URL Decoder
Decode percent-encoded URLs and query strings. Handles + as space, repeated encoding, and points at the exact character when a value is broken.
Related tools
All Developer tools →This tool runs entirely in your browser. Nothing you enter is sent to our servers, so there is nothing for us to store or see.
About the URL Decoder
Turn a percent-encoded URL or parameter back into readable text. Paste a whole address, a single query-string value, or a redirect parameter that has been through three systems on its way to you.
Three things make this more useful than a one-line call to decodeURIComponent. First, errors say where: a malformed escape is reported with its position and an explanation, rather than the bare "URI malformed" that tells you nothing about a two-thousand character tracking URL. Second, plus signs are treated as spaces by default, because that is how form data and query strings are encoded — and a genuinely encoded plus, written %2B, still comes back as a plus. Third, repeated encoding is handled: analytics and single sign-on redirects routinely encode a value two or three times, and one option decodes until the value stops changing.
When the result is a complete URL, it is broken into its parts underneath — scheme, host, path, each query parameter separately, and the fragment. That is usually the reason you were decoding it in the first place.
How to use the URL Decoder
-
Paste the encoded value
A whole URL or just one parameter — both work. Decoding starts as soon as you stop typing.
-
Choose how to treat plus signs
Leave it on for query strings and form data, where + means a space. Turn it off when decoding a path segment or a value where a literal plus matters.
-
Turn on repeat decoding if needed
If the result still contains %25 sequences, it was encoded more than once. Repeat decoding keeps going until the value settles.
-
Read the breakdown
When the decoded value is a URL, its scheme, host, path, parameters and fragment are listed separately below the boxes.
Frequently asked questions
Why does my decoded URL still contain %20?
Because it was encoded more than once. Each round of encoding turns the % of the previous round into %25, so %2520 is a space encoded twice and %252520 three times. Turn on repeat decoding and the tool keeps going until the value stops changing.
Should + be treated as a space?
In a query string or form submission, yes — that is what application/x-www-form-urlencoded specifies. In a path segment, no: a plus there is a literal plus. The option exists because there is no way to tell from the text alone which context a value came from.
What does "invalid UTF-8" mean when decoding?
The percent sequences are well formed but the bytes they produce do not make a valid character — usually because the value was encoded from one character set and is being decoded as another, or because a multi-byte character was cut in half when the string was truncated.
Is URL encoding the same as Base64?
No. Percent encoding replaces individual unsafe characters with a % and two hex digits, leaving the rest readable, and it makes text slightly longer. Base64 re-encodes all the bytes into a 64-character alphabet and makes data about a third longer. Both are encodings, neither is encryption.
Is anything sent to a server?
No. Decoding happens entirely in your browser and nothing is transmitted or stored, which matters because query strings frequently carry session tokens, email addresses and single sign-on parameters.