URL Encoder & Decoder
URL Encoder & Decoder percent-encodes special characters in URLs (spaces become %20, & becomes %26) so links work correctly in query strings, APIs and redirects — and decodes them back to readable text.
Broken links with spaces or non-English characters are one of the most common web bugs; this tool fixes them in seconds.
How to use the url encoder & decoder
- Paste your URL or text into the input.
- Click “Encode URL” to percent-encode it, or “Decode URL” to reverse the process.
- Copy the result and use it in your link, API call or redirect.
- Verify round-trip — decode the encoded URL to confirm it returns to the original.
Key features
- Full percent-encoding: handles spaces, symbols and Unicode correctly.
- Decode mode: turn %20-filled URLs back into readable text.
- Error detection: malformed encodings (bad % sequences) are flagged.
- Instant & private: everything runs in your browser.
Encode the Parameters, Not the Whole URL
The classic mistake is encoding an entire URL, which turns the :// and ? into gibberish and breaks the link. Encode only the parameter values — the search terms, names, and messages — and leave the structure alone. This tool handles the values while you keep the skeleton intact. Working with encoded data in other formats? The Base64 encoder-decoder and HTML entity encoder cover those.
Decode That Endless Redirect URL
Ever copied a link and gotten a monster full of %3A%2F%2F? That’s a URL nested inside another URL’s parameter — common with redirects and share trackers. Paste the whole mess into the decode box to reveal the real destination hiding underneath. It’s the quickest way to see where a link actually goes before you click it. Decoding API tokens instead? The Base64 decoder handles those.
Frequently asked questions
When do I need to URL-encode?
Whenever a URL contains spaces, non-English characters, or reserved symbols like &, ?, # or = inside a query-string value. Unencoded, these break the link or change its meaning.
What’s the difference between encodeURI and encodeURIComponent?
This tool uses encodeURIComponent-style encoding, which encodes every reserved character — the safe choice for query-string values and form data.
Why do I see %20 in my URLs?
%20 is the percent-encoded form of a space. Decode it here to see the original readable URL.
Is my URL sent to a server?
No — encoding and decoding happen locally in your browser.
Should I encode the whole URL or just the parameters?
Just the parameter values. Encoding the whole URL mangles its :// separators and & connectors — encode the values, leave the structure.
Why do I see %2F in my links?
%2F is an encoded forward slash. It shows up when one URL is tucked inside another URL’s parameter, like in redirect and tracking links.
Can I encode non-English characters in URLs?
Yes. Characters like اردو or 中文 are converted to UTF-8 bytes and then percent-encoded — browsers decode and display them normally.
Pro Tips
- Sharing links with special characters: encode URLs containing spaces, ampersands, or Unicode before pasting into emails or documents.
- Debug redirect issues: decode a messy URL to see the real destination hiding inside tracking parameters.
- Developers: encode query parameter values (not the whole URL) to avoid double-encoding bugs.
More FAQs
What does %20 mean in a URL?
It’s an encoded space. Characters that aren’t allowed raw in URLs are replaced with a % followed by their hex code.
When should I encode vs. decode?
Encode before putting special text into a URL; decode when you want to read what an encoded URL actually contains.
How It Works: Under the Hood
URL encoding — percent-encoding — exists because URLs can only safely carry a limited character set. Take a byte’s value, write it as two hex digits, prefix with %: space becomes %20, slash %2F, ampersand %26.
Non-ASCII characters become UTF-8 bytes first: an é is two bytes, encoded separately as %C3%A9; a three-byte kanji becomes %E6%97%A5. Encoding grows with byte length, not character count.
RFC 3986 splits characters into two sets: unreserved (A–Z a–z 0–9 – _ . ~) never need encoding, while reserved characters (: / ? # [ ] @ ! $ & ‘ ( ) * + , ; =) have structural meaning and must be encoded when used as data. A raw / in a path is a separator; %2F in a query value is just data.
Double-encoding happens when an already-encoded string is encoded again: %20 becomes %2520 because % itself encodes as %25. Decode once and you get %20 back, not a space — the link looks right but points nowhere.
Real-World Use Cases
- A marketing analyst encodes “summer sale 2026” into summer%20sale%202026 so analytics reads it as one UTM parameter instead of breaking the URL at the spaces.
- A developer passing a callback URL as a query parameter encodes every ?, &, and = into %3F, %26, %3D so the outer parser ignores the inner URL’s structure.
- A content manager decodes a CMS-generated link to a product named “café” to verify the UTF-8 bytes round-trip, catching mojibake before an email blast.
- An API integrator debugging an OAuth signature mismatch discovers the signature was computed on the raw parameter, not the encoded one sent.
- A support agent decodes a garbled share-link and finds %2520 sequences — double-encoded spaces — proving the bug is in the redirect.
Advanced Tips
- Decode suspicious URLs twice when debugging. Leftover % sequences after the first decode mean double-encoding — one check separating “broken” from “encoded twice.”
- Encode path segments and query values separately — encoding https:// into https%3A%2F%2F produces a string no browser will navigate.
- Remember + means space only in form data. In a path, + is a literal plus — mixing contexts causes “lost plus” bugs.
- Check encoding before blaming the server. A 404 on a non-ASCII URL is often Latin-1 bytes where the server expects UTF-8 — re-encode as UTF-8 to test in one step.
Common Mistakes to Avoid
- Encoding the entire URL. https%3A%2F%2Fexample.com is data, not an address — encode only the dynamic parts.
- Encoding the same value twice. Most HTTP clients already encode query parameters — manual encoding on top produces %2520-style breakage.
- Assuming decoding is safe to display. A decoded URL can carry a javascript: scheme — decode to debug, sanitize before injecting into a page.
- Confusing URL encoding with HTML entities. %26 and & solve different problems — literal “%26” on a page means you encoded for the wrong layer.