where you assemble the URL, and never encode a value you received already encoded.
encodeURI or encodeURIComponent?
- encodeURIComponent is what you almost always want. It escapes everything that isn't safe in a single parameter value, including / ? & = #.
- encodeURI is for encoding a whole URL that's already assembled — it deliberately leaves the structural characters alone so the URL stays functional.
- Using encodeURI on a parameter value is a bug: an & inside the value will be read as a parameter separator.
- Neither escapes the ! ' ( ) * characters, which are technically reserved. Escape them manually if a strict parser is involved.
Frequently asked questions
- Why does a space become %20 or a + sign?
- Both represent an encoded space — %20 is the standard percent-encoding, while + is a convention specific to encoding form data (application/x-www-form-urlencoded), not general URLs.
- Which characters actually need to be encoded in a URL?
- Reserved characters like ?, &, #, =, and spaces, along with any non-ASCII characters, need encoding when they appear as data rather than as URL structure — this tool handles that automatically.
- Can this parse an existing URL's query parameters?
- Yes — paste a full URL and the tool breaks its query string down into individual key-value pairs for easy inspection.
- Why do I see %2520 in my URL?
- Double encoding — a string containing %20 was encoded a second time, turning the % into %25. Encode exactly once, when you build the URL.
- What's the difference between encodeURI and encodeURIComponent?
- encodeURIComponent escapes everything unsafe in a parameter value including / ? & =. encodeURI leaves those alone because it's meant for a complete URL. For a single value, use encodeURIComponent.
- Is anything after the # sent to the server?
- No. The fragment is handled entirely by the browser and never appears in the HTTP request, which is why it's used for client-side routing and anchors.