URL Encoder

Percent-encode a value so it survives inside a URL, or decode a URL full of %20 and %3A back into something readable.

Runs entirely in your browser. Nothing is uploaded.

Why URLs need encoding

A URL has a grammar. Characters like ?, &, =, /, # and space are structural - they separate the path from the query, one parameter from the next, and the URL from its fragment. When one of those characters appears inside a value rather than between them, it has to be escaped or it will be read as structure and quietly break the address.

The classic failure is a search term containing an ampersand. Passing colour & light unencoded creates a second parameter named light out of nothing, and the value your server receives is truncated at the ampersand. Percent-encoding turns it into %26, which arrives as data instead of punctuation.

Encoding a component versus a whole URL

These are two different operations and picking the wrong one is the usual source of confusion. Encoding a component escapes everything structural, because the whole string is a value going into one slot. Encoding a full URL leaves the structural characters alone, because they are doing their job, and escapes only what would be illegal in an address.

The rule of thumb: if you are inserting a value into a query string, encode it as a component. If you are cleaning up an address that a user typed with a space in it, encode it as a full URL. Encoding a whole URL as a component produces a string where https%3A%2F%2F appears - which is correct when that URL is itself a parameter value, as with a redirect_uri, and wrong everywhere else.

Spaces, plus signs and Unicode

Space encodes as %20 in a path, but form submissions historically encode it as a plus sign in the query string. Both are seen in the wild, which is why a decoder has to know which context it is in - a literal plus sign in a value must itself be encoded as %2B, or it will decode back into a space and silently corrupt the data.

Non-ASCII characters are encoded as their UTF-8 bytes, so a single accented character becomes two percent-escapes and an emoji becomes four. That is expected, and it round-trips exactly.

Frequently asked questions

What is the difference between encoding a URI and a URI component?
Component encoding escapes reserved characters such as &, = and ? because the whole string is a single value. Full-URI encoding leaves those characters intact because they are structural, and escapes only illegal ones such as spaces.
Why does a space become %20 sometimes and a plus sign other times?
Percent-twenty is the standard encoding for a space. The plus sign comes from HTML form submissions, which use it in query strings. A literal plus sign must be encoded as %2B to avoid being decoded back into a space.
Do I need to encode a URL that goes in a redirect parameter?
Yes, and as a component. A URL used as a parameter value must have its colons and slashes escaped, otherwise the receiving server reads them as part of its own address structure.
Is anything sent to a server?
No. Encoding and decoding happen entirely in your browser, so URLs containing tokens or internal hostnames stay on your machine.