URL Encoder / Decoder

Percent-encode or decode text and URLs safely.

About this tool

Percent-encode text so it's safe to drop into a URL, or decode an encoded URL back to readable text. Spaces, punctuation with special meaning, and non-ASCII characters become %XX escape sequences; everything else is left alone. It runs in your browser.

Why URLs need encoding. A URL has structure — ? begins the query, & separates parameters, / separates path segments, # starts the fragment. If a value in the URL contains one of those characters, a space, or a character outside ASCII, it must be escaped so it isn't mistaken for structure. Percent-encoding replaces each such byte with % followed by its two hex digits.

space → %20  ·  & → %26  ·  = → %3D  ·  "café" → caf%C3%A9 (é is two UTF-8 bytes)

Encode a component, not the whole URL. If you percent-encode an entire URL, its own ://, /, and ? get escaped and it stops working. Encode each value — a search term, a redirect target, an ID — before you assemble it into the URL. In code this is the difference between encodeURIComponent() (for a value) and encodeURI() (for a whole URL); this tool's Encode mode does component-style escaping.

Space is the fiddly one. In a path, a space must be %20. In application/x-www-form-urlencoded data — the classic HTML form POST body, and often query strings — a space is +, and a literal + becomes %2B. If a decoded value shows stray + signs where spaces should be, it was form-encoded; if it shows literal %20, decode it again.

Don't double-encode. Encoding an already-encoded string escapes the percent signs themselves: %20 becomes %2520. If you see %25 everywhere, something encoded the value twice — decode until it's clean, then encode once.

Decoding malformed input. An incomplete escape like %2 or %GG isn't valid. The tool shows a hint rather than emitting garbage.

Percent-encoding is not Base64 and not HTML entities — the guide to the three encodings covers when each applies. For escaping < and & in HTML, use the HTML entity encoder; for encoding bytes as text, Base64. To pull a URL apart into its pieces, the URL parser.

Frequently asked questions

Why do spaces become "%20"?
URLs can't contain literal spaces. In a path a space is %20; in form data and many query strings it's + instead.
How is this different from Base64?
URL encoding only escapes characters that aren't URL-safe and leaves the rest readable. Base64 re-encodes all the bytes into a denser, unreadable form for a different purpose (carrying binary through text).
Should I encode the whole URL or just part of it?
Just the values you insert into it. Encoding a full URL escapes its own :// and / and breaks it.
My decoded text has "+" where spaces should be — why?
It was form-encoded (x-www-form-urlencoded), where + means space. Decode with that in mind, or replace + with a space first.
What does "%2520" mean?
A double-encoded space: %20 got encoded again, turning its % into %25. Decode twice, then encode once.
What happens with malformed input like "%2"?
The tool shows a hint that the input has an invalid percent-escape, instead of producing corrupted output.