URL Encoder & Decoder

Encode and decode URL components safely in your browser.

  • Free
  • No signup
  • Runs in your browser
Mode

This uses URL-component semantics, not whole-URL parsing.

How it works

How to use

Choose Encode or Decode and enter one URL component.

Method

Browser-standard component encoding preserves URL delimiters outside the value.

Example

Encode hello world as hello%20world.

Encode the value before you assemble the URL

A URL uses characters such as &, =, ?, # and / as structure. If those same characters belong to a search term, filename or other value, they may need percent encoding so they are treated as data instead of delimiters. For example, the query value coffee & tea becomes coffee%20%26%20tea before it is placed after a parameter name.

SnakTool works at the component level with encodeURIComponent and decodeURIComponent. A practical pattern is to encode the individual value first and then place that encoded value into the URL structure that owns it.

Encode the value, then assemble the query
Value: coffee & tea
Encoded value: coffee%20%26%20tea
Query: ?q=coffee%20%26%20tea

A complete URL is not the same input as one component

A complete address contains syntax that must keep its structural role: the colon after a scheme, slashes around the host and path, a question mark before a query, ampersands between parameters and a hash before a fragment. Encoding the complete string as one component also escapes those delimiters.

For example, entering https://example.com/search?q=cat into this encoder treats the whole string as component data, so characters such as :, /, ? and = are percent-encoded. That can be correct when an entire URL must itself become a value inside another parameter, but it is not the same operation as preparing a normal navigable URL.

Whole string treated as component data
Input: https://example.com/search?q=cat
Encoded: https%3A%2F%2Fexample.com%2Fsearch%3Fq%3Dcat

Reserved characters can be structure or data

Percent encoding matters because the meaning of a character depends on where it appears. An ampersand can separate query parameters, while an ampersand inside a parameter value is ordinary data. A slash normally separates path segments, while a slash that belongs inside one encoded component may need to be represented as %2F.

Do not encode punctuation mechanically without knowing which component you are building. The receiving system's URL format determines whether a reserved character is acting as a delimiter or belongs to the value.

CharacterComponent encodingCommon structural role
space%20Whitespace inside a value
&%26Separates query parameters
=%3DSeparates a query key from its value
?%3FStarts a query
#%23Starts a fragment
/%2FSeparates path segments
%%25Begins a percent-encoded byte

Percent escapes represent UTF-8 bytes

Percent encoding is byte-oriented. For characters outside the unescaped ASCII set, encodeURIComponent first represents the text as UTF-8 and then writes escaped bytes as % followed by two hexadecimal digits. One visible Unicode character can therefore produce several percent escapes.

For example, é is UTF-8 bytes C3 A9 and becomes %C3%A9. Arabic text and emoji follow the same principle with their own multi-byte UTF-8 sequences. Decoding must reconstruct a valid character sequence from those bytes rather than treating every %XX escape as a complete character.

One character can require multiple escapes
Character: é
UTF-8 bytes: C3 A9
Encoded component: %C3%A9

A plus sign stays a plus in this decoder

HTML form-style query encoding has a convention where a space can be written as +. Component decoding with decodeURIComponent does not apply that convention: hello+world remains hello+world, while hello%20world becomes hello world.

This difference matters when copying values from form submissions or APIs that use application/x-www-form-urlencoded rules. If the producer defines + as a space, that form-decoding step belongs to the producer's format; this tool performs percent component decoding rather than form parsing.

Double encoding leaves %25 behind

A percent sign is itself encoded as %25. If hello world is encoded once, the result is hello%20world. Encoding that already encoded text again escapes the percent sign and produces hello%2520world.

Decoding removes one encoding layer at a time: %2520 becomes %20 after one pass, not a space. Repeatedly decoding until a value looks readable can change data that was intentionally encoded, so the expected number of layers should come from the system that produced the value.

One layer versus two
Original: hello world
Encoded once: hello%20world
Encoded twice: hello%2520world
One decode of %2520: %20

Malformed escapes are rejected instead of guessed

A percent escape needs two hexadecimal digits. Inputs such as %, %2 or %GG are malformed and cannot be decoded as percent-encoded components. SnakTool reports the malformed input rather than inventing a character.

A sequence can also have valid-looking %XX escapes but still describe an invalid UTF-8 byte sequence. decodeURIComponent rejects that case as well. Fix the source encoding instead of replacing bytes or repeatedly decoding an uncertain value.

Decoded does not mean safe to visit

Encoding and decoding transform text; they do not inspect the destination behind a URL. Turning %2Fadmin%3Fdelete%3Dtrue into /admin?delete=true only makes the component readable. It does not determine whether the path is trusted, authorized or safe.

This tool does not visit remote addresses, detect phishing, sanitize HTML, validate redirect destinations or make authorization decisions. Those checks belong to the application that uses the decoded value.

Frequently asked questions about URL Encoder & Decoder

Why does %252F decode to %2F rather than a slash?

The slash was encoded through two layers. %25 represents a percent sign, so one decode turns %252F into %2F. A second decode would produce / only when the surrounding data format actually requires another layer.

Does this tool encode an entire URL as a navigable address?

No. It applies component encoding with encodeURIComponent. If you paste a complete URL, its structural punctuation is treated as component data and encoded too.

What is URL encoding or percent encoding?

Percent encoding represents bytes that should not appear literally in a URL component as % followed by two hexadecimal digits. It lets data contain characters that could otherwise be confused with URL syntax.

How do I encode a query parameter value?

Encode the value itself first, then place the result after the parameter name and equals sign. For example, coffee & tea becomes coffee%20%26%20tea before it is inserted into ?q=... .

Why does & become %26?

An ampersand commonly separates query parameters. When the ampersand belongs inside one component value, encodeURIComponent writes it as %26 so it is treated as data.

Why does / become %2F?

A slash has a structural role as a path-segment separator. encodeURIComponent treats a slash inside the input component as data and percent-encodes it as %2F.

What is the difference between encodeURI and encodeURIComponent?

encodeURI is designed to preserve more punctuation that has structural meaning in a complete URI. encodeURIComponent escapes more of that punctuation because its input is treated as one component. SnakTool uses encodeURIComponent.

Does + mean a space in this URL decoder?

No. SnakTool uses decodeURIComponent, so a literal + remains +. If a producer uses form-style encoding where + means a space, that convention needs form-aware parsing.

Why does %2520 decode to %20 instead of a space?

One decoding pass removes one layer. %25 becomes %, leaving %20. Decode a second layer only when the format that produced the value explicitly requires it.

Can URL encoding handle Arabic, accented characters, and emoji?

Yes. encodeURIComponent uses UTF-8 percent encoding for Unicode text, so one visible character can become several %XX byte escapes.

Can I encode a redirect URL inside another URL?

Yes, when the receiving parameter is defined to contain a URL as its value. Encode that nested URL as component data, then place the encoded result into the outer URL. Follow the receiving service's specification so you do not add an unintended extra encoding layer.

What is the maximum input size for the URL encoder and decoder?

The current developer-text limit is 1,048,576 UTF-16 code units. Input above that limit is rejected before component encoding or decoding.

Browse all Developer Tools