Skip to main content

URL Decoder

Decode percent-encoded URLs and query strings. Handles + as space, repeated encoding, and points at the exact character when a value is broken.

This tool runs entirely in your browser. Nothing you enter is sent to our servers, so there is nothing for us to store or see.

About the URL Decoder

Turn a percent-encoded URL or parameter back into readable text. Paste a whole address, a single query-string value, or a redirect parameter that has been through three systems on its way to you.

Three things make this more useful than a one-line call to decodeURIComponent. First, errors say where: a malformed escape is reported with its position and an explanation, rather than the bare "URI malformed" that tells you nothing about a two-thousand character tracking URL. Second, plus signs are treated as spaces by default, because that is how form data and query strings are encoded — and a genuinely encoded plus, written %2B, still comes back as a plus. Third, repeated encoding is handled: analytics and single sign-on redirects routinely encode a value two or three times, and one option decodes until the value stops changing.

When the result is a complete URL, it is broken into its parts underneath — scheme, host, path, each query parameter separately, and the fragment. That is usually the reason you were decoding it in the first place.

How to use the URL Decoder

  1. Paste the encoded value

    A whole URL or just one parameter — both work. Decoding starts as soon as you stop typing.

  2. Choose how to treat plus signs

    Leave it on for query strings and form data, where + means a space. Turn it off when decoding a path segment or a value where a literal plus matters.

  3. Turn on repeat decoding if needed

    If the result still contains %25 sequences, it was encoded more than once. Repeat decoding keeps going until the value settles.

  4. Read the breakdown

    When the decoded value is a URL, its scheme, host, path, parameters and fragment are listed separately below the boxes.

Frequently asked questions

Why does my decoded URL still contain %20?

Because it was encoded more than once. Each round of encoding turns the % of the previous round into %25, so %2520 is a space encoded twice and %252520 three times. Turn on repeat decoding and the tool keeps going until the value stops changing.

Should + be treated as a space?

In a query string or form submission, yes — that is what application/x-www-form-urlencoded specifies. In a path segment, no: a plus there is a literal plus. The option exists because there is no way to tell from the text alone which context a value came from.

What does "invalid UTF-8" mean when decoding?

The percent sequences are well formed but the bytes they produce do not make a valid character — usually because the value was encoded from one character set and is being decoded as another, or because a multi-byte character was cut in half when the string was truncated.

Is URL encoding the same as Base64?

No. Percent encoding replaces individual unsafe characters with a % and two hex digits, leaving the rest readable, and it makes text slightly longer. Base64 re-encodes all the bytes into a 64-character alphabet and makes data about a third longer. Both are encodings, neither is encryption.

Is anything sent to a server?

No. Decoding happens entirely in your browser and nothing is transmitted or stored, which matters because query strings frequently carry session tokens, email addresses and single sign-on parameters.