URLs may contain only a limited set of characters. Spaces, accented letters, emoji and symbols with special meaning — ?, &, =, #, / — must be written as percent-escapes like %20 when they appear inside a value. Getting this wrong breaks links, splits query parameters in the wrong place or opens injection holes. This tool encodes text the way browsers and server frameworks do, decodes escaped strings back to readable text, and breaks a full URL into its parts.
How to use the URL encoder and decoder
- Choose Encode or Decode and paste your text or URL.
- When encoding, pick what the text is for:
- Component — a single query value or path segment; everything outside the unreserved set is escaped.
- Full URL — a complete address; structural characters (
: / ? # & =) are kept. - Form data — like Component, but spaces become
+.
- When decoding, leave Treat + as a space on for query strings and form posts; turn it off for paths, where + is literal.
- Copy the result from the output box. The table lists each encoded character with its code point and UTF-8 bytes, and a URL is split into scheme, host, path, query parameters and fragment.
How percent-encoding works
RFC 3986, the URL standard, defines unreserved characters that never need escaping:
Every other character is converted to UTF-8 bytes, and each byte is written as a percent sign followed by two hexadecimal digits:
Decoding reverses it: each %XX becomes one byte, and the bytes are read as UTF-8 text.
Worked example
Encode the search phrase Q&A: café prices / 50% off? as a query value.
Letters and digits stay as they are.
& → %26, : → %3A, space → %20, é → UTF-8 C3 A9 → %C3%A9, / → %2F, % → %25, ? → %3F.
Result: Q%26A%3A%20caf%C3%A9%20prices%20%2F%2050%25%20off%3F (52 characters from 27).
As form data, the spaces become + instead: Q%26A%3A+caf%C3%A9+prices+%2F+50%25+off%3F.
Decoding caf%C3%A9+cr%C3%A8me with + as a space gives café crème.
Common encodings
| Character | Encoded | Why it must be escaped in a value |
|---|---|---|
| space | %20 or + | Not allowed in URLs |
| & | %26 | Separates query parameters |
| = | %3D | Separates a name from its value |
| ? | %3F | Starts the query string |
| # | %23 | Starts the fragment |
| / | %2F | Separates path segments |
| % | %25 | Starts an escape sequence |
| + | %2B | Means a space in form data |
| é | %C3%A9 | Non-ASCII, two UTF-8 bytes |
Pitfalls
- Double encoding. Encoding an already-encoded string turns
%20into%2520. Encode raw values once, at the point where you build the URL. - Encoding a whole URL as a component escapes the
://and slashes, producing an unusable link. Use Full URL mode for complete addresses. - Hand-built query strings. In code, prefer the URL and URLSearchParams classes (or your framework’s equivalent), which apply these rules automatically.
- International domain names are not percent-encoded; they use Punycode (xn–…) in the host part.
To encode binary data as text instead, use the Base64 encoder and decoder. To inspect the code points and UTF-8 bytes of any character, try the text to ASCII converter.
Frequently asked questions
Should a space be %20 or +?
Both are valid in different places. In a URL path or a general component, a space is %20. In query strings submitted by HTML forms (application/x-www-form-urlencoded), a space is written +. When decoding a query string, treat + as a space; in a path, a + is a literal plus sign.
What is the difference between encodeURI and encodeURIComponent?
encodeURI is meant for a whole URL, so it leaves the characters that give a URL its structure — : / ? # & = and others — untouched. encodeURIComponent is meant for one piece, such as a query value, and escapes those characters too. Using encodeURI on a value that contains & or = breaks the query string.
Why does é become %C3%A9?
URLs carry bytes, and modern URLs use UTF-8. The letter é (U+00E9) is two bytes in UTF-8, C3 and A9, and each byte becomes % plus two hex digits. Older systems that used Latin-1 encoded it as %E9; this decoder detects that and falls back to Latin-1.
What does %25 mean?
It is an encoded percent sign. If a decoded result still contains sequences like %3C, the text was encoded twice (the % became %25); decode it again.