URL Decoder
Turn %20 back into a space. If you paste a full URL, the query parameters are also split into a readable table.
How to use the URL Decoder
- Paste the encoded string or the whole URL.
- Leave Treat + as a space switched on for form data; switch it off if a literal plus sign matters.
- Press Decode. Paste a full URL and the query parameters are listed separately.
Spotting double encoding
If your decoded output still contains %20 or %26, the string was encoded twice. It happens when a value is escaped once when built and again when placed into a link. The signature is %25 in the input — that is an encoded percent sign, which means the escapes themselves got escaped.
The fix is to decode repeatedly until the output stops changing, then correct the code that encodes twice. This tool flags the pattern when it sees it, but decodes only one layer per press so you can watch what each pass removes.
The plus sign problem
There is no way to know from a string alone whether + means a space or a literal plus. Context decides: in a form body it is a space, in a URL path it is a plus, and in a query string it depends on who built the URL.
This matters for real data. A phone number written +15551234 decodes to 15551234 with the option on. If your decoded output has a suspicious leading space or a missing plus, switch the option off and decode again.
Frequently asked questions
Why does it say the escape sequence is broken?
A percent sign must be followed by exactly two hexadecimal digits. Text like "100% cotton" contains a percent that is not an escape, so decoding fails. Encode the percent as %25 first.
Can it decode a full URL safely?
Yes. Decoding a whole URL is safe to read, but do not use the decoded form as a link — the reserved characters are no longer escaped, so the address may be ambiguous.
Where did the query parameter table go?
It only appears when the decoded text looks like a complete URL with a scheme and a query string. A bare fragment of text has nothing to split.
Is anything sent to a server?
No. Decoding uses the browser's built-in decodeURIComponent, so URLs containing session tokens or personal data stay on your machine.
Related tools
Percent-encode text for URLs, query strings and form data.
Decode Base64 back to text, with automatic URL-safe detection.
Format, indent and validate JSON with precise error locations.
Convert Unix timestamps to dates and back, in any time zone.
Turn titles into clean, URL-safe slugs.