Putting a link inside a query parameter
A redirect target has to be encoded in value mode, otherwise its own query string merges into the outer one and the redirect goes somewhere unexpected.
Percent-encode and decode URLs in your browser, choosing between encoding a value inside a URL and encoding a whole address.
Maintained by Roshan.
Percent-encoding, done in the tab. Component mode escapes the separators that structure a URL; full-address mode leaves them alone.
Find related browser-local tools for nearby tasks without starting another search.
Browse all developer and data toolsPercent-encoding looks like one operation and is actually two, which is why so many broken links trace back to it. Encoding a value that will sit inside a URL must escape the characters that give a URL its structure. Encoding an entire address must leave those same characters alone, or the address stops working. Pick the wrong one and the failure is quiet: the string looks encoded, the request goes out, and the server receives something subtly different from what you meant. This page keeps the two modes separate, names them in plain language, and shows exactly which characters they disagree about.
A redirect target has to be encoded in value mode, otherwise its own query string merges into the outer one and the redirect goes somewhere unexpected.
An address copied from a document often contains spaces. Address mode escapes those and leaves the structure intact, so the link works.
Decoding turns a wall of percent escapes back into readable text, which makes it obvious what a request actually carried.
Decode once and look at the result. If it still contains percent escapes, it was encoded twice somewhere upstream.
No. Encoding and decoding both run in your browser using standard string functions. Nothing is transmitted, which matters because URLs frequently contain tokens and identifiers.
If the string will be placed inside a larger URL, choose value mode. If the string is itself a complete address, choose address mode. When unsure, look at the list of differing characters shown with the result.
Almost always an unpaired percent sign. A literal percent in text must itself be written as %25; otherwise the decoder reads the next two characters as a hex code and gives up when they are not.
%20 is correct percent-encoding and works in both paths and query strings. The plus form comes from HTML form encoding and is only understood in a query string, so %20 is the safer default.
Double encoding. A space became %20, then that string was encoded again, turning its percent sign into %25. Find the step that encodes twice rather than trying to fix the output.
Encode UTF-8 text to standard Base64 or decode Base64 back to Unicode text locally in your browser, with strict malformed and non-text error handling.
Decode a JSON Web Token and inspect claims and expiry in your browser. Your token is never transmitted.
Produce SHA-1, SHA-256, SHA-384, or SHA-512 digests from text in your browser using Web Crypto. Nothing is uploaded, so pasting sensitive text is safe.
Make a QR code from a link or any text in your browser. No redirects, no expiry, no account, and nothing sent to a server.
Decode a QR code from a photo or screenshot and read its destination as text before following it. Runs in your browser.
Turn a URL query string into readable JSON in your browser. Repeated keys become arrays rather than being lost.
Turn a JSON object into a properly encoded URL query string in your browser, with arrays repeated correctly.