Skip to content
Encoders & Decoders

Last updated:

URL Encode Online

URL encode text in seconds. Paste or type your text and this free tool replaces spaces and special characters with percent codes as you type, with an optional plus sign for spaces. Everything runs in your browser, so nothing is uploaded.

Plain text

0 characters · 0 lines

URL-encoded text

Loading tool
0 characters · 0 linesLive preview

Your text is processed in your browser and never uploaded.

More free tools you may need next.

How to use URL Encode

  1. 1

    Paste the text you want to encode

    Add the text to the left box. It's usually one value, such as a search phrase, a query parameter or a redirect address. Press Example for a quick sample.

  2. 2

    Check the result

    Percent codes appear on the right as you type. Spaces and symbols become codes such as %20. If you need the form-data style, tick Write spaces as + to get a plus sign instead of %20.

  3. 3

    Copy it into your URL

    Press Copy and paste the result into your URL. The swap button opens URL Decode, so you can check that the original text comes back.

What is URL encoding?

A URL can only contain a small set of characters, and some of them have special jobs: ? starts the query, & separates parameters, = joins a name to its value, # starts a fragment and / separates path segments. If your data contains one of these, or a space, or a letter such as é, it has to be rewritten before it goes into a URL.

URL encoding, also called percent-encoding, does exactly that. Each unsafe byte is written as a percent sign followed by two hexadecimal digits. A space becomes %20 and an ampersand becomes %26.

How percent-encoding works

The text is first turned into UTF-8 bytes, and every byte that isn't safe is written as %XX, where XX is the byte in hexadecimal. A plain ASCII character is one byte and gives one code. Other characters take several bytes and give several codes:

Text
space  ->  %20
&      ->  %26
é      ->  %C3%A9
€      ->  %E2%82%AC

That's why a single non-English letter can turn into two or three codes. The server that receives the URL puts the bytes back together and reads them as UTF-8.

A worked example

Say you want to pass this text as the value of a query parameter:

Text
name=Ali & Sara, city=Lahore?

Left as it is, the = and & would be read as part of the URL's own structure. Encoded, the whole text is safe:

Text
name%3DAli%20%26%20Sara%2C%20city%3DLahore%3F

Which characters stay unchanged?

This tool follows the behavior of JavaScript's encodeURIComponent. It leaves these characters as they are:

  • Letters A to Z and a to z
  • Digits 0 to 9
  • The symbols - _ . ! ~ * ' ( and )

Everything else is encoded, including spaces and the characters that have a special meaning in URLs: / ? : @ & = + $ , ; and #.

This tool encodes everything that has a special meaning in a URL. That is exactly right for a single value and wrong for a link you want people to click. Encode a complete address and its structure is gone:

Text
https://example.com/search?q=cats
https%3A%2F%2Fexample.com%2Fsearch%3Fq%3Dcats

The second line is no longer a working link. There is one important exception: when a complete address is itself the value of a query parameter, such as a redirect address, encode all of it.

Text
https://example.com/login?redirect=https%3A%2F%2Fexample.com%2Faccount%3Ftab%3Dsettings

Spaces: %20 or a plus sign?

Both appear in real URLs. %20 is understood everywhere, including in the path of a URL. A plus sign for a space belongs to HTML form data (application/x-www-form-urlencoded), which is also how many query strings are written. In a path, a plus is just a plus.

This tool writes %20 by default because it's always safe. Tick Write spaces as + when you need the form style. A real plus sign in your text is written as %2B either way, so it can never be mistaken for a space.

Common mistakes

  • Encoding twice. A % in text that is already encoded becomes %25, so %20 turns into %2520 and the server reads the wrong thing.
  • Leaving an & or = inside a value. The server then splits your value into several parameters.
  • Using + for spaces in a path. Outside form data, a plus sign is a real plus sign.
  • Encoding a complete link that people should click, instead of encoding only its values.
  • Pasting text that is already encoded. If it already contains codes such as %20, decode it first with URL Decode.

URL encoding in your own code

JavaScript
const text = "name=Ali & Sara, city=Lahore?";
const encoded = encodeURIComponent(text);

console.log(encoded); // name%3DAli%20%26%20Sara%2C%20city%3DLahore%3F
Python
from urllib.parse import quote

text = "name=Ali & Sara, city=Lahore?"
encoded = quote(text, safe="!*'()")

print(encoded)  # name%3DAli%20%26%20Sara%2C%20city%3DLahore%3F

Is it safe to paste private text here?

The encoding runs in your browser, and what you paste is not sent to our servers. The Privacy Policy has the details.

Frequently asked questions

Paste or type it into the left box. The percent-encoded version appears on the right straight away. Press Copy to use it.

Encode only the value, not the whole URL. Paste the value here, copy the result and put it after the equals sign, as in ?q=ENCODED_VALUE. Encoding is what stops an & or = inside the value from breaking the query.

%20 is the safe choice and works in every part of a URL. A plus sign for a space is only valid in HTML form data and query strings written in that style. This tool writes %20 by default, and the Write spaces as + option switches to the plus form.

encodeURI is for a complete URL and leaves characters such as / ? & and = alone. encodeURIComponent is for a single value and encodes them. This tool behaves like encodeURIComponent.

Letters, digits and the symbols - _ . ! ~ * ' ( ) stay as they are. Everything else is encoded.

You can, but the result won't work as a link, because the colon and the slashes are encoded too. Do it only when the whole URL is the value of another URL's parameter, such as a redirect address. For a link people should click, encode just the values you insert.

They are converted to UTF-8 bytes, and each byte is written as a percent code. For example, é becomes %C3%A9.

The text has half of an emoji or another character, which usually happens when a string is cut in the middle of a character. It can't be encoded. Remove the broken character and try again.

No. Everything runs in your browser and your text never leaves your device.