Programming tool

URL Encoder & Decoder

Apply or remove percent encoding for a single URL component or a complete URL without sending your text anywhere.

Encodes query values, path segments, and other individual parts, including reserved characters.

Processed locally. Text is never fetched, executed, or rendered as HTML. A plus sign stays +; this tool does not apply form-encoding rules.

What is URL encoding?

URL encoding, also called percent encoding, represents characters as a percent sign followed by two hexadecimal digits for each UTF-8 byte. It lets URLs carry spaces, Unicode, and characters that otherwise have structural meaning.

Why URLs need percent encoding

Characters such as spaces are not valid literally everywhere in a URL. A space becomes %20. Reserved characters such as ?, &, and = separate parts of a URL, so whether they should be encoded depends on whether you are processing a component or a complete URL.

encodeURI vs encodeURIComponent

encodeURI is for a complete URL and preserves its structural delimiters. encodeURIComponent is for one value or segment and encodes those delimiters so they become data rather than URL syntax. The matching decode operations reverse those rules.

Component: name=Calquo & tools becomes name%3DCalquo%20%26%20tools

URL encoding is not Base64

Percent encoding makes text safe in URL contexts and leaves many ordinary characters readable. Base64 represents bytes with a separate 64-character alphabet and is not a substitute for correct URL component encoding.

Frequently asked questions

Does a plus sign mean a space?

Only under application/x-www-form-urlencoded conventions, commonly used for form bodies and query strings. The JavaScript URI functions used here leave plus signs unchanged.

Why can decoding fail?

Every percent sign must be followed by two hexadecimal digits, and encoded byte sequences must form valid Unicode text. Inputs such as %, %2, and %ZZ are malformed.

Is my URL sent anywhere?

No. The browser processes your input locally. This tool never opens, requests, or executes an entered URL.

How the URL encoder and decoder works

Choose one of four operations, paste your text, and press Encode or Decode. Encode component and Decode component use the browser's encodeURIComponent and decodeURIComponent functions, which are meant for a single value such as a query parameter or path segment. Encode full URL and Decode full URL use encodeURI and decodeURI, which leave the characters that give a URL its structure untouched.

The tool never fetches, opens, or renders the text you enter; it is treated purely as a string. If a decode operation meets a malformed sequence, such as a lone % or %ZZ, it reports an error rather than returning partial output. Plus signs are left as they are in both directions because the JavaScript functions follow RFC 3986 rather than the form-encoding rules that turn spaces into +.

What percent encoding is

A URL can only contain a limited set of ASCII characters. Anything else, including spaces, quotes, and every non-English character, has to be written as one or more escape sequences. Percent encoding, defined in RFC 3986, converts a character to its UTF-8 bytes and writes each byte as a percent sign followed by two hexadecimal digits. A space is one byte, 0x20, so it becomes %20. A check mark is three UTF-8 bytes, so it becomes %E2%9C%93.

space (0x20) → %20
✓ (U+2713, UTF-8 E2 9C 93) → %E2%9C%93
name=Calquo & tools ✓ → name%3DCalquo%20%26%20tools%20%E2%9C%93

Decoding reverses the process: each %XX pair is turned back into a byte and the bytes are interpreted as UTF-8. The letters, digits, hyphen, underscore, period, and tilde are called unreserved characters and are never encoded because they have no special meaning anywhere in a URL.

encodeURIComponent versus encodeURI

The two functions differ only in which characters they leave alone. encodeURIComponent escapes everything except letters, digits, and - _ . ! ~ * ' ( ). Use it on each individual value before you assemble a URL, so that an ampersand or slash inside a value cannot be mistaken for a separator. encodeURI additionally preserves ; , / ? : @ & = + $ # so that an existing URL keeps working after encoding; it only fixes spaces, non-ASCII characters, and other clearly unsafe characters.

The decode functions mirror that split. decodeURIComponent decodes every valid %XX sequence. decodeURI decodes most sequences but deliberately leaves %23, %26, %3D, %3F, and the other reserved characters encoded, because decoding them would change the structure of the URL.

encodeURI: https://calquo.app/search?q=hello world#results → https://calquo.app/search?q=hello%20world#results
encodeURIComponent: hello world&more → hello%20world%26more

One caveat: encodeURIComponent leaves ! ' ( ) * unencoded even though RFC 3986 lists them as reserved sub-delimiters. Most servers accept them literally, but if you need strict RFC 3986 output, replace those five characters with %21 %27 %28 %29 %2A afterwards.

Reserved characters in a URL

RFC 3986 reserves a set of characters that act as delimiters. Whether one of them needs encoding depends on its role: a question mark that starts the query string must stay literal, but a question mark inside a search term must become %3F or the server will cut the value short. The same applies to every character in the list below.

  • : / ? # [ ] @ – general delimiters that separate scheme, host, path, query, and fragment
  • ! $ & ' ( ) * + , ; = – sub-delimiters used inside the query string, path parameters, and user info
  • % – the escape character itself, which must be written as %25 when it appears literally
  • Space, quotes, < > \ ^ ` { | } – not allowed in a URL at all and always encoded

Common pitfalls

Double encoding is the most frequent problem. If a value is encoded once to %20 and then passed through an encoder again, the percent sign itself is escaped and the result is %2520, which decodes back to the literal text %20. Encode each value exactly once, right before it is inserted into the URL, and decode it exactly once on the receiving side.

Running a complete URL through encodeURIComponent breaks it, because the :// and ? are converted to %3A%2F%2F and %3F. Conversely, using encodeURI on a single value leaves an embedded ampersand alone and silently splits the parameter. Finally, HTML form submissions and many query-string libraries use application/x-www-form-urlencoded, which writes spaces as + rather than %20; a + that reaches this tool is kept as a literal plus sign, so convert it to %20 first if it was meant to be a space.

Frequently asked questions

What is the difference between encodeURI and encodeURIComponent?

encodeURIComponent encodes everything except letters, digits, and - _ . ! ~ * ' ( ), so it is safe for a single query value or path segment. encodeURI also leaves ; , / ? : @ & = + $ # untouched so a complete URL keeps its structure.

What does %20 mean in a URL?

%20 is the percent-encoded form of a space. The hexadecimal value 20 is the ASCII code for the space character, which is not allowed to appear literally in a URL.

Should a space be %20 or a plus sign?

Use %20 in paths and in any context governed by RFC 3986. The plus sign stands for a space only in application/x-www-form-urlencoded data, such as HTML form submissions and query strings parsed by form-aware servers. This tool always uses %20 and leaves + unchanged.

Which characters need to be URL encoded?

Everything except the unreserved characters A–Z, a–z, 0–9, hyphen, underscore, period, and tilde, unless the character is being used for its structural meaning. Spaces, non-ASCII text, and reserved characters used as data must always be encoded.

Why does decoding fail with a URI malformed error?

Every percent sign must be followed by exactly two hexadecimal digits, and the decoded bytes must form valid UTF-8. Inputs such as 100%, %2, %ZZ, or a lone %C3 are malformed and cannot be decoded.

Is URL encoding the same as HTML encoding?

No. URL encoding writes bytes as %XX so they can travel inside a URL, while HTML encoding uses entities such as &amp; and &lt; so characters display in a web page. An ampersand is %26 in a URL and &amp; in HTML.