To URL decode a string, paste it into the Input box and select Process URL. With Action on Auto detect, any input containing percent codes such as %20 is decoded: %20 and + become spaces and %C3%A9 becomes é. Text without percent codes is encoded instead, so set Action to Decode or Encode to be explicit.
How to URL decode or encode text
- Paste the text. Put a URL, query string or encoded value in the Input box, or choose Select URL File to load a .txt file. Load Sample loads a URL with spaces in it.
- Choose the action. Leave Action on Auto detect, or pick Decode or Encode. For encoding, choose URL Component for a single value or Full URL (preserve structure) for a whole address.
- Set spaces and repeats. Spaces Behavior picks
%20or+when encoding. Set Repeat to 2 or 3 times for text that was encoded more than once. - Process. Select Process URL (Ctrl+Enter). Then Copy Output, Download it as .txt, or select Analyze URL to see each parameter decoded.
What URL encoding (percent-encoding) is
A URL can only contain a limited set of ASCII characters, and some of those have a job: ? starts the query, & separates parameters, # starts the fragment. Percent-encoding, defined in RFC 3986, writes any other byte as % plus two hexadecimal digits. Non-ASCII characters are first converted to UTF-8 bytes, so é (two bytes) becomes %C3%A9. Only letters, digits and - . _ ~ never need encoding.
| Character | Encoded | Why it's encoded |
|---|---|---|
| Space | %20 (or + in forms) | Spaces aren't allowed in URLs |
& | %26 | Would start a new parameter |
= | %3D | Would split a key from its value |
/ | %2F | Would start a new path segment |
? | %3F | Would start the query string |
# | %23 | Would start the fragment |
+ | %2B | Means a space in form-encoded data |
% | %25 | Starts every escape |
URL decoding reverses this: every %XX becomes its byte again and the bytes are read as UTF-8.
encodeURIComponent vs encodeURI
JavaScript has two built-in encoders, and they differ in what they leave alone. encodeURIComponent escapes everything except letters, digits and - _ . ! ~ * ' ( ). Use it for one value that goes inside a URL. encodeURI also keeps the characters that give a URL its structure, such as : / ? # & =, so it suits a complete address that only needs its spaces and non-ASCII characters fixed.
encodeURIComponent("https://example.com/search?q=hello world")
// https%3A%2F%2Fexample.com%2Fsearch%3Fq%3Dhello%20world
encodeURI("https://example.com/a b?q=1&r=é")
// https://example.com/a%20b?q=1&r=%C3%A9The URL encoder on this page has two modes. URL Component is encodeURIComponent applied to the whole input. Full URL (preserve structure) keeps the scheme, host and separators, and runs encodeURIComponent on each path segment, query key, query value and the fragment. It decodes each part first, so codes that are already there aren't encoded twice:
https://example.com/my files/report.pdf?q=hello world&city=São Paulo
// becomes
https://example.com/my%20files/report.pdf?q=hello%20world&city=S%C3%A3o%20Paulo
How the URL decoder handles + signs and errors
The decoder treats + as a space before decoding, which matches how HTML forms send data (application/x-www-form-urlencoded). So q%3Dhello+world decodes to q=hello world. A real plus sign should arrive as %2B; if your text has a literal + that isn't a space, it will turn into one. Python draws the same line with unquote(), which keeps +, and unquote_plus(), which turns it into a space.
A % that isn't followed by two hex digits, as in 100%, makes decoding fail with the browser's "URI malformed" error. Replace it with %25 first. Double-encoded text shows %25 where you expect %: caf%25C3%25A9 needs Repeat set to 2 times to reach café.
Reading a URL's parameters
Analyze URL parses the input as a URL and shows the protocol, origin, host, path and hash, plus a table of every query parameter with its key and decoded value. It's a quick way to read tracking links, OAuth redirects or long search URLs, where a redirect= parameter often holds a second encoded URL. The Search Output box highlights matches in the result.
Everything runs in your browser, so URLs with session tokens or signed parameters aren't sent anywhere. If a parameter holds a Base64 value, decode it with the Base64 decoder; if it holds a token beginning with eyJ, use the JWT decoder. For & and other HTML entities, which are a different kind of escaping, use the HTML entity converter.
Frequently asked questions
How do I decode a URL online?
Paste the encoded URL into the input box and select Process URL. Percent codes like %20, %2F and %C3%A9 are turned back into spaces, slashes and accented letters.
What does %20 mean in a URL?
It's an encoded space. 20 is the hexadecimal code for the space character, so my%20file.pdf means "my file.pdf".
Should I encode spaces as %20 or +?
Use %20 in URL paths and in most APIs. Use + only in query strings and form data that follow the application/x-www-form-urlencoded format. The Spaces Behavior setting switches between them.
What's the difference between URL encode and decode?
Encoding turns unsafe characters into %XX codes so text fits inside a URL. Decoding turns those codes back into the original characters so you can read them.
Why does URL decoding fail with "URI malformed"?
The input has a % sign that isn't followed by two valid hex digits, or the codes don't form valid UTF-8. Replace stray % signs with %25 and try again.
Is the URL I paste sent to a server?
No. URL decoding and encoding run in your browser with JavaScript, so links with tokens or personal data stay on your device.