Skip to content
Quaestio

URL encoder

Encode text that has to go into a web address, or turn an encoded address back into readable text.

0 characters · 0 bytes

Result

Type something in the field above.

As a single component, slashes and question marks are encoded too. Without the tick the address structure is preserved and only illegal characters are escaped.

Embed

Embed this tool on your site

Copy the code and paste it where the tool should appear, such as a blog post or a school page. It is free, the box has no ads and the tool calculates in the visitor’s browser.

How it works

Web addresses may only contain a limited set of characters. Everything else is written as a percent sign followed by the character’s value in hexadecimal, which is why a space becomes %20.

The difference between the two modes is what counts as structure. Encoding a single component also encodes slashes, question marks and equals signs, because they would otherwise be read as parts of the address.

Encoding a whole address leaves those characters alone so the structure survives. Use that mode on a finished address that merely contains a few characters needing escape.

Choose the wrong mode for a parameter and the receiver may read one value as several. A value going after an equals sign should almost always be encoded as a single component.

The plus sign is a trap: in the query part of an address it historically means a space, while in the path it means an actual plus.

The functions behind the modes

Component mode uses JavaScript’s encodeURIComponent and decodeURIComponent, and whole-address mode encodeURI and decodeURI, all four defined in the ECMAScript standard. Each character to be encoded is first turned into UTF-8, and each byte is written as a percent sign and two hexadecimal digits. As a component, fish & chips £5 therefore becomes fish%20%26%20chips%20%C2%A35. As a whole address the ampersand stays: fish%20&%20chips%20%C2%A35. A character that cannot be written in UTF-8, such as a lone half of a surrogate pair left by a broken copy, gives an error message instead of a result.

Characters that are never encoded

ECMAScript leaves the letters A–Z and a–z, the digits, underscore, hyphen, full stop, exclamation mark, tilde, asterisk, apostrophe and brackets unencoded in both modes. RFC 3986 counts only hyphen, full stop, underscore and tilde as unreserved; the exclamation mark, apostrophe, brackets and asterisk belong to the reserved delimiters and can carry meaning in some addresses.

Whole-address mode also leaves the semicolon, slash, question mark, colon, at sign, ampersand, equals sign, plus, dollar, comma and hash alone. Square brackets, on the other hand, are encoded, so an IPv6 address in a URL, such as http://[::1]:8080/, becomes http://%5B::1%5D:8080/.

Plus signs and forms

Forms are encoded as application/x-www-form-urlencoded, where the WHATWG URL Standard writes a space as a plus sign and also encodes the exclamation mark, apostrophe, brackets and tilde. The tool always writes %20, and decoding does not turn a plus into a space: a+b stays a+b. If the text comes from a form, replace the plus signs with spaces first.

Decoding errors

Decoding requires valid UTF-8. %A3, which is £ in the older Latin-1 encoding, gives the error message, while %C2%A3 gives £. A percent sign not followed by two hexadecimal digits, as in 100%, is also an error. In whole-address mode encoded delimiters are left alone: a%2Fb stays a%2Fb, because a decoded slash would change the structure of the address.

Sources

How the tools are checked