%url-decoder.net

URL Decoder

Paste a percent-encoded URL or string to decode it as you type. See every %XX sequence, catch double encoding, and break the query string into parameters.

Runs in your browser. Nothing is uploaded.
Direction
Try
126 chars · 126 bytes
Decoded output
https://shop.example.com/search?q=café au lait&tags=coffee,paris&next=https%3A%2F%2Fshop.example.com%2Fcart
107 chars · 108 bytes
The result still contains percent-encoded sequences such as %3A %2F. The input was probably encoded more than once.

Each encoded run is split into characters. Multi-byte UTF-8 sequences are grouped, so %C3%A9 shows as one character.

https://shop.example.com/search?q=café%C3%A9U+00E9␠%20U+0020au␠%20U+0020lait&tags=coffee,%2CU+002Cparis&next=https%%25U+00253A%%25U+00252F%%25U+00252Fshop.example.com%%25U+00252Fcart
Share links keep your text after the #, which browsers never send to a server.

What URL decoding does

URL decoding (percent-decoding) turns each %XX sequence back into the byte it stands for, then reads those bytes as UTF-8 text. %20 becomes a space, %2F becomes /, and the two bytes %C3%A9 become é.

A plus sign means a space only in form data (application/x-www-form-urlencoded). Everywhere else it is a literal +, which is why the Scope setting matters. To go the other way, use the URL Encoder.

Pick the right scope

Component

One value: a query parameter, a path segment, a token. Matches encodeURIComponent.

Full URL

A whole address. Keeps : / ? # & = intact. Matches encodeURI.

Form data

HTML form submissions and most query strings, where + means a space.

Common percent-encoded characters

Full percent-encoding table
CharacterEncodedencodeURIComponentencodeURIWhy it matters
space%20EncodesEncodesForm data may use + instead
"%22EncodesEncodesBreaks HTML attributes if left raw
#%23EncodesKeepsStarts the fragment; cuts a value short
%%25EncodesEncodesSeeing %25 often means double encoding
&%26EncodesKeepsSeparates query parameters
+%2BEncodesKeepsRead as a space in form data
,%2CEncodesKeepsSub-delimiter; often safe in values
/%2FEncodesKeepsPath separator; some servers reject %2F
:%3AEncodesKeepsSeparates scheme and port
=%3DEncodesKeepsSeparates a key from its value
?%3FEncodesKeepsStarts the query string
@%40EncodesKeepsSeparates user info from the host

Decode a URL in code

decodeURIComponent("caf%C3%A9%20au%20lait");
// "café au lait"

// Query strings: URLSearchParams also turns + into a space
new URLSearchParams("q=caf%C3%A9+au+lait").get("q");

decodeURIComponent throws URIError on a stray % or invalid UTF-8.

When decoding goes wrong

Questions

Should a space be %20 or +?

Both appear, in different places. %20 is valid anywhere in a URL. + means a space only in application/x-www-form-urlencoded data, such as HTML form submissions and many query strings. In a path, + is a literal plus sign. Choose the Form data scope to decode + as a space.

Why does my URL contain %2520?

It was encoded twice. The first pass turned a space into %20; the second pass encoded the % sign itself as %25. Decode it twice to read it (the tool offers this automatically), then fix the code that encodes an already-encoded value.

What is the difference between decodeURI and decodeURIComponent?

decodeURIComponent decodes every escape sequence. decodeURI is meant for whole URLs and leaves escapes for reserved characters such as %2F, %3F, %26 and %23 untouched, so the decoded URL keeps its structure. The Component and Full URL scopes match the two functions.

Why do I get “URI malformed”?

decodeURIComponent throws this when a % is not followed by two hex digits, or when the decoded bytes are not valid UTF-8, for example %E9 produced from Latin-1 text. This tool shows the exact position, and Lenient mode decodes everything else while leaving the bad sequence as it is.

Is my data sent to a server?

No. Decoding and encoding run in your browser with JavaScript. Nothing you paste is uploaded or logged, files you open are read locally, and the tool keeps working offline once the page has loaded.

Behaviour checked against RFC 3986, the WHATWG URL Standard and MDN. Updated October 3, 2026