URL Encoder & Decoder
Percent-encode and decode URLs, full strings or single components.
Component mode escapes reserved characters such as & = ? / — use it for a single query value.
| Key | Value |
|---|---|
| q | hello world |
| lang | en |
About this tool
Percent-encode text for safe use in a URL, or decode an encoded URL back to readable form. Component mode escapes reserved characters like & and = so a value can be dropped into a query string safely.
How to use it
- Choose Encode or Decode.
- Pick Component to escape reserved characters, or Full URL to leave the structure intact.
- Paste your input and copy the result.
Component or full URL — picking the wrong one silently breaks things
This is the distinction that causes most percent-encoding bugs.
Full URL mode leaves the characters that give a URL its structure alone — : / ? # & = — and escapes only genuinely unsafe ones like spaces. Use it when you have a complete address that is already correct and just needs tidying.
Component mode escapes those structural characters too. Use it for a single value you are about to embed in a query string.
The failure looks like this. A redirect URL passed as a parameter:
?next=https://example.com/a?b=c
The second ? and the & that follow are read as part of the outer URL, so your parameter is truncated and extra parameters appear from nowhere. Encoding the value as a component first turns it into one opaque blob and the problem disappears.
The rule of thumb: encoding a whole URL, use Full. Encoding something that goes inside a URL, use Component.
Plus signs, spaces, and double encoding
A space has two encodings. Percent-encoding says %20. HTML form submissions use +, a convention from the application/x-www-form-urlencoded content type. Both appear in the wild; %20 is valid everywhere, which is what this tool produces.
Double encoding is the other common bug. Encode %20 again and you get %2520, because the % itself gets escaped. The symptom is literal %2520 strings appearing in logs or on a page. It usually means a value is being encoded by both your code and a framework that was already handling it.
If you see %25 where you expect %, decode twice and work out which layer to remove.
Frequently asked questions
- What is the difference between the two modes?
- Full URL keeps characters like : / ? & = intact so a whole address stays valid. Component escapes them too, which is what you want when embedding a value inside a query parameter.
- Why does a space become %20 and sometimes +?
- Percent-encoding uses %20. The + convention comes from HTML form submissions. This tool produces %20, which is valid everywhere.
- Are the URLs I paste logged?
- There is nothing to log them with. Encoding and decoding use the browser's own encodeURIComponent, so URLs containing session tokens or query parameters are never sent anywhere.