What is URL decoding?
URL decoding turns percent codes back into the characters they stand for. %20 becomes a space, %26 becomes an ampersand and %C3%A9 becomes the letter é. It's the reverse of URL Encode.
Percent-encoding exists because URLs can only carry a small set of characters. Whenever something else has to travel inside a URL, it is written as codes, and decoding is how you read it again.
Where percent codes come from
- Search queries and filters in a browser's address bar.
- Redirect and return addresses passed as parameters, such as a login page remembering where you came from.
- Server logs and analytics reports, which store addresses the way they were requested.
- Links copied from email or chat apps.
- API requests that carry text in the query string.
A worked example
A value copied from a query string:
name%3DAli%20%26%20Sara%2C%20city%3DLahore%3FAfter decoding, it reads:
name=Ali & Sara, city=Lahore?Non-English text works the same way. The text caf%C3%A9 decodes to café, because the two codes %C3 and %A9 are the two UTF-8 bytes of the letter é.
When a plus sign means a space
In a standard URL, a plus sign is an ordinary character. In HTML form data (application/x-www-form-urlencoded), which is also how many query strings are written, a plus sign stands for a space. Which one you have depends on where the text came from.
The order matters. Plus signs must be turned into spaces before the percent codes are decoded. If you decode first, a real plus sign that was written as %2B becomes a + and would then be mistaken for a space. This is what the Treat + as a space option does:
Input: C%2B%2B+guide
Option off (default): C+++guide
Option on: C++ guideDouble-encoded text
Sometimes text is encoded twice, for example when an address is passed as a parameter inside another address. A space then appears as %2520, because the % of %20 was itself encoded as %25.
If you know the text was encoded twice, paste the result back in to decode the second layer. Decode only as many times as the text was encoded. If you're not sure, stop after one round and check where the text came from, because decoding too far turns text that was meant to contain a literal %20 into a space.
Why decoding fails
These are the usual reasons a string can't be decoded:
- A % that isn't followed by two hexadecimal digits, such as the stray percent sign in
100%. - Codes that don't form valid UTF-8. A single code such as
%E9is not a complete character in UTF-8. It usually comes from an older system that used Latin-1. - Text that was never encoded. A literal percent sign, for example in a discount of 50%, can't be told apart from the start of a code.
URL decoding in your own code
const encoded = "C%2B%2B+guide";
// Plain percent-decoding: a plus sign stays a plus sign
console.log(decodeURIComponent(encoded)); // C+++guide
// Form data: turn + into a space first, then decode
console.log(decodeURIComponent(encoded.replace(/\+/g, " "))); // C++ guidefrom urllib.parse import unquote, unquote_plus
encoded = "C%2B%2B+guide"
print(unquote(encoded)) # C+++guide
print(unquote_plus(encoded)) # C++ guideIs it safe to paste private text here?
Decoding runs in your browser, and what you paste is not sent to our servers. That makes it a sensible place to read links that contain tokens or personal details. The Privacy Policy has the details.