URL Encode

Percent-encode text so it's safe inside a URL path, query string or form body, with an option for + instead of %20. Runs in your browser only.

Loading tool…

Worked examples

  • A path segment and query string with reserved characters

    The everyday case: making a value with slashes, spaces and question marks safe to embed as a single query parameter.

  • Form-style encoding with + for spaces

    The application/x-www-form-urlencoded convention used by HTML forms encodes spaces as + instead of %20 — turn this on when building that exact content type.

  • Multi-byte UTF-8 characters

    Each non-ASCII character expands to its UTF-8 bytes first, then each byte becomes a %XX triplet — a typical emoji (four UTF-8 bytes) takes up twelve encoded characters.

What this tool does

URL encoding (also called percent-encoding) replaces characters that aren't safe inside a URL — spaces, slashes, ampersands, question marks, and anything outside the ASCII letters, digits and a small set of punctuation — with a % followed by the character's byte value in hexadecimal. This tool percent-encodes text entirely in your browser, with an option to use + instead of %20 for the space character when you need the exact format HTML forms submit.

When you need it

  • Building a query parameter value that might contain spaces, slashes, ampersands or other characters the URL's own structure relies on, like ?redirect=https://example.com/a&b.
  • Preparing a value for an application/x-www-form-urlencoded request body, the default content type for HTML form submissions and many API bodies.
  • Embedding user-provided text — a search term, an email address, a file path — into a URL without it breaking the URL's own delimiters.
  • Understanding exactly what a percent-encoded value in a log file or browser address bar actually contains, by decoding it back with the companion URL Decode tool.

Rules the encoder applies

  1. Letters, digits, and the characters - _ . ~ ! * ' ( ) are left unescaped. The first four are the "unreserved" characters of RFC 3986; the last four (! * ' ( )) are additionally left alone by JavaScript's encodeURIComponent, which this tool uses, so they are not escaped even though RFC 3986 reserves them. If a strict RFC 3986 encoder is required, percent-encode those four by hand.
  2. Every other character is replaced with one or more %XX sequences. Non-ASCII characters are first encoded as UTF-8 bytes (an unpaired surrogate, which is not valid text, is replaced with U+FFFD first), and each byte becomes its own two-digit hex escape — so a single accented letter or emoji can expand into several %XX groups.
  3. The space character becomes %20 by default, the correct encoding anywhere in a URL. Turning on the plus-for-space option instead produces a literal +, but only use that when the target explicitly expects application/x-www-form-urlencoded — using + in a URL path or a regular query value that isn't form-encoded is incorrect and some servers will not decode it back to a space.
  4. The encoding works on a single value, not a whole URL. It's meant for a path segment or a query parameter's value — running it on an entire URL would also escape the ://, breaking the URL's own structure.

Things to check after encoding

  • If the encoded value is going into a query string, ?key=value&key2=value2, make sure you didn't also encode the ?, = and & characters that structure the query string itself — only encode the individual values.
  • Double-encoding is a common bug: encoding an already-encoded string turns every % into %25, corrupting the result. Encode raw text exactly once.
  • If a receiving system stores literal + characters instead of decoding them to spaces, it's likely not treating the value as form-encoded — switch off the plus-for-space option and use %20 instead.

Limits

Input is capped at 2 MB of text. This tool encodes a text value for use inside a URL — it doesn't validate or parse a complete URL, and it doesn't handle binary data directly; encode binary data to Base64 first if you need to put it in a URL.

Frequently asked questions

Is my text uploaded anywhere?
No. Encoding runs entirely in your browser; nothing is sent to a server.
What does URL encoding actually do?
It replaces characters that aren't safe inside a URL — spaces, slashes, ampersands, non-ASCII letters — with a % followed by their byte value in hex, so the string can travel through a URL without being misread.
When should I use + instead of %20 for spaces?
Only when building an application/x-www-form-urlencoded body, the format HTML forms submit. Everywhere else in a URL, %20 is the correct encoding for a space.
Does this encode the whole URL or just a value?
It encodes the text as a single component — use it on individual query parameter values or path segments, not on a complete URL, since that would also escape the :// and other structural characters.