URL encode and URL decode online: converts special characters to the percent-encoded %XX format and back, and decodes a whole link. Four modes: encodeURIComponent, encodeURI, strict RFC 3986 for OAuth and AWS signatures, and form encoding (URLSearchParams).
Examplesa whole address is for encodeURI, the other functions are for a parameter value
Result · encodeURIComponent
Result will appear here…
Input: 0 chars · Output: 0 chars
02
What each function encodes
encodeURIComponent is more aggressive — encodes everything except safe. encodeURI preserves URL structure.
Character
encodeURIComponent
encodeURI
A–Z a–z 0–9
Not encoded
Not encoded
- _ . ! ~ * ' ( )
Not encoded
Not encoded
: / ? # @ &
%3A %2F %3F %23 %40 %26
Not encoded
= + , ;
%3D %2B %2C %3B
Not encoded
Space
%20
%20
Cyrillic А–Я а–я
%D0%9F… (UTF-8)
%D0%9F… (UTF-8)
Chinese, Arabic, emoji
%XX%XX… (UTF-8)
%XX%XX… (UTF-8)
Strict RFC 3986 and form encoding
A parameter value can be written under three rules: encodeURIComponent, strict RFC 3986 for OAuth and AWS signatures, and HTML form encoding (URLSearchParams). The codes in the table are computed by the same functions the encoder above uses.
Character
encodeURIComponent
RFC 3986
Form
space
%20
%20
+
!
!
%21
%21
'
'
%27
%27
(
(
%28
%28
)
)
%29
%29
*
*
%2A
*
~
~
~
%7E
-
-
-
-
_
_
_
_
.
.
.
.
+
%2B
%2B
%2B
/
%2F
%2F
%2F
&
%26
%26
%26
=
%3D
%3D
%3D
?
%3F
%3F
%3F
#
%23
%23
%23
The rows where the modes differ are exactly five characters ! ' ( ) * plus the space and the tilde. Everything else is the same.
Every printable ASCII character
The codes are computed by the same functions the encoder above uses, not copied from a list. Red marks the 11 characters where the two functions disagree: encodeURI leaves them alone because they hold the syntax of the address together.
Character
Code
encodeURIComponent
encodeURI
RFC 3986
Form
RFC 3986 role
␠
%20
%20
%20
%20
+
unsafe
!
%21
!
!
%21
%21
sub-delimiter
"
%22
%22
%22
%22
%22
unsafe
#
%23
%23
#
%23
%23
general delimiter
$
%24
%24
$
%24
%24
sub-delimiter
%
%25
%25
%25
%25
%25
unsafe
&
%26
%26
&
%26
%26
sub-delimiter
'
%27
'
'
%27
%27
sub-delimiter
(
%28
(
(
%28
%28
sub-delimiter
)
%29
)
)
%29
%29
sub-delimiter
*
%2A
*
*
%2A
*
sub-delimiter
+
%2B
%2B
+
%2B
%2B
sub-delimiter
,
%2C
%2C
,
%2C
%2C
sub-delimiter
-
%2D
-
-
-
-
unreserved
.
%2E
.
.
.
.
unreserved
/
%2F
%2F
/
%2F
%2F
general delimiter
0
%30
0
0
0
0
unreserved
1
%31
1
1
1
1
unreserved
2
%32
2
2
2
2
unreserved
3
%33
3
3
3
3
unreserved
4
%34
4
4
4
4
unreserved
5
%35
5
5
5
5
unreserved
6
%36
6
6
6
6
unreserved
7
%37
7
7
7
7
unreserved
8
%38
8
8
8
8
unreserved
9
%39
9
9
9
9
unreserved
:
%3A
%3A
:
%3A
%3A
general delimiter
;
%3B
%3B
;
%3B
%3B
sub-delimiter
<
%3C
%3C
%3C
%3C
%3C
unsafe
=
%3D
%3D
=
%3D
%3D
sub-delimiter
>
%3E
%3E
%3E
%3E
%3E
unsafe
?
%3F
%3F
?
%3F
%3F
general delimiter
@
%40
%40
@
%40
%40
general delimiter
A
%41
A
A
A
A
unreserved
B
%42
B
B
B
B
unreserved
C
%43
C
C
C
C
unreserved
D
%44
D
D
D
D
unreserved
E
%45
E
E
E
E
unreserved
F
%46
F
F
F
F
unreserved
G
%47
G
G
G
G
unreserved
H
%48
H
H
H
H
unreserved
I
%49
I
I
I
I
unreserved
J
%4A
J
J
J
J
unreserved
K
%4B
K
K
K
K
unreserved
L
%4C
L
L
L
L
unreserved
M
%4D
M
M
M
M
unreserved
N
%4E
N
N
N
N
unreserved
O
%4F
O
O
O
O
unreserved
P
%50
P
P
P
P
unreserved
Q
%51
Q
Q
Q
Q
unreserved
R
%52
R
R
R
R
unreserved
S
%53
S
S
S
S
unreserved
T
%54
T
T
T
T
unreserved
U
%55
U
U
U
U
unreserved
V
%56
V
V
V
V
unreserved
W
%57
W
W
W
W
unreserved
X
%58
X
X
X
X
unreserved
Y
%59
Y
Y
Y
Y
unreserved
Z
%5A
Z
Z
Z
Z
unreserved
[
%5B
%5B
%5B
%5B
%5B
general delimiter
\
%5C
%5C
%5C
%5C
%5C
unsafe
]
%5D
%5D
%5D
%5D
%5D
general delimiter
^
%5E
%5E
%5E
%5E
%5E
unsafe
_
%5F
_
_
_
_
unreserved
`
%60
%60
%60
%60
%60
unsafe
a
%61
a
a
a
a
unreserved
b
%62
b
b
b
b
unreserved
c
%63
c
c
c
c
unreserved
d
%64
d
d
d
d
unreserved
e
%65
e
e
e
e
unreserved
f
%66
f
f
f
f
unreserved
g
%67
g
g
g
g
unreserved
h
%68
h
h
h
h
unreserved
i
%69
i
i
i
i
unreserved
j
%6A
j
j
j
j
unreserved
k
%6B
k
k
k
k
unreserved
l
%6C
l
l
l
l
unreserved
m
%6D
m
m
m
m
unreserved
n
%6E
n
n
n
n
unreserved
o
%6F
o
o
o
o
unreserved
p
%70
p
p
p
p
unreserved
q
%71
q
q
q
q
unreserved
r
%72
r
r
r
r
unreserved
s
%73
s
s
s
s
unreserved
t
%74
t
t
t
t
unreserved
u
%75
u
u
u
u
unreserved
v
%76
v
v
v
v
unreserved
w
%77
w
w
w
w
unreserved
x
%78
x
x
x
x
unreserved
y
%79
y
y
y
y
unreserved
z
%7A
z
z
z
z
unreserved
{
%7B
%7B
%7B
%7B
%7B
unsafe
|
%7C
%7C
%7C
%7C
%7C
unsafe
}
%7D
%7D
%7D
%7D
%7D
unsafe
~
%7E
~
~
~
%7E
unreserved
A special case is ! ' ( ) *: RFC 3986 calls them sub-delimiters, but encodeURIComponent comes from ECMAScript 3 and leaves them untouched. Inside a path or a file name they reach the server as they are.
