What URL encoding is
A web address may only contain a small set of characters: letters, digits and a few symbols such as -, ., _ and ~. Other characters have special jobs. ? starts the query string, & separates parameters, = joins a name to a value and # starts a fragment. Spaces and letters outside English are not allowed at all.
URL encoding, also called percent encoding, solves this. Each unsafe character is converted to UTF-8 bytes, and each byte is written as % plus two hex digits. A space becomes %20, & becomes %26 and é becomes %C3%A9.
How to use the URL encoder
Encode. Type or paste text into Plain text. The encoded version appears in URL encoded. Press Copy to take it.
Decode. Paste encoded text into URL encoded. The readable text appears on the left.
Choose what you are encoding with the menu under the boxes:
- A value or part of a URL (encodeURIComponent) is the right choice most of the time. It encodes everything except letters, digits and
- _ . ~. Use it for search terms, parameter values and path segments. - A full URL, keep : / ? & = (encodeURI) leaves the structure of the address alone and only encodes spaces, non-English letters and similar characters.
- Form data, spaces as + (x-www-form-urlencoded) matches what a browser sends when you submit an HTML form. Spaces become
+, and when decoding,+turns back into a space.
Clear empties both boxes.
How it works
The text is first turned into UTF-8 bytes. Each byte that is not allowed is replaced by % and its value in hexadecimal. The letter é is two bytes in UTF-8, so it becomes two escapes: %C3%A9. An emoji is four bytes, so it becomes four escapes.
This tool goes a step further than the plain browser function in component mode. It also encodes ! ' ( ) *, following RFC 3986. Those characters are technically allowed but have caused problems in some servers and email clients.
Decoding works in reverse. Runs of %XX sequences are collected into bytes and read as UTF-8.
Examples
| Input | Component | Full URL | Form data |
|---|---|---|---|
hello world |
hello%20world |
hello%20world |
hello+world |
Tom & Jerry |
Tom%20%26%20Jerry |
Tom%20&%20Jerry |
Tom+%26+Jerry |
a+b=c |
a%2Bb%3Dc |
a+b=c |
a%2Bb%3Dc |
50% off |
50%25%20off |
50%25%20off |
50%25+off |
café |
caf%C3%A9 |
caf%C3%A9 |
caf%C3%A9 |
it's (ok)*! |
it%27s%20%28ok%29%2A%21 |
it's%20(ok)*! |
it%27s+%28ok%29%2A%21 |
A full address shows the difference best. https://example.com/a b?q=1&r=é in full URL mode becomes https://example.com/a%20b?q=1&r=%C3%A9, which still works as a link. In component mode the same text becomes https%3A%2F%2Fexample.com%2Fa%20b%3Fq%3D1%26r%3D%C3%A9, which is right only when the whole address is itself a parameter value, such as a redirect target.
Tips and limits
- Encode values, not whole links. Build the link first, then encode only the pieces you insert.
- Watch for double encoding. If you see
%2520, the text was encoded twice. Decode it once. - + is not always a space. It means space only in form data. In a path,
+is a plain plus sign. Pick the matching mode before decoding. - Encoding is not hiding. Anyone can read encoded text. Do not put passwords in links.
- Case does not matter in escapes.
%c3%a9and%C3%A9mean the same thing. Upper case is the common style.
Other ways to do it
JavaScript. encodeURIComponent('Tom & Jerry') returns Tom%20%26%20Jerry. Use decodeURIComponent to reverse it. Note that it throws an error on a broken sequence such as %zz, while this tool leaves it in place.
Python. urllib.parse.quote('Tom & Jerry', safe='') returns Tom%20%26%20Jerry, and urllib.parse.quote_plus returns Tom+%26+Jerry.
Excel. =ENCODEURL(A1) percent-encodes the text in cell A1 (Excel 2013 and later on Windows).
Command line. curl --data-urlencode "q=Tom & Jerry" encodes a form value as it sends it.
Related tools
Building campaign links? The UTM generator encodes every tag for you. To turn a title into a clean path, use the slug generator. For binary data inside a URL, Base64 encoding with the URL-safe option is often a better fit.