URL Encoder & Decoder

Encode text for safe use in a URL, or decode %XX sequences back to readable text. Below, paste a whole URL to see its parts.

URL parser

Protocolhttps:
Hostexample.com
Path/search
?qcafé au lait
?langfr
?page2
Fragment#results

Which characters need encoding?

RFC 3986 lets these through untouched: letters, digits and - . _ ~. Reserved characters such as : / ? # [ ] @ ! $ & ' ( ) * + , ; = have jobs in a URL, so they must be encoded when they appear inside a value. Everything else — spaces, quotes, non-English letters and emoji — is converted to UTF-8 bytes and written as %XX.

A common bug is double encoding: encoding an already-encoded value turns %20 into %2520. If you see %25 in a URL, decode once more.

Questions people ask

What is URL encoding?

URL encoding (percent-encoding, defined in RFC 3986) replaces characters that are unsafe or reserved in a URL with % followed by two hex digits for each UTF-8 byte. A space becomes %20, “&” becomes %26 and “é” becomes %C3%A9.

What is the difference between encodeURI and encodeURIComponent?

encodeURIComponent encodes everything except letters, digits and - _ . ! ~ * ' ( ), so it is right for a single query value or path segment. encodeURI leaves the characters that structure a URL (: / ? # & =) alone, so it is for a complete URL. Using encodeURI on a value that contains & will break your query string.

Why do some URLs use + instead of %20?

HTML form submissions (application/x-www-form-urlencoded) encode spaces as +. In the path part of a URL, + means a literal plus. The decoder here treats + as a space by default; switch it off if your text contains real plus signs.

What does “URI malformed” mean?

A % sign is followed by something that is not two hex digits, or the bytes do not form valid UTF-8. A lone % in text must itself be encoded as %25.

Related tools