Encode or decode URLs and query string values using percent-encoding (encodeURIComponent).
Plain text / URL
Encoded output
URLs can only contain a limited set of ASCII characters. Any other character, including spaces, ampersands, equals signs, and slashes, must be percent-encoded. This is critical for query string values: a URL like ?q=hello world will break without encoding.
encodeURI encodes a full URL, leaving characters like /, ?, &, = intact because they have meaning in a URL structure. encodeURIComponent encodes everything except letters, digits, and - _ . ! ~ * ' ( ), making it the right choice for individual query parameter values.
Space → %20 (or + in form data), & → %26, = → %3D, # → %23, + → %2B, / → %2F, ? → %3F. Knowing these by sight helps when reading encoded URLs manually.
Double encoding happens when an already-encoded string is encoded again: %20 becomes %2520. Always decode first before re-encoding. Double-encoded URLs often cause 400 Bad Request errors on servers.
HTML forms use application/x-www-form-urlencoded, which encodes spaces as + rather than %20 and uses & between parameters. This differs slightly from URL encoding, so be aware of the difference when constructing requests manually.
Non-ASCII characters (e.g. Chinese, Arabic, accented letters) are first converted to UTF-8 bytes, then each byte is percent-encoded. So the Chinese character 中 becomes %E4%B8%AD. Most modern browsers display the decoded version in the address bar for readability.
Encode text for safe use in a URL, or decode a percent-encoded string back to readable text. Results update instantly as you type.
Encode: "hello world"
hello%20world
Encode: "price=£10&qty=5"
price%3D%C2%A310%26qty%3D5
Decode: "caf%C3%A9"
café
Decode: "100%25%20off"
100% off
How percent-encoding works
"hello world" → "hello%20world"
Percent-encoding was first formalised in the URL specification RFC 1738 in 1994. Non-ASCII characters such as Chinese, Arabic, or accented letters are first converted to UTF-8 bytes, then each byte is percent-encoded. Most modern browsers display the decoded version in the address bar for readability, even though the underlying URL uses percent-encoding.
Encode text when placing it inside a URL and it may contain spaces, punctuation, non-ASCII characters, or reserved symbols. Encoding turns characters into percent sequences so software can transport them unambiguously. Encode a query parameter value rather than blindly encoding an entire URL that already contains its scheme, separators, and parameter structure.
URL encoding changes a representation for safe transport; it does not hide information. Anyone can decode a percent-encoded value. Do not put passwords, access tokens, or other secrets in a URL, because URLs can appear in browser history, server logs, analytics, referrer headers, and copied messages even when the text is encoded.
A percent-encoded space is represented as %20. In form-style query strings, a plus sign can also mean a space, while a literal plus may need encoding so it is not misread. Follow the format expected by the receiving application and decode only once; repeated encoding is a common cause of confusing values.
Encode individual path segments or query parameter values, not the separators that give the URL its structure. Keep the scheme, host, slashes, question mark, and ampersands intact when assembling a URL. Decode a value only once and inspect the final URL before sending it to an application.