← Back to Tools

URL Encoder / Decoder

Percent-encode or decode URLs, query values, and callback strings in your browser.

Encoding runs locally in your browser. Your URL is not uploaded.

Input: 0 characters

Output

Encoded or decoded text will appear here.

URL encoder and decoder for query strings

Percent-encode a query value or a full URL, and decode an encoded string back to readable text. Use it for webhook callback URLs, OAuth redirect_uri values, and API query parameters. Encoding runs in your browser.

What is percent-encoding?

Percent-encoding is the rules in RFC 3986 for putting arbitrary characters into a URI. Reserved characters such as ?, &, =, and # have structural meaning. If they appear inside a value, they must be encoded or the parser will split the URL in the wrong place.

hello world becomes hello%20world. a&b=c as a single parameter value becomes a%26b%3Dc.

encodeURIComponent vs encodeURI

Query value uses encodeURIComponent. Encode each parameter value on its own, then join with &. This is the right choice for search text, redirect URLs, and filter expressions.

Full URL uses encodeURI. It leaves :/?#&= in place so the URL still has a scheme, path, and query. Use it when the input is already a complete URL that only needs unsafe characters escaped.

How to encode or decode a URL

  1. 1. Paste the text. That can be a raw query value, a full URL, or an already encoded string.
  2. 2. Choose the encode mode. Query value for a single component. Full URL when the string includes the scheme and query structure.
  3. 3. Encode or decode. Copy the output into the request, the fixture, or the documentation example.

Where developers hit encoding bugs

  • OAuth redirect_uri. The callback must be encoded as one parameter value. A raw ? inside it splits the query.
  • Webhook URLs. Signed payloads and callback query strings fail verification when a character was encoded twice or left raw.
  • Spaces and plus signs. Form encoding writes spaces as +. A literal plus must be %2B.
  • Double encoding. Encoding an already encoded value turns %20 into %2520. Decode once and compare.

Inspect the request that carried the URL with the request catcher, then decode the query here. More utilities are on the developer tools page.

Related tools

  • Developer tools — JSON, JWT, timestamps, and the rest of the free toolkit.
  • JSON Formatter — format a body after you build the request URL.
  • JWT Decoder — read a bearer token that arrived on an encoded callback.
  • Request catcher — capture the HTTP request and see the raw query string.

Frequently asked questions

What is URL encoding?
URL encoding, also called percent-encoding, replaces characters that are not allowed in a URL with a percent sign and two hex digits. A space becomes %20, and a question mark inside a query value becomes %3F. This keeps the URL structure intact while still sending the original characters.
What is the difference between encodeURI and encodeURIComponent?
encodeURIComponent encodes a single value, such as a query parameter or a path segment. It encodes &, =, ?, and /. encodeURI encodes a full URL and leaves those structural characters alone so the URL still parses. Use component encoding for values. Use full-URL encoding only when the string is already a complete URL.
Does this URL encoder run in my browser?
Yes. Encoding and decoding happen locally with the browser’s built-in encodeURI, encodeURIComponent, and decodeURIComponent functions. The text you paste is not uploaded.
Should spaces be %20 or +?
In a URL path or in encodeURIComponent output, a space is %20. In HTML form bodies and some query strings that use application/x-www-form-urlencoded, a space is written as +. Turn on “Use + for spaces” when you are matching form encoding. Decoding accepts both.
Why did decoding fail?
Decoding fails when a percent sign is not followed by two hexadecimal digits, for example a stray % or %ZZ. Fix the input or encode the raw string again. A literal percent sign in text must be encoded as %25.
Can I use this for webhook and OAuth URLs?
Yes. Callback URLs, redirect_uri values, and signed query strings all break when a character is left raw. Encode the parameter value, then paste the result into the request. Decode a logged URL when you need to read the original query.