🔗 TOOL • 100% PRIVATE

URL Encoder & Decoder — Percent-Encoding, Both Ways

Turn spaces, ampersands and emojis into URL-safe text — or read a mangled link back into plain words.

How to encode or decode (3 steps)

  1. Pick the direction — Encode turns plain text into a URL-safe string; Decode reads a percent-encoded string back into words.
  2. Paste the input. In encode mode you can also choose the flavor: percent encoding (spaces as %20) for the path part of a URL, or query encoding (spaces as +) for the part after the ?.
  3. Copy the output. Both directions are live — the result updates as you type, and one click copies it to your clipboard.

Why URLs need encoding

A URL has a small set of characters it may contain as-is — letters, digits, and a few punctuation marks — because other characters carry meaning inside the address itself: / separates path segments, ? starts the query string, & separates query parameters, # starts the fragment. When a value you want to send contains any of those — a search phrase like "coffee & cake", a filename with a space, a line of JSON — percent-encoding rewrites the offending character as % plus its two-hex-digit code, so the value travels safely inside a slot that has its own grammar. Decoding is the reverse: every %XX (and every + in a query string) becomes the character it stands for. Browsers, servers and runtimes all do this invisibly, which is exactly why a mangled link — double-encoded, half-decoded, mixed with plus signs in the wrong place — is so common in the wild.

The traps this tool removes

  • Double encoding — text that was encoded twice shows up as %2520 instead of %20; one decode pass undoes exactly one layer, so you can see the layers and peel them one at a time.
  • Plus vs. percent-20 — in a query string + means space; in a path it means a literal plus. The two encode flavors keep them apart on purpose.
  • Non-ASCII text — Urdu, emoji, accented names: encoding works on UTF-8 bytes, so "آب" becomes %D8%A7%D8%A8, and decoding brings it back exactly.

Privacy note

The input is processed by your browser's built-in encodeURIComponent / decodeURIComponent functions — the same primitives your form controls use. A URL that contains an internal host name, a signed token, or a client identifier never leaves this tab; there is no server to send it to.

🔒
100% PrivateEverything runs in your browser. Your data never touches a server.
⚡
Instant & FreeNo signup, no paywall, no limits. Fast on any device.
💬
Questions?Read our About page or contact us — I read every message and reply personally.
⌘ESC