URL Encoder & Decoder
Percent-encode and decode URLs, strip the tracking parameters out of a shared link, and see the parts of any URL you paste in — with a choice between full-URL and single-component encoding.
The two encoders, side by side
| Input | Full URL | Component |
|---|---|---|
| https://a.com/b?c=d | https://a.com/b?c=d | https%3A%2F%2Fa.com%2Fb%3Fc%3Dd |
| hello world | hello%20world | hello%20world |
| a&b | a&b | a%26b |
The middle row is the one where the two agree — a space is escaped either
way. The last row is why component encoding is the right default when you
are building a query string: ?tag=a&b is read as two
parameters, while ?tag=a%26b is read as one parameter whose
value contains an ampersand.
Non-ASCII characters
Percent-encoding works on bytes, not characters, and URLs use UTF-8. The
letter ə is two bytes in UTF-8, so it encodes to
%C9%99 — two escapes for one letter. Characters outside the
Basic Multilingual Plane, including most emoji, take four bytes and
therefore four escapes: 😀 becomes %F0%9F%98%80. This is why
the counter above reports escapes rather than characters.
Frequently asked questions
Which tracking parameters does the cleaner remove?
Everything beginning utm_, pk_ or mtm_ — the campaign tags used by Google Analytics and Matomo — plus the click identifiers that name a person rather than a campaign: gclid, fbclid, msclkid, ttclid, twclid, yclid, igshid, mkt_tok, mc_eid and a dozen more. It deliberately leaves ref and source alone, because plenty of sites route on them, and a cleaner that breaks links is worse than one that misses a few.
Why bother removing them?
A link out of a newsletter or an ad often carries an identifier for you specifically, not just for the campaign. Forward it into a group chat and everyone who opens it is counted as you; paste it into a document and it stays there. Removing the tail also makes the link shorter and easier to read, and every site tested still opens exactly the same page.
What is the difference between encodeURI and encodeURIComponent?
encodeURI leaves the characters that give a URL its structure alone — slashes, question marks, ampersands — so it is for encoding a whole URL. encodeURIComponent escapes those too, so it is for encoding a single value going into a query parameter. Using the wrong one is the most common URL bug there is: a value containing an ampersand silently splits into two parameters.
Why does a space sometimes become %20 and sometimes a plus?
Percent-20 is the correct encoding in a URL path. The plus sign comes from HTML form submission, which uses application/x-www-form-urlencoded — an older convention where plus means space. Both appear in query strings in the wild, so decoders generally have to accept either.
Which characters actually need encoding?
Everything except A–Z, a–z, 0–9 and the four marks hyphen, underscore, dot and tilde. Reserved characters such as :/?#[]@!$&'()*+,;= carry structural meaning and must be encoded when they appear inside a value rather than as delimiters. Non-ASCII characters are encoded as their UTF-8 bytes, which is why one accented letter becomes two percent-escapes.
Is double-encoding a problem?
Yes, and it is easy to do accidentally. Encoding an already-encoded string turns %20 into %2520, and the receiving system then decodes once and gets a literal %20 back. If your output looks like it is full of %25, something in the chain has encoded twice.
Related tools
- Diagram & Flowchart MakerDraw flowcharts and diagrams, connect the boxes with arrows that route themselves, and let it arrange the whole thing. Exports SVG. Nothing is uploaded.
- Password GeneratorGenerate strong random passwords using your browser's cryptographic RNG, with a live strength estimate.
- HTML Entity EncoderEncode text for HTML or decode entities back — the five markup breakers, named Latin-1 and symbol sets, numeric references up to emoji. Decodes exactly once.