Dev Toolbox · Windows 10 and 11
URL encode and decode text
Make text safe to put in a link, or turn an address full of %20, %3D and %C3%A9 back into words you can read. Choose whether you are encoding a single value or a whole address, and the result updates as you type, on your own PC.
How to URL encode or decode text
- 1
Open URL encode & decode
Type url into the search box on Octoolo's home screen and open URL encode & decode, or find it under Data in the Dev Toolbox.
- 2
Pick Encode or Decode
Set Direction. Decode turns every %XX sequence back into its character, and + into a space.
- 3
Say what you are encoding
Leave Keep the address's own characters (: / ? & =) off for a single value, such as a search term or a link that goes inside a parameter. Turn it on to tidy a whole address that contains spaces or accented letters.
- 4
Copy the result
Paste your text into Input and press Copy above Result.
What percent-encoding does
A URL can only carry a limited set of characters, and some of those have jobs: ? starts the query, & separates parameters, = joins a name to its value, # starts the fragment and / separates path segments. Anything else, and any of those characters used as plain data, is written as a percent sign followed by two hex digits for each byte.
| Character | Encoded | Why |
|---|---|---|
| space | %20 | A space ends the link in emails, chats and logs |
| & | %26 | Would start a new parameter |
| = | %3D | Would split a name from its value |
| / | %2F | Would start a new path segment |
| é | %C3%A9 | Two bytes in UTF-8 |
| 😀 | %F0%9F%98%80 | Four bytes in UTF-8 |
Letters, digits and - _ . ~ are never encoded. Like the encodeURIComponent function browsers use, Octoolo also leaves ! * ' ( ) alone, since URLs allow them.
One value or a whole address: the switch that matters
The most common URL-encoding bug is encoding the wrong amount.
- A value going into a URL (switch off). Searching for fish & chips? The value must become fish%20%26%20chips, so the & is not read as the start of another parameter. The same goes for a whole link passed as a parameter, like a return_url or a redirect_uri: as a value, https://example.com/?q=1 becomes https%3A%2F%2Fexample.com%2F%3Fq%3D1.
- A whole address (switch on). Here the : / ? & = have to stay, or the link stops working. Only spaces and non-ASCII letters are encoded, so https://example.com/a b?q=café&x=1 becomes https://example.com/a%20b?q=caf%C3%A9&x=1.
Encode a whole address with the switch off and you get one long string no browser can open. Encode a value with it on and any & or = inside the value slips through and breaks the parameters. When you build a URL by hand, encode each value on its own, then join the pieces.
Decoding, plus signs and double encoding
Decoding reverses it: each %XX sequence is read as UTF-8 and turned back into its character. Octoolo also turns + into a space, because HTML forms and many analytics tools write spaces that way (the application/x-www-form-urlencoded format). A real plus sign in data should arrive as %2B, which decodes to + as it should. A literal + in a path, as in some file names, will come back as a space.
If the result still contains %20 or %3A, the text was encoded twice. %2520 is a % (which itself encodes to %25) followed by 20. Decode again until the percent signs are gone. This happens a lot with redirect links that pass through several services, each adding a layer.
A % that is not followed by two hex digits, or bytes that do not form valid UTF-8, stop decoding with "This text has a broken % sequence." Look for a lone % in the text, such as 50% off, which should have been encoded as 50%25.
Other ways to do it on Windows
PowerShell has both directions built in. [uri]::EscapeDataString("fish & chips") encodes a value, the same as the switch-off mode here, and [uri]::UnescapeDataString() decodes. [System.Net.WebUtility]::UrlDecode() decodes and also treats + as a space. In Excel, the ENCODEURL function encodes a cell's text for use in a query string. Browsers do some of it for you: the address bar shows accented letters as letters, but copying the address gives you the encoded form, which is why a pasted link can look different from the one you saw.
Those suit scripts. For reading a messy tracking link, an OAuth redirect or a log line with nested encodings, a live two-pane view is quicker: paste, read, decode again if needed. When the text you are pulling apart turns out to be a token, hand it to the JWT decoder or Base64. For clean addresses made of words and hyphens, Text Studio has a slug generator.
Questions, answered
Should spaces be %20 or +?
In the path of a URL, always %20. In a query string most servers understand both, since + is how form data writes a space. Octoolo encodes spaces as %20, which is safe everywhere, and decodes both.
What is the difference between URL encoding and percent-encoding?
None. Percent-encoding is the name used in the URL standard, RFC 3986; URL encoding is what most people call it.
Do I need to encode non-English characters?
Browsers display them, but what they send is the encoded form, and many systems accept only that. Encoding writes the UTF-8 bytes: ü becomes %C3%BC, and the Chinese character 中 becomes %E4%B8%AD.
Is URL encoding a way to hide or protect data?
No. Anyone can decode it, and the values still end up in browser history and server logs. Keep passwords and tokens out of URLs whenever you can.
Can it decode a whole URL with its parameters?
Yes. Paste the full address and choose Decode: everything that was encoded comes back, and the : / ? & = that were never encoded stay as they are.
URL encode and decode, and 16 more apps.
Download for Windows7 days free, then from $3.99 a month for all 17 apps. Windows 10 and 11.