Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

URL Encoder & Decoder

Percent-encode and decode safely, and see every part of a URL.

Developer No upload Works offline Free, no sign-up
Encoding

Next steps

About the URL Encoder & Decoder

URLs may only contain a limited set of ASCII characters, so everything else — spaces, & inside a value, accented letters, emoji — has to be percent-encoded as % plus two hex digits for each UTF-8 byte (é becomes %C3%A9). This tool encodes and decodes text the way browsers and servers actually do, with four exactly-defined modes, and parses complete URLs into their parts.

Decoding never fails silently: a broken escape such as %G1 or a byte sequence that is not valid UTF-8 is reported with its exact position and a suggestion for fixing it. The Parse URL view lists the scheme, host (including the readable form of internationalised domain names), port, path, fragment and every query parameter with its decoded value.

How to use it

  1. Choose Encode, Decode or Parse URL, then paste your text. Results update as you type.
  2. When encoding, pick the rule that matches where the text will go: a query value or path segment (Component), a whole URL (Full URL), an HTML form body (Form data) or a signature base string (RFC 3986 strict).
  3. When decoding query strings, turn on Decode + as a space. If the text came from an old system, try the Windows-1252 character set.
  4. Copy the result, or press Use as input to reverse the operation.

Examples

Encode a query value (Component)
Input
café & crème = 100%
Result
caf%C3%A9%20%26%20cr%C3%A8me%20%3D%20100%25
The same text as form data
Input
café & crème = 100%
Result
caf%C3%A9+%26+cr%C3%A8me+%3D+100%25

HTML forms and URLSearchParams write spaces as +.

A malformed escape
Input
100%G1
Result
Malformed escape "%G1" at position 4: "%" must be followed by two hex digits (0–9, A–F). A literal percent sign is written %25.
Parse a URL
Input
https://shop.example/search?q=red+shoes&size=9#reviews
Result
Host: shop.example · Path: /search · q = red shoes · size = 9 · Fragment: #reviews

Common uses

  • Building query strings and API request URLs by hand, or debugging ones generated by code.
  • Reading tracking links, redirect URLs and OAuth callbacks that contain encoded URLs inside them.
  • Fixing "URI malformed" errors and garbled characters such as é in decoded text.
  • Preparing values for OAuth 1.0 and AWS Signature Version 4, which require strict RFC 3986 encoding.
  • Checking UTM parameters and canonical URLs for SEO.

Which encoding should I use?

  • Component (encodeURIComponent) is right for a single query-string value or path segment. It encodes everything except A–Z a–z 0–9 - _ . ! ~ * ' ( ), so &, =, / and ? inside the value cannot break the URL.
  • Full URL (encodeURI) is for a complete URL that only needs spaces and non-ASCII characters fixed. It leaves the URL's structure alone — : / ? # @ & = + $ , ; are kept — so do not use it for individual values.
  • Form data follows the WHATWG URL Standard used by HTML forms and URLSearchParams: spaces become +, and only A–Z a–z 0–9 * - . _ stay as they are.
  • RFC 3986 strict leaves only the unreserved characters A–Z a–z 0–9 - . _ ~ (RFC 3986 §2.3). OAuth 1.0 (RFC 5849) and AWS Signature Version 4 require exactly this.

Why decoding sometimes fails

A % must always be followed by two hexadecimal digits; anything else (such as %G1 or a % at the very end) is malformed — a literal percent sign is written %25. After decoding, the bytes must form valid UTF-8. Old systems sometimes encoded text as Windows-1252 or Latin-1, where é is %E9 rather than %C3%A9; choose the Windows-1252 character set to read those correctly.

If the result still contains sequences like %20, the text was encoded twice (%2520) — press Decode again.

Limitations

  • Parse URL accepts one URL at a time. Relative URLs (starting with /, ? or #) are shown without a scheme or host.
  • Internationalised domain names are shown in both Punycode (xn--…, as produced by your browser's URL parser) and readable Unicode form (decoded here following RFC 3492).

Privacy

Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

Frequently asked questions

What is the difference between %20 and + for spaces?

Both mean a space, but in different places. %20 works everywhere in a URL. + means a space only in query strings and form bodies (application/x-www-form-urlencoded); in a path, + is a literal plus sign. When in doubt, use %20.

Why does decodeURIComponent throw "URI malformed"?

Because the text contains a % that is not followed by two hex digits, or escapes that do not form valid UTF-8. This tool shows the exact position of the problem instead, and can keep malformed sequences unchanged if you prefer.

Should I encode the whole URL or just the values?

Encode each query value (and path segment) separately with Component, then join them with &, = and /. Encoding a finished URL with Component would also encode its : and / and break it.

Is anything I paste sent to a server?

No. Encoding, decoding and parsing all run in your browser, so URLs with tokens or personal data stay on your device.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.