A URL encoder that distinguishes a URL from a value inside one

The classic single-box URL encoder has been at the same address for twenty years and still works, which is more than can be said for most things on the web. It also encodes one way, and the bug that actually costs people an afternoon is caused by picking the wrong way.

Open the URL Encoder →

the meyerweb URL Decoder and Softland, side by side

 the meyerweb URL DecoderSoftland
Encoding a whole URLOne mode, applied to whatever you pasteSeparate mode - structural characters are preserved
Encoding a value to put inside a URLSame modeSeparate mode - slashes, colons and ampersands are escaped
DecodingYesYes
UnicodeHandledUTF-8, matching what browsers and servers expect
Where it runsIn the pageIn the page

Two encodings that look identical until they are not

Encoding a URI leaves the characters that give a URL its structure alone: the colon after the scheme, the slashes between path segments, the question mark that starts the query, the ampersands between parameters. That is right when you are cleaning up a whole address that happens to contain a space or an accented character.

Encoding a URI component escapes those same characters, because in that context they are not structure - they are data that must survive being embedded inside somebody else structure. Get this backwards and the symptom is specific and maddening: everything works until a value contains an ampersand, at which point the receiving end reads one parameter as two and the second half of your value vanishes.

The redirect parameter is where this always bites

A login page that takes ?next=/dashboard is fine until the destination has a query string of its own. Now you are putting a URL inside a URL, and the inner one has to be component-encoded or its question mark terminates the outer query and its ampersands split it. Half the open-redirect bugs and most of the lost-return-path bugs in the world start here.

The same applies to anything carrying a URL as a value: OAuth redirect_uri, tracking links wrapping a destination, webhook callbacks, and the share links that social buttons build. If a URL is the value of a parameter, it is a component, and it needs the encoding that escapes structure rather than the one that protects it.

Why a space is sometimes a plus sign

Percent-encoding turns a space into %20. The plus sign comes from a different specification - the form encoding browsers use when submitting a query string - where a space is a plus and a literal plus must itself be escaped. Both are correct, in their own context, which is why they coexist and confuse everyone.

The practical rule: in a path, a space is always %20. In a query string, %20 is accepted everywhere and a plus is accepted by most things, so %20 is the safer choice when you are building the URL yourself. If you are decoding something that came from a form submission and pluses are appearing in your text, that is what happened.

When the meyerweb URL Decoder is the better choice

  • You want the fastest possible decode of a string you already understand, from a page that has not changed or broken in two decades.
  • You are working with a tool or specification that expects form encoding, where a plus rather than %20 is the correct output.
  • You have it bookmarked, which is a perfectly good reason.

Frequently asked questions

What is the difference between encoding a URI and a URI component?
Encoding a URI keeps the characters that make it a URL - the colon, slashes, question mark and ampersands - intact. Encoding a component escapes them, because there they are data rather than structure. Use the second whenever the result is going to sit inside a parameter value.
Why does a space become %20 sometimes and a plus other times?
Percent-encoding produces %20. Form encoding, used when browsers submit a query string, produces a plus. Both appear in the wild. %20 is accepted in every context, so prefer it when you are constructing the URL yourself.
Do I need to encode a URL I am putting in a redirect parameter?
Yes, as a component. Otherwise its question mark ends your query string and its ampersands split it into parameters the receiving end will misread.
Is anything sent to a server?
No. Both directions use the encoding functions built into your browser, so the value stays in the page.

Try it yourself

Percent-encode and decode URLs and query strings.

Open the URL Encoder

the meyerweb URL Decoder is a trademark of its respective owner. Softland is not affiliated with, endorsed by or sponsored by the meyerweb URL Decoder. This comparison reflects how each product works rather than what either costs, because pricing and plan limits change; check the meyerweb URL Decoder’s own site for its current terms.