URL Encoder/Decoder
Paste a percent-encoded link below and this url decoder turns it back into readable text, or encode plain text so it's safe to drop into a URL.
About
About URL Encoder/Decoder
A url decoder reverses percent-encoding, the %XX sequences that stand in for characters a URL isn't allowed to carry directly, like a space or an ampersand. This url encoder decoder works in the other direction too, turning a string of plain text into a format that survives being passed around as part of a web address without breaking anything downstream.
The URL spec, RFC 3986, only permits a specific set of ASCII characters inside a URL: letters, digits, and a handful of symbols like - . _ ~. Everything else gets converted into its UTF-8 byte sequence and each byte is written as a percent sign followed by two hex digits, which is why a single accented letter can turn into something like %C3%A9 once encoded.
There's a small but real inconsistency worth knowing about: a space in a URL path gets encoded as %20, but in a query string built with the older application/x-www-form-urlencoded convention, a space is often written as a plus sign instead. This tool handles both conventions correctly depending on where in the URL the text sits.
Paste a link or a string of text and pick a direction. Decoding unpacks every %XX sequence back into its original character, including multi-byte UTF-8 sequences for emoji and non-Latin scripts. Encoding does the reverse, safely wrapping anything outside the allowed character set.
This comes up constantly when you're staring at a tracking link, a session parameter, or an OAuth redirect URL that's been encoded so many times it's unreadable. Running it through here strips that back to plain text in one pass, and since the conversion happens in your browser, a sensitive token in that URL never gets logged anywhere outside your own tab.
FAQ
Frequently asked questions
Why do URLs need encoding in the first place?
Because a URL can only legally contain a narrow set of ASCII characters under RFC 3986. A space, an ampersand used outside its reserved role, or any non-ASCII letter has to be represented as a percent-encoded byte sequence so servers and browsers interpret the link consistently.
What's the actual difference between encodeURI and encodeURIComponent?
encodeURI leaves reserved characters like / and & alone because it assumes you're encoding a full URL. encodeURIComponent escapes those too, since it assumes you're encoding a single value, like a query parameter, that might itself contain those characters.
Why do I sometimes see a plus sign instead of %20 for a space?
That's a quirk of the application/x-www-form-urlencoded format used in form submissions and query strings, where a plus sign is the historical stand-in for a space. Percent-encoding with %20 is the more general-purpose rule used everywhere else in a URL.
Can this decode non-English characters and emoji?
Yes. Non-ASCII characters get encoded as their UTF-8 byte sequence, and this tool decodes the full multi-byte sequence back into the correct character, not just single bytes.
Is it safe to decode a link with a session token or password reset code in it?
Yes, decoding happens entirely in your browser's JavaScript, so nothing you paste gets sent to a server or logged anywhere.
Why does a URL sometimes look double-encoded, with %25 appearing in it?
%25 is the encoded form of the percent sign itself. If a URL gets encoded twice, every original percent sign turns into %25, which is a common bug when a link passes through more than one system that each try to encode it.
Related tools
View all developer tools →Hash Generator (MD5/SHA-256)
Generate MD5, SHA-1 and SHA-256 hashes from text or files on your device.
Open toolJWT Decoder
Decode a JWT to read its header, payload, claims and expiry.
Open toolUUID/GUID Generator
Generate v4 UUIDs or GUIDs in bulk, in the format you prefer.
Open toolText to Binary Converter
Convert plain text to binary code and back.
Open tool