/tools/url-encoder

URL Encoder

Escape characters that would otherwise break a URL. Pick the mode that matches where the text is going — a query value, a whole URL, or a form body.

URL EncoderRuns in your browser
Encoding mode

Escapes everything unsafe, including &, =, ? and /. Use this for a single parameter value.


How to use the URL Encoder

  1. Paste the text you want to put into a URL.
  2. Choose a mode: Query value for one parameter, Whole URL for a full address, Form data for a POST body.
  3. Press Encode and copy the result.

Choosing the right mode

The mode matters more than people expect, and picking the wrong one is the most common source of broken links.

InputQuery valueWhole URL
a&ba%26ba&b
x/yx%2Fyx/y
hello worldhello%20worldhello%20world

Encoding a whole URL in Query value mode destroys it — the :// and every slash get escaped. Encoding a single value in Whole URL mode leaves & intact, so a value containing an ampersand silently splits into two parameters. That is how a search for "salt & pepper" turns into a search for "salt" plus a mystery parameter called "pepper".

Why spaces have two encodings

In a path or query string, a space is %20. In a form body sent as application/x-www-form-urlencoded, it is +. Both are correct in their own context, and servers generally accept either in a query string — but + in a URL path means a literal plus sign, not a space. When in doubt, %20 is safe everywhere.

Encoding is not sanitising

Percent-encoding makes text safe to transport in a URL. It does not make it safe to use. A URL-encoded string can still carry an SQL injection payload, a path traversal sequence or a script tag once decoded on the far side. Validate and escape at the point of use as well.

Frequently asked questions

Which characters never need encoding?

Letters A–Z and a–z, digits 0–9, and the four marks hyphen, underscore, period and tilde. Everything else is either reserved or unsafe depending on position.

How are emoji and accented letters handled?

They are converted to UTF-8 bytes first, then each byte becomes a percent-escape. That is why a single emoji expands to four escape sequences.

Should I encode the same string twice?

No. Double-encoding turns % into %25, so %20 becomes %2520 and the receiver gets a literal "%20" rather than a space. Encode exactly once, at the point the value is placed into the URL.

Does encoding hide what I am sending?

Not at all. Percent-encoding is trivially reversible and is visible in server logs, browser history and proxies. It is a formatting rule, not a privacy measure.

Related tools