URL Decode
Decode a percent-encoded URL, query string or form value back to plain text, with an option to treat + as a space. Nothing is uploaded to a server.
Worked examples
- A percent-encoded path and query string
The everyday case: turning a value copied from a browser address bar or server log back into readable text.
- Form-encoded body with + for spaces
application/x-www-form-urlencoded bodies (from HTML forms) use + for spaces rather than %20 — decoding without this option would leave literal plus signs in the text.
- A stray % that isn't a valid escape sequence
A % not followed by two hex digits is invalid percent-encoding, often from text that was never actually URL-encoded — the tool reports it instead of guessing.
What this tool does
URL decoding reverses percent-encoding: it turns %XX escape sequences back into the bytes they represent, then interprets those bytes as UTF-8 text. This tool decodes a percent-encoded string entirely in your browser, with an option to treat literal + characters as spaces for values that came from an application/x-www-form-urlencoded body.
When you need it
- Reading a query parameter or path segment copied from a browser address bar, a server access log, or an API request, where the raw value is hidden behind
%20,%2Fand similar escapes. - Decoding a value submitted by an HTML form, where spaces arrive as
+rather than%20— the plus-as-space option handles that case correctly. - Debugging a webhook payload, redirect URL, or tracking link where the meaningful content is buried in percent-encoded text.
- Verifying that a URL-encoding step elsewhere in your code produced the value you expected, by round-tripping it back to plain text.
How decoding works
- Each
%XXsequence is converted back to a single byte, using the two hex digits after the%as that byte's value. - The resulting bytes are interpreted as UTF-8, which is why a single accented letter or emoji, originally encoded as several
%XXgroups, reassembles correctly into one character. - With the plus-as-space option on, every literal
+is first replaced with a space before the percent-decoding runs — this matches how browsers and servers interpretapplication/x-www-form-urlencodeddata, where a+is a space and an actual plus sign must itself be percent-encoded as%2B. - Anything not matching
%XXor a plain character is passed through unchanged, except that a%not followed by two valid hex digits is reported as invalid rather than silently ignored or guessed at.
Why decoding can fail
A percent-encoded string is invalid if it contains a % that isn't followed by exactly two hexadecimal digits — for example, a % used as a literal character that was never itself encoded (it should have been written as %25), or text that was truncated mid-escape. Rather than dropping the broken sequence or guessing what was meant, this tool reports the failure so you can see exactly which part of the input doesn't parse. That's usually a sign the text wasn't actually percent-encoded in the first place, or was double-processed somewhere upstream.
Things to check after decoding
- If the decoded text still contains
+characters where you expected spaces, the value wasn't form-encoded, or you need to turn the plus-as-space option on. - If decoding fails on text you're confident was encoded correctly, check for accidental double-encoding upstream — decoding it once first, then feeding the result back in, often reveals the real content.
- Decoded text can contain any character, including ones with special meaning in HTML, SQL or shell commands — never treat decoded output as automatically safe to insert elsewhere without its own escaping.
Limits
Input is capped at 2 MB of text. This tool decodes a single percent-encoded value, not a full URL with query string and fragment — for inspecting a whole URL's structure, split it into its parts first.
Frequently asked questions
- Is my text uploaded anywhere?
- No. Decoding runs entirely in your browser; nothing is sent to a server.
- Why does decoding fail on my input?
- A % that isn't followed by exactly two hex digits is not valid percent-encoding — that usually means the text was already decoded, or was never encoded in the first place.
- When do I need the + as space option?
- Only for application/x-www-form-urlencoded values, the format HTML forms submit — plain URL query strings use %20 for spaces, not +.
- Can I decode a full URL with this?
- Yes for the encoded characters, but a full URL's structural characters like :// are never percent-encoded in the first place, so decoding a whole URL is usually unnecessary.