URL Decoder
Paste a percent-encoded URL or string to decode it as you type. See every %XX sequence, catch double encoding, and break the query string into parameters.
%3A %2F. The input was probably encoded more than once.Each encoded run is split into characters. Multi-byte UTF-8 sequences are grouped, so %C3%A9 shows as one character.
What URL decoding does
URL decoding (percent-decoding) turns each %XX sequence back into the byte it stands for, then reads those bytes as UTF-8 text. %20 becomes a space, %2F becomes /, and the two bytes %C3%A9 become é.
A plus sign means a space only in form data (application/x-www-form-urlencoded). Everywhere else it is a literal +, which is why the Scope setting matters. To go the other way, use the URL Encoder.
Pick the right scope
Component
One value: a query parameter, a path segment, a token. Matches encodeURIComponent.
Full URL
A whole address. Keeps : / ? # & = intact. Matches encodeURI.
Form data
HTML form submissions and most query strings, where + means a space.
Common percent-encoded characters
Full percent-encoding table| Character | Encoded | encodeURIComponent | encodeURI | Why it matters |
|---|---|---|---|---|
| space | %20 | Encodes | Encodes | Form data may use + instead |
| " | %22 | Encodes | Encodes | Breaks HTML attributes if left raw |
| # | %23 | Encodes | Keeps | Starts the fragment; cuts a value short |
| % | %25 | Encodes | Encodes | Seeing %25 often means double encoding |
| & | %26 | Encodes | Keeps | Separates query parameters |
| + | %2B | Encodes | Keeps | Read as a space in form data |
| , | %2C | Encodes | Keeps | Sub-delimiter; often safe in values |
| / | %2F | Encodes | Keeps | Path separator; some servers reject %2F |
| : | %3A | Encodes | Keeps | Separates scheme and port |
| = | %3D | Encodes | Keeps | Separates a key from its value |
| ? | %3F | Encodes | Keeps | Starts the query string |
| @ | %40 | Encodes | Keeps | Separates user info from the host |
Decode a URL in code
decodeURIComponent("caf%C3%A9%20au%20lait");
// "café au lait"
// Query strings: URLSearchParams also turns + into a space
new URLSearchParams("q=caf%C3%A9+au+lait").get("q");decodeURIComponent throws URIError on a stray % or invalid UTF-8.
from urllib.parse import unquote, unquote_plus
unquote("caf%C3%A9%20au%20lait") # 'café au lait'
unquote_plus("caf%C3%A9+au+lait") # + becomes a spaceunquote leaves + alone; unquote_plus is for form data.
import java.net.URLDecoder;
import java.nio.charset.StandardCharsets;
URLDecoder.decode("caf%C3%A9%20au%20lait", StandardCharsets.UTF_8);
// "café au lait"URLDecoder follows form rules, so it also turns + into a space. The Charset overload needs Java 10+.
rawurldecode("caf%C3%A9%20au%20lait"); // "café au lait"
urldecode("caf%C3%A9+au+lait"); // + becomes a spacerawurldecode leaves + alone; urldecode is for form data.
import "net/url"
s, err := url.PathUnescape("caf%C3%A9%20au%20lait")
// s == "café au lait"
q, err := url.QueryUnescape("caf%C3%A9+au+lait") // + becomes a spaceBoth return an error for malformed escapes instead of panicking.
using System;
Uri.UnescapeDataString("caf%C3%A9%20au%20lait");
// "café au lait"UnescapeDataString leaves + alone; WebUtility.UrlDecode treats it as a space.
When decoding goes wrong
Questions
Should a space be %20 or +?
Both appear, in different places. %20 is valid anywhere in a URL. + means a space only in application/x-www-form-urlencoded data, such as HTML form submissions and many query strings. In a path, + is a literal plus sign. Choose the Form data scope to decode + as a space.
Why does my URL contain %2520?
It was encoded twice. The first pass turned a space into %20; the second pass encoded the % sign itself as %25. Decode it twice to read it (the tool offers this automatically), then fix the code that encodes an already-encoded value.
What is the difference between decodeURI and decodeURIComponent?
decodeURIComponent decodes every escape sequence. decodeURI is meant for whole URLs and leaves escapes for reserved characters such as %2F, %3F, %26 and %23 untouched, so the decoded URL keeps its structure. The Component and Full URL scopes match the two functions.
Why do I get “URI malformed”?
decodeURIComponent throws this when a % is not followed by two hex digits, or when the decoded bytes are not valid UTF-8, for example %E9 produced from Latin-1 text. This tool shows the exact position, and Lenient mode decodes everything else while leaving the bad sequence as it is.
Is my data sent to a server?
No. Decoding and encoding run in your browser with JavaScript. Nothing you paste is uploaded or logged, files you open are read locally, and the tool keeps working offline once the page has loaded.
Behaviour checked against RFC 3986, the WHATWG URL Standard and MDN. Updated October 3, 2026
Related tools
URL Encoder
Percent-encode a value, a full URL or form data, with strict RFC 3986 and +/%20 options.
URL Parser
Split a URL into scheme, host, port, path, query and fragment, with checks for common problems.
Query String Parser
Edit query parameters as a table, rebuild the string, or export it as JSON.
Base64 Encode/Decode
Convert text to Base64 and back, including the URL-safe Base64URL alphabet.
HTML Encode/Decode
Escape text to HTML entities and decode entities back to text.
JWT Decoder
Read a JSON Web Token's header and payload and check its expiry.