URL Parser
Break a URL into its parts, list its query parameters, strip tracking codes to get the canonical form, and decode punycode host names.
Components
- Scheme
- —
- Host
- —
- Subdomain
- —
- Port
- —
- Path
- —
- Fragment
- —
Query parameters
None.
Canonical URL
Related tools
All Webmaster tools →This tool runs entirely in your browser. Nothing you enter is sent to our servers, so there is nothing for us to store or see.
About the URL Parser
Paste a URL and see everything it contains: scheme, host, port, path segments, every query parameter separately, and the fragment. Long URLs with thirty parameters are why this exists — reading one by eye is how you miss the parameter you were looking for.
Tracking parameters are identified and can be stripped. The list covers Google Analytics and Ads, Meta, Microsoft, TikTok, LinkedIn, Mailchimp, HubSpot and a dozen others. What is left is the canonical URL — the one that belongs in a canonical tag, the one worth sharing, and the one two links should be compared on. Two URLs that differ only by a utm_source are the same page, and treating them as different is how analytics reports fragment and how duplicate content appears where there is none.
Punycode host names are decoded. A URL class stores an internationalised domain as xn--bcher-kva.example, which is unreadable — and unreadable is exactly how a homograph attack survives inspection. The readable form is shown alongside, with a warning.
Credentials embedded before the host are flagged too. That form is how a link disguises which site it really points at, and modern browsers strip or block it for that reason.
How to use the URL Parser
-
Paste a URL
With or without the scheme — https is assumed if you leave it off. Parsing happens as you type.
-
Read the components
Scheme, host, port, path and fragment are listed separately, with the path broken into segments.
-
Check the parameters
Every query parameter is listed with its decoded value. Tracking parameters are marked so you can see what is campaign data and what is content.
-
Take the canonical form
The canonical URL has the tracking removed, the parameters sorted and any redundant default port dropped. Copy it for a canonical tag or for sharing.
Frequently asked questions
What is a canonical URL and why remove tracking parameters?
The canonical URL is the single address that identifies a page, ignoring anything that only records how someone arrived. A page reached with utm_source=newsletter and one reached with utm_source=twitter are the same page. Search engines can treat the two as duplicates, and analytics that does not normalise them splits one page's figures across dozens of rows.
Why is the parameter order changed in the canonical form?
So that two URLs with the same parameters in a different order come out identical. ?a=1&b=2 and ?b=2&a=1 request exactly the same resource from every server that follows the specification, and sorting makes that visible. Turn sorting off if the order matters to the application you are working with — a few signed URLs depend on it.
What is punycode and why is it a security concern?
Punycode encodes an internationalised domain name into ASCII, so bücher.example becomes xn--bcher-kva.example. The concern is homograph attacks: some Cyrillic and Greek letters are visually identical to Latin ones, so a name can be registered that looks exactly like a familiar brand but is a different domain. Browsers show punycode for mixed-script names for this reason, and the tool decodes it so you can see both forms.
What does a URL with a username and password in it mean?
It is HTTP basic authentication credentials, from a form of URL that predates modern login. It is also the classic phishing disguise — https://[email protected] looks like your bank but goes to attacker.example, because everything before the @ is credentials. Most browsers now strip or block it entirely.
Is the URL I paste sent anywhere?
No. Parsing runs entirely in your browser and nothing is transmitted or stored — which matters, because URLs from a log or an email routinely carry session tokens, reset links and personal identifiers.