Percent-encode text for URLs — with the component-vs-whole-URL distinction made explicit,
because that’s the choice that breaks links — and decode anything back, live, with +-as-space
handled the way query strings actually work.
How to use it
- Pick Encode or Decode.
- Encoding: say whether it’s a value going into a URL or a whole URL — the modes escape differently, and the labels explain what each keeps.
- Paste; copy the live result.
The distinction every broken link traces back to
encodeURIComponent and encodeURI exist because “encode this for a URL” means two different
things. A value — someone’s email in ?to=, a redirect URL in ?next= — must have its
&, =, ?, and / escaped, or it silently splits into extra parameters (the classic bug
where everything after an & in a name vanishes). A whole URL needs the opposite: leave
the structure alone, escape only what can’t appear raw (spaces, quotes, non-ASCII). Pick wrong
in one direction and links break; in the other, parameters leak. The radio buttons here ARE the
documentation.
Decoding what the logs gave you
Query strings arrive percent-encoded and often form-encoded on top (+ for spaces). The
decoder handles both at once, and tells you plainly when a stray % isn’t valid encoding
rather than throwing cryptic errors. Nested encodings unwrap one layer per pass — if %25
appears, decode again. Base64 chunks inside your URL parameters (state tokens, callbacks) go
to the Base64 decoder; decoded JSON payloads read best through
the JSON formatter.
Private by design
URLs carry session tokens, emails, and internal hostnames. Everything here runs in your browser — nothing you paste is transmitted or kept.