Letters beyond Latin
Percent encoding works on bytes, not characters: a letter takes as many pairs as it takes bytes in UTF-8.
п
%D0%BF
2 bytes
ы
%D1%8B
2 bytes
中
%E4%B8%AD
3 bytes
😀
%F0%9F%98%80
4 bytes
03
About URL encoding
URL encoding (percent-encoding) represents any character in a URL using ASCII sequences like %XX, where XX is a UTF-8 byte in hex. Necessary because a URL can only contain a limited set of safe characters.
Choose the function by task: encodeURIComponent — for a single query parameter value. encodeURI — for a full URL when you need to preserve its syntax (colons, slashes, question marks).
Why not everyone encodes ! ' ( ) *. In RFC 3986 these five characters belong to sub-delims — they are allowed in an address, and encodeURIComponent leaves them alone. But OAuth 1.0a and AWS SigV4 signatures require “percent-encode everything except A–Z a–z 0–9 - _ . ~”: if even one of these characters stays as it is, the signature will not match and the server returns an error. That is why signatures and URL comparison need the strict mode. The tilde ~ is the opposite: in RFC 3986 it is unreserved and must not be encoded, although older libraries habitually turn it into %7E. Forms (application/x-www-form-urlencoded) use yet another set: a space becomes +, the tilde is encoded and the asterisk stays.
encodeURIComponent
most common
'hello world!' → hello%20world!
Encodes everything except letters, digits and `- _ . ! ~ * ' ( )`. Characters `: / ? # @ & =` are also encoded — so a parameter value won't break the URL structure. Use for query values ?q=… and form data.
encodeURI
for full URLs
'https://site.tld/path' → 'https://site.tld/path'
Preserves URL structure: does not encode `: / ? # [ ] @ ! $ & ' ( ) * + , ; =`. Use when you need to pass a full URL as a string without breaking its syntax.
Decoding
%D0%BF%D1%80%D0%B8%D0%B2%D0%B5%D1%82 → 'привет'
The inverse operation — turns %XX sequences back into readable text. Also supports the `+` for space format from HTML forms (application/x-www-form-urlencoded).
Percent-encoding
RFC 3986
%XX — where XX is the hex byte in UTF-8
Each unsafe character is written as `%XX`, where XX is the hex byte in UTF-8. Cyrillic takes 2 bytes (6 %XX%XX chars per letter), emoji up to 4 bytes.
04
Frequently asked questions
Paste the text and pick the encoding you need — the tool replaces every character a URL cannot carry with a percent sequence. A space becomes `%20`, a slash `%2F`, and non-Latin letters expand to two or three pairs each, because percent encoding works on UTF-8 bytes rather than on characters.
RFC 3986 allows the characters `! ' ( ) *` in an address, so the standard function leaves them alone. But OAuth 1.0a and AWS SigV4 signatures require encoding everything except letters, digits and `- _ . ~`: if even one of those five stays as it is, the signature will not match and the server returns an error. The Strict RFC 3986 mode here encodes them too and keeps the tilde.
They differ in what they leave alone. `encodeURI` preserves `: / ? # & =` because it is meant for a whole address. `encodeURIComponent` encodes those too, because it is meant for a single parameter value that may itself contain slashes or ampersands. Using the wrong one is how query strings end up split in the wrong places.
A plus is how an HTML form encodes a space under `application/x-www-form-urlencoded`, and by convention it is accepted in query strings; elsewhere in a URL a space is `%20`. Form and address encoding differ in more than that: a form encodes the tilde as `%7E` and leaves the asterisk alone. To check what actually went out in a request, choose the As a form mode. Decoding here works out whether `+` is a space or a plus.
Because the string was encoded twice. `%25` is the encoded form of the percent sign itself, so `%25D0` is what a first-pass decode leaves behind when `%D0` had already been encoded once. Run the decode again and the original text appears — double encoding almost always means two layers of code each escaped the same value.
No. Encoding and decoding run in your browser and the address never leaves the device. That matters more here than elsewhere: links routinely carry authorisation tokens, API keys and session identifiers, and pasting one into a service that processes text server-side hands over working access. Only the name of the opened tool is sent.