URL Encoder and Decoder

Percent-encode text for safe use in a URL, or decode an encoded URL back to readable text. Runs in your browser — the input is never uploaded.

What URL encoding does

A URL may only contain a limited set of ASCII characters. Anything outside that set — spaces, accented letters, most punctuation, and characters that have structural meaning such as &, ?, = and / when they appear inside a value — has to be percent-encoded: a % followed by the two hex digits of each UTF-8 byte. A space becomes %20; é is two bytes and becomes %C3%A9; the euro sign is three bytes, %E2%82%AC.

Decoding reverses that: %C3%A9 is read back as the byte pair 0xC3 0xA9 and rendered as é.

How to decode a URL

Paste the encoded link or string and choose Decode URL (Auto-detect switches to decoding by itself when it sees %XX sequences). The URL decoder turns every percent sequence back into its UTF-8 character, and when the result is a full address it also splits it into scheme, host, path and a table of query parameters — handy for reading tracking links, OAuth redirect_uri values, or API calls copied from browser dev tools.

Which mode to use

ModeJavaScript equivalentUse it for
Component valueencodeURIComponent()A single query-parameter value, a path segment, or a form field. Encodes / ? & = # : and space.
Full URLencodeURI()An entire URL that only needs spaces and non-ASCII characters fixed. Leaves / ? & = # : intact so the URL still works.
Form (+ for space)encodeURIComponent() then %20→+The body or query of an application/x-www-form-urlencoded request, where a space is conventionally +.

The most common bug is running Full URL on a value that itself contains & or =. Those characters survive, the browser or server splits on them, and the request breaks. When in doubt, encode each value with Component value and build the URL from the encoded pieces.

URL-encode JSON or XML

To pass a whole JSON object or XML document in a GET query string, a deep link, an OAuth state value or a webhook callback URL, encode it as one parameter value with Component value mode (encodeURIComponent). That escapes every brace, quote, colon, comma, angle bracket, slash, & and = inside the payload, so none of them can break the surrounding URL. Paste the JSON or XML above and choose Encode URL; the tool confirms when the input is valid JSON or well-formed XML. To go back, choose Decode URL: a decoded JSON value gets a Pretty-print JSON button, and decoded XML is checked for well-formedness. The round trip is lossless.

PayloadInputURL-encoded (Component value)
JSON{"q":"café & tea","page":2}%7B%22q%22%3A%22caf%C3%A9%20%26%20tea%22%2C%22page%22%3A2%7D
XML<id>7</id>%3Cid%3E7%3C%2Fid%3E

Common payload characters: { %7B, } %7D, [ %5B, ] %5D, " %22, : %3A, , %2C, < %3C, > %3E, / %2F. Two notes: URL encoding is not compression or encryption — the result is longer and anyone can decode it — and it does not minify, so minify the JSON first if URL length matters (many servers cap URLs at about 8 KB). Do not use Full URL mode for a payload: it leaves & = ? / # unencoded.

Percent-encoding reference

CharacterEncodedCharacterEncoded
space%20 (or + in forms)#%23
!%21$%24
&%26'%27
(%28)%29
+%2B,%2C
/%2F:%3A
;%3B=%3D
?%3F@%40
%%25"%22

Never encoded (the unreserved set): A–Z a–z 0–9 - _ . ~. The encodeURIComponent function also leaves ! * ' ( ) untouched even though they are reserved — encode those yourself if a strict parser needs them escaped.

Encoding in code

JavaScript

const url = "https://api.example.com/search?q="
  + encodeURIComponent("café & croissant");
// .../search?q=caf%C3%A9%20%26%20croissant

decodeURIComponent("caf%C3%A9%20%26%20croissant"); // "café & croissant"

Python

from urllib.parse import quote, quote_plus, unquote

quote("café & croissant")        # 'caf%C3%A9%20%26%20croissant'
quote_plus("café & croissant")   # 'caf%C3%A9+%26+croissant'  (form style)
unquote("caf%C3%A9%20%26%20croissant")  # 'café & croissant'

PHP

rawurlencode("café & croissant"); // caf%C3%A9%20%26%20croissant
urlencode("café & croissant");    // caf%C3%A9+%26+croissant  (form style)
rawurldecode("caf%C3%A9%20%26%20croissant");

Java

import java.net.URLEncoder;
import java.nio.charset.StandardCharsets;

URLEncoder.encode("café & croissant", StandardCharsets.UTF_8);
// caf%C3%A9+%26+croissant  — Java uses form (+) style; replace "+" with "%20" for path use
URLDecoder.decode("caf%C3%A9+%26+croissant", StandardCharsets.UTF_8); // "café & croissant"

Go

url.QueryEscape("café & croissant")   // caf%C3%A9+%26+croissant  (form style)
url.PathEscape("café & croissant")    // caf%C3%A9%20&%20croissant
s, err := url.QueryUnescape("caf%C3%A9+%26+croissant")

Bash / command line

# encode with jq (no Python needed)
printf '%s' 'café & croissant' | jq -sRr @uri      # caf%C3%A9%20%26%20croissant
# decode with Python's standard library
python3 -c 'import sys,urllib.parse as u;print(u.unquote_plus(sys.argv[1]))' 'caf%C3%A9+%26+croissant'

Common questions

What is the difference between %20 and + for a space?

%20 is valid anywhere in a URL. + means space only in a form-encoded query string; in a path segment it is a literal plus. Use %20 unless you are building application/x-www-form-urlencoded data.

Why did encoding my string twice produce %2520 instead of %20?

% encodes to %25, so a second pass turns %20 into %2520. Always encode the raw value once.

Should I encode the whole URL or just the parameter value?

Encode each parameter value with Component value, then assemble the URL. Full URL mode leaves & = ? / alone, so a value containing them would corrupt the query string.

Is anything sent to a server?

No. Everything runs locally using the browser's built-in encodeURIComponent, encodeURI and decodeURIComponent.

Which characters are safe and never get encoded?

The unreserved set: A–Z a–z 0–9 - _ . ~. encodeURIComponent also leaves ! * ' ( ) alone; everything else in a component is percent-encoded.

How do I decode a URL online?

Paste the encoded URL or string and choose Decode URL (Auto-detect does this when it sees %XX). Each sequence becomes its UTF-8 character, a full URL is split into host, path and a query-parameter table, and a warning appears if the value was encoded twice.

How do I encode a URL online?

Paste the text or URL, choose Encode URL, then pick Component value for a single query parameter or path segment, or Full URL for a whole address. The percent-encoded result appears instantly — no upload, no install.

How do I URL-encode JSON or XML?

Paste the JSON or XML, choose Encode URL and keep Component value selected. That is encodeURIComponent, which also escapes the braces, quotes, colons, angle brackets, slashes, & and = inside the payload, so the whole document travels as one query-parameter value. {"q":"a&b"} becomes %7B%22q%22%3A%22a%26b%22%7D and <id>7</id> becomes %3Cid%3E7%3C%2Fid%3E. The tool confirms when the text is valid JSON or well-formed XML.

How do I decode URL-encoded JSON or XML?

Paste the encoded string and choose Decode URL. If the decoded text is valid JSON, a Pretty-print JSON button appears; if it is XML, the tool checks that it is well-formed. The round trip is lossless: decoding returns exactly the JSON or XML that was encoded.