URL Decode

Decode a percent-encoded URL, query string or form value back to plain text, with an option to treat + as a space. Nothing is uploaded to a server.

Loading tool…

Worked examples

  • A percent-encoded path and query string

    The everyday case: turning a value copied from a browser address bar or server log back into readable text.

  • Form-encoded body with + for spaces

    application/x-www-form-urlencoded bodies (from HTML forms) use + for spaces rather than %20 — decoding without this option would leave literal plus signs in the text.

  • A stray % that isn't a valid escape sequence

    A % not followed by two hex digits is invalid percent-encoding, often from text that was never actually URL-encoded — the tool reports it instead of guessing.

What this tool does

URL decoding reverses percent-encoding: it turns %XX escape sequences back into the bytes they represent, then interprets those bytes as UTF-8 text. This tool decodes a percent-encoded string entirely in your browser, with an option to treat literal + characters as spaces for values that came from an application/x-www-form-urlencoded body.

When you need it

  • Reading a query parameter or path segment copied from a browser address bar, a server access log, or an API request, where the raw value is hidden behind %20, %2F and similar escapes.
  • Decoding a value submitted by an HTML form, where spaces arrive as + rather than %20 — the plus-as-space option handles that case correctly.
  • Debugging a webhook payload, redirect URL, or tracking link where the meaningful content is buried in percent-encoded text.
  • Verifying that a URL-encoding step elsewhere in your code produced the value you expected, by round-tripping it back to plain text.

How decoding works

  1. Each %XX sequence is converted back to a single byte, using the two hex digits after the % as that byte's value.
  2. The resulting bytes are interpreted as UTF-8, which is why a single accented letter or emoji, originally encoded as several %XX groups, reassembles correctly into one character.
  3. With the plus-as-space option on, every literal + is first replaced with a space before the percent-decoding runs — this matches how browsers and servers interpret application/x-www-form-urlencoded data, where a + is a space and an actual plus sign must itself be percent-encoded as %2B.
  4. Anything not matching %XX or a plain character is passed through unchanged, except that a % not followed by two valid hex digits is reported as invalid rather than silently ignored or guessed at.

Why decoding can fail

A percent-encoded string is invalid if it contains a % that isn't followed by exactly two hexadecimal digits — for example, a % used as a literal character that was never itself encoded (it should have been written as %25), or text that was truncated mid-escape. Rather than dropping the broken sequence or guessing what was meant, this tool reports the failure so you can see exactly which part of the input doesn't parse. That's usually a sign the text wasn't actually percent-encoded in the first place, or was double-processed somewhere upstream.

Things to check after decoding

  • If the decoded text still contains + characters where you expected spaces, the value wasn't form-encoded, or you need to turn the plus-as-space option on.
  • If decoding fails on text you're confident was encoded correctly, check for accidental double-encoding upstream — decoding it once first, then feeding the result back in, often reveals the real content.
  • Decoded text can contain any character, including ones with special meaning in HTML, SQL or shell commands — never treat decoded output as automatically safe to insert elsewhere without its own escaping.

Limits

Input is capped at 2 MB of text. This tool decodes a single percent-encoded value, not a full URL with query string and fragment — for inspecting a whole URL's structure, split it into its parts first.

Frequently asked questions

Is my text uploaded anywhere?
No. Decoding runs entirely in your browser; nothing is sent to a server.
Why does decoding fail on my input?
A % that isn't followed by exactly two hex digits is not valid percent-encoding — that usually means the text was already decoded, or was never encoded in the first place.
When do I need the + as space option?
Only for application/x-www-form-urlencoded values, the format HTML forms submit — plain URL query strings use %20 for spaces, not +.
Can I decode a full URL with this?
Yes for the encoded characters, but a full URL's structural characters like :// are never percent-encoded in the first place, so decoding a whole URL is usually unnecessary.