Security

URL Encoder / Decoder

Encode and decode URLs and query parameters with correct percent-encoding. Handles UTF-8, component vs full-URI encoding, and double-encoded strings.

Last reviewed by the Radiatus Cloud team

URL Encoder/Decoder

Encode and decode URLs using percent-encoding.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Percent-encoding, briefly

URLs may only contain a restricted set of ASCII characters. Anything outside that set, and any reserved character used with a meaning other than its structural one, must be percent-encoded: converted to UTF-8 bytes and written as % followed by two hexadecimal digits. A space becomes %20, an ampersand inside a value becomes %26, and an accented character becomes two or more bytes.

Encoding a component is not encoding a URI

This distinction causes most bugs. JavaScript exposes two functions. encodeURIComponent escapes everything that is not unreserved, including /, ?, &, = and #, and is what you want for a single query parameter value or path segment. encodeURI leaves those structural characters intact because it assumes it is being handed a complete URL. Using encodeURI on a parameter value is how an ampersand inside a value ends up splitting the query string and truncating the data. This tool offers both modes and defaults to component encoding.

The plus sign problem

In the application/x-www-form-urlencoded format used by HTML form submissions, a space is encoded as +, not %20. In the path portion of a URL, + is a literal plus. The same byte means two different things depending on where it appears. A literal plus in a query value must always be written as %2B, otherwise it will very likely be read as a space. This is a frequent source of corrupted email addresses containing tagged aliases.

Double encoding

Encoding an already-encoded string turns %20 into %2520, because the percent character itself gets escaped. This happens when a value is encoded by application code and then again by a framework or a redirect layer. The visible symptom is literal %20 text appearing on a page. The decoder here detects the pattern and tells you when input appears to be encoded more than once.

Reserved characters worth memorising

Inside a query parameter value, escape & as %26, = as %3D, ? as %3F, # as %23, + as %2B, / as %2F and space as %20. The fragment character # is especially damaging unescaped, because everything after it is never sent to the server at all.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What is the difference between encodeURI and encodeURIComponent?

encodeURIComponent escapes structural characters such as / ? & = and #, so it is correct for a single query value or path segment. encodeURI leaves them intact because it expects a whole URL. Using encodeURI on a parameter value lets an ampersand inside the value split the query string.

Why does a plus sign in my URL become a space?

In form-encoded query strings a plus means a space by convention. To send a literal plus, encode it as %2B. This commonly corrupts email addresses with tagged aliases such as user+tag@example.com.

What is double encoding and how do I spot it?

Encoding an already-encoded string escapes the percent signs, turning %20 into %2520. The visible symptom is literal %20 text appearing in rendered output. Decode once and inspect: if the result still contains percent sequences, it was encoded twice.

Do I need to encode non-English characters?

Yes. Characters outside the permitted ASCII set are converted to UTF-8 bytes and percent-encoded byte by byte, so one character can become several sequences. Browsers display these decoded in the address bar, but the wire format is still encoded.

Is percent-encoding a security measure?

No. It ensures correct parsing, not safety. It does not prevent injection: you still need context-appropriate output escaping for HTML, SQL and shell commands. Treat it purely as a transport concern.

Privacy & Security

No data transmitted.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter a URL string and choose Encode or Decode.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.