Skip to content
TNToolsNexus

URL encode / decode

Percent-encode values or whole URLs and decode them back — component vs full-URL modes explained, live, free, private.

Direction
What are you encoding?

Your text never leaves your browser — encoding happens on your device.

Percent-encode text for URLs — with the component-vs-whole-URL distinction made explicit, because that’s the choice that breaks links — and decode anything back, live, with +-as-space handled the way query strings actually work.

How to use it

  1. Pick Encode or Decode.
  2. Encoding: say whether it’s a value going into a URL or a whole URL — the modes escape differently, and the labels explain what each keeps.
  3. Paste; copy the live result.

encodeURIComponent and encodeURI exist because “encode this for a URL” means two different things. A value — someone’s email in ?to=, a redirect URL in ?next= — must have its &, =, ?, and / escaped, or it silently splits into extra parameters (the classic bug where everything after an & in a name vanishes). A whole URL needs the opposite: leave the structure alone, escape only what can’t appear raw (spaces, quotes, non-ASCII). Pick wrong in one direction and links break; in the other, parameters leak. The radio buttons here ARE the documentation.

Decoding what the logs gave you

Query strings arrive percent-encoded and often form-encoded on top (+ for spaces). The decoder handles both at once, and tells you plainly when a stray % isn’t valid encoding rather than throwing cryptic errors. Nested encodings unwrap one layer per pass — if %25 appears, decode again. Base64 chunks inside your URL parameters (state tokens, callbacks) go to the Base64 decoder; decoded JSON payloads read best through the JSON formatter.

Private by design

URLs carry session tokens, emails, and internal hostnames. Everything here runs in your browser — nothing you paste is transmitted or kept.

Last updated:

Frequently asked questions

Component or whole-URL mode — which do I need?
Encoding a VALUE going into a URL (a search term, a redirect target, an email in a query string) → component mode, which escapes &, =, ?, and / so they can't break the URL's structure. Encoding a complete URL that should stay a working URL → whole-URL mode, which escapes spaces and Unicode but leaves the structural characters alone.
Why does %20 sometimes appear as + instead?
Two encodings share the street: percent-encoding proper uses %20 for a space, while HTML form submissions historically use +. The decoder here treats + as a space, which matches what you're usually pasting (query strings); if you genuinely need a literal plus, it arrives encoded as %2B anyway.
What does "malformed percent-encoding" mean?
A % in the input isn't followed by two hex digits — usually a truncated paste or a raw % that was never encoded (like "100%"). Real encoded text always has %XX pairs.
Can I double-encode by accident?
Easily — encoding an already-encoded string turns %20 into %2520, the classic broken-link signature. If you see %25 in your output, the input was already encoded; decode it first.
Is anything uploaded?
No — encoding and decoding run entirely in your browser.

Related tools

Base64 Encode / Decode

Encode text to Base64 and decode it back — Unicode-safe, URL-safe variant included, instant, and nothing leaves your browser.

JSON Formatter

Format, validate, and minify JSON as you paste — 2/4-space or tab indentation, clear syntax errors, copy or download. Private.

Case Converter

Convert text to UPPERCASE, lowercase, Title Case, Sentence case, and more — instantly, in your browser, with one-click copy.