URL Encode
Percent-encode text so it's safe inside a URL path, query string or form body, with an option for + instead of %20. Runs in your browser only.
Worked examples
- A path segment and query string with reserved characters
The everyday case: making a value with slashes, spaces and question marks safe to embed as a single query parameter.
- Form-style encoding with + for spaces
The application/x-www-form-urlencoded convention used by HTML forms encodes spaces as + instead of %20 — turn this on when building that exact content type.
- Multi-byte UTF-8 characters
Each non-ASCII character expands to its UTF-8 bytes first, then each byte becomes a %XX triplet — a typical emoji (four UTF-8 bytes) takes up twelve encoded characters.
What this tool does
URL encoding (also called percent-encoding) replaces characters that aren't safe inside a URL — spaces, slashes, ampersands, question marks, and anything outside the ASCII letters, digits and a small set of punctuation — with a % followed by the character's byte value in hexadecimal. This tool percent-encodes text entirely in your browser, with an option to use + instead of %20 for the space character when you need the exact format HTML forms submit.
When you need it
- Building a query parameter value that might contain spaces, slashes, ampersands or other characters the URL's own structure relies on, like
?redirect=https://example.com/a&b. - Preparing a value for an
application/x-www-form-urlencodedrequest body, the default content type for HTML form submissions and many API bodies. - Embedding user-provided text — a search term, an email address, a file path — into a URL without it breaking the URL's own delimiters.
- Understanding exactly what a percent-encoded value in a log file or browser address bar actually contains, by decoding it back with the companion URL Decode tool.
Rules the encoder applies
- Letters, digits, and the characters
- _ . ~ ! * ' ( )are left unescaped. The first four are the "unreserved" characters of RFC 3986; the last four (! * ' ( )) are additionally left alone by JavaScript'sencodeURIComponent, which this tool uses, so they are not escaped even though RFC 3986 reserves them. If a strict RFC 3986 encoder is required, percent-encode those four by hand. - Every other character is replaced with one or more
%XXsequences. Non-ASCII characters are first encoded as UTF-8 bytes (an unpaired surrogate, which is not valid text, is replaced with U+FFFD first), and each byte becomes its own two-digit hex escape — so a single accented letter or emoji can expand into several%XXgroups. - The space character becomes
%20by default, the correct encoding anywhere in a URL. Turning on the plus-for-space option instead produces a literal+, but only use that when the target explicitly expectsapplication/x-www-form-urlencoded— using+in a URL path or a regular query value that isn't form-encoded is incorrect and some servers will not decode it back to a space. - The encoding works on a single value, not a whole URL. It's meant for a path segment or a query parameter's value — running it on an entire URL would also escape the
://, breaking the URL's own structure.
Things to check after encoding
- If the encoded value is going into a query string,
?key=value&key2=value2, make sure you didn't also encode the?,=and&characters that structure the query string itself — only encode the individual values. - Double-encoding is a common bug: encoding an already-encoded string turns every
%into%25, corrupting the result. Encode raw text exactly once. - If a receiving system stores literal
+characters instead of decoding them to spaces, it's likely not treating the value as form-encoded — switch off the plus-for-space option and use%20instead.
Limits
Input is capped at 2 MB of text. This tool encodes a text value for use inside a URL — it doesn't validate or parse a complete URL, and it doesn't handle binary data directly; encode binary data to Base64 first if you need to put it in a URL.
Frequently asked questions
- Is my text uploaded anywhere?
- No. Encoding runs entirely in your browser; nothing is sent to a server.
- What does URL encoding actually do?
- It replaces characters that aren't safe inside a URL — spaces, slashes, ampersands, non-ASCII letters — with a % followed by their byte value in hex, so the string can travel through a URL without being misread.
- When should I use + instead of %20 for spaces?
- Only when building an application/x-www-form-urlencoded body, the format HTML forms submit. Everywhere else in a URL, %20 is the correct encoding for a space.
- Does this encode the whole URL or just a value?
- It encodes the text as a single component — use it on individual query parameter values or path segments, not on a complete URL, since that would also escape the :// and other structural characters.