What Is URL Encoding? A Complete Explanation of Percent-Encoding
Quick Answer
URL encoding (percent-encoding) replaces unsafe characters in a URL with % followed by two hex digits. For example, space becomes %20, & becomes %26. It ensures URLs can be transmitted without ambiguity. Use our free URL Encoder and Decoder to convert in your browser.
Introduction
URL encoding, also called percent-encoding, is a mechanism for encoding special characters in a URL so they can be safely transmitted over the internet. URLs can only contain a limited set of ASCII characters — letters, digits, and a few reserved characters. Any other character (spaces, quotes, non-ASCII letters) must be encoded as a percent sign (%) followed by two hexadecimal digits representing the character's byte value. URL encoding is defined by RFC 3986.
Step by Step
-
Understand which characters need encoding
Unreserved characters (A-Z, a-z, 0-9, -, _, ., ~) do not need encoding. Reserved characters (:, /, ?, #, [, ], @, !, $, &, ', (, ), *, +, ,, ;, =) have special meaning in URLs and should be encoded when used as data. All other characters (spaces, quotes, non-ASCII) must be encoded.
-
Learn the encoding mechanism
Each character that needs encoding is converted to its UTF-8 byte sequence, then each byte is represented as %XX where XX is the hex value. Space (0x20) → %20. The non-ASCII character 'é' (UTF-8: 0xC3 0xA9) → %C3%A9.
-
Distinguish encodeURI vs encodeURIComponent
encodeURI() encodes a full URL but preserves reserved characters (:/?&=) that are part of the URL structure. encodeURIComponent() encodes everything except unreserved characters — use it for query parameter values where reserved characters are data, not structure.
-
Decode percent-encoded URLs
Decoding reverses the encoding: %20 → space, %C3%A9 → é. Use decodeURI() for full URLs and decodeURIComponent() for query parameter values. Invalid escape sequences (like %ZZ) throw errors.
Examples
Encode a space
Input: hello world
Output: hello%20world
Encode non-ASCII text
Input: café
Output: caf%C3%A9
Encode a query parameter value
Input: name=John Doe & Co.
Output: name%3DJohn%20Doe%20%26%20Co.
Common Problems
- Encoding the entire URL when only values need encoding —encode query parameter values, not the URL structure (://?&=).
- Double-encoding —if a URL is already encoded, encoding again produces %2520 instead of %20. Decode first if unsure whether it is already encoded.
- Using encodeURI vs encodeURIComponent incorrectly —encodeURI preserves URL structure characters; encodeURIComponent encodes them. Use the latter for query parameter values.
- Invalid escape sequences —%ZZ or a single % at the end are invalid and will throw errors when decoded.
Tips
- Always encode query parameter values that may contain spaces, special characters, or user input to prevent URL injection.
- Use encodeURIComponent() for query parameter values, and encodeURI() for full URLs that just need unsafe characters encoded.
- URL encoding is not encryption —anyone can decode it. Never use it to hide sensitive data.
- Use our URL Encoder and Decoder for instant, private conversion in your browser.