Menu

URL Encoder / Decoder

Purpose: Percent-encode text for use in URLs and query strings, or decode an encoded URL back to readable text.

URL Encoder: How It Works

URL encoding replaces characters that have structural meaning in a web address with a percent sign and their hexadecimal byte value. Knowing which of the two encoding functions to use, and where, prevents a whole class of bugs that only appear with unusual input.

Reserved characters

These have a job in a URL, so a literal one must be escaped when it appears in data.

CharEncodedIts structural role
space%20 (or + in query strings)Terminates a URL in many contexts
?%3FStarts the query string
&%26Separates parameters
=%3DSeparates key from value
#%23Starts the fragment
/%2FPath separator
+%2BMeans space in form encoding

The two functions

JavaScript offers encodeURI and encodeURIComponent, and choosing wrongly is the standard bug.

Encoding a parameter with encodeURI leaves any & in the value unescaped, which silently splits it into two parameters. A search for 'fish & chips' becomes a search for 'fish ' plus an unexpected parameter named 'chips'. Use encodeURIComponent for values, always.

The plus-sign ambiguity

Two conventions coexist. In application/x-www-form-urlencoded data — HTML form submissions — a space is encoded as +. In URL paths and in the modern percent-encoding standard, a space is %20 and + is a literal plus.

The practical consequence: an email address containing a plus, such as user+tag@example.com, arrives as user tag@example.com if the receiving code treats the query string as form-encoded. Always encode a literal plus as %2B.

Double encoding

Encoding an already-encoded string escapes the percent signs themselves: %20 becomes %2520. The result decodes once to %20 and only twice to a space. This appears whenever a URL passes through two layers that each helpfully encode it — a redirect service, a tracking wrapper, a framework's router. If you see %25 sequences in production logs, something is encoding twice.

Unicode

Percent-encoding operates on bytes, so text must first be encoded to bytes — in practice UTF-8. A single non-ASCII character often becomes several percent sequences: é is %C3%A9, and an emoji can be four. Truncating an encoded URL by character count can therefore split a multi-byte sequence and produce an undecodable string.

Where to encode

Encoding is not sanitisation. It makes a value safe to carry in a URL; it does not make it safe to insert into HTML, SQL or a shell command, each of which needs its own escaping at its own boundary.

Frequently Asked Questions

What is the difference between encodeURI and encodeURIComponent?
encodeURI is for a complete URL and preserves structural characters like / ? & =. encodeURIComponent is for a single value and escapes those too. Use the component version for parameter values, or an ampersand in your data will split the query string.
Why is a space sometimes %20 and sometimes +?
Two conventions. Form-encoded data uses + for a space; URL paths and modern percent-encoding use %20. This is why a literal plus in an email address must be encoded as %2B, or it may be decoded as a space.
What causes %2520 to appear in a URL?
Double encoding. An already-encoded string was encoded again, so %20 became %2520. It usually happens when a URL passes through two layers that each encode it, such as a redirect wrapper plus a framework router.
Do I need to encode non-English characters?
Yes. They are encoded as their UTF-8 bytes, so one character can become several percent sequences — é is %C3%A9. Modern browsers display them readably but transmit the encoded form.
Does URL encoding protect against injection attacks?
No. It makes a value safe to transport in a URL. Preventing injection requires escaping appropriate to the destination — HTML escaping for markup, parameterised queries for SQL, and so on.
Is my input sent to a server by this tool?
No. Encoding and decoding happen entirely in your browser, so nothing you paste leaves your device.

Related Developer Tools

Browse all Developer tools →