URL Decode Online (Live Percent-Decoder & Query Tool)
Decode percent-encoded URLs, query string parameters, and API endpoints back into readable plain text. Automatically normalize + signs into spaces, safely recover truncated UTF-8 characters, unroll double-encoded strings, and inspect query parameters in a real-time table.
To decode a percent-encoded URL, locate every percent triplet (%XX) and convert the two hexadecimal digits back into their corresponding ASCII or UTF-8 byte. The browser reassembles these bytes into original text (e.g., %20 decodes to a space, %26 to an ampersand &, and %3D to an equals sign =).
How Percent-Decoding Works Under RFC 3986
Under RFC 3986, web browsers and HTTP proxy servers convert reserved and non-ASCII characters into hexadecimal triplets for transmission.
The decoding process reverses this operation:
- Identify Percent Markers (
%): The parser scans the string for the percent character delimiter. - Parse Hexadecimal Pairs: The two characters immediately following the
%are read as an 8-bit base-16 number (e.g.,20in hex is $2 \times 16 + 0 = \mathbf{32}$ in decimal, matching the ASCII space code). - Reconstruct UTF-8 Multibyte Sequences: For characters that span multiple bytes (such as accents or emojis), the decoder reads consecutive percent triplets (e.g.,
%C3%A9→0xC3 0xA9) and resolves them through the UTF-8 character table into a single character (é).
Common Percent-Encoded Triplets Reference Matrix
| Character | Decoded Symbol | Percent-Encoded Triplet | URI Syntactic Role |
|---|---|---|---|
| Space | (space) | %20 or + | Word separation in query strings |
| Ampersand | & | %26 | Separates multiple query parameters |
| Equals Sign | = | %3D | Assigns values to parameter keys |
| Question Mark | ? | %3F | Indicates the start of query parameters |
| Forward Slash | / | %2F | Hierarchical path segment delimiter |
| Hash / Fragment | # | %23 | Indicates anchor or client-side fragment |
Double-Encoded URLs: How `%2520` Happens
A frequent architectural issue in web applications is double percent-encoding. This occurs when an already encoded URL passes through a secondary proxy, redirect handler, or API router that encodes the string again:
Original String: "Hello World" Single-Encoded: "Hello%20World" Double-Encoded: "Hello%2520World" (• The '%' of '%20' became '%25'!)
Standard decoders decode %2520 into %20 and stop. By enabling the "Recursive decode" checkbox in this tool, the engine applies iterative unrolling to restore the true underlying plaintext automatically.
Related URL & Encoding Utilities:
- URL Percent-Encoding Converter — Encode query parameters under RFC 3986 with encodeURIComponent vs. encodeURI options.
- Full URL Converter Hub — Master URL encoder and decoder.
- SEO URL Slug Generator — Convert headlines into lowercase, hyphenated URL permalinks.
- HTML Entity Converter — Escape DOM markup characters to prevent XSS.
- HTML Entities vs. URL Encoding Guide — Technical comparison of web encoding standards.
Frequently Asked Questions
How do I decode a URL with plus signs (+) instead of %20?
Keep the "Decode + as spaces" checkbox enabled. HTML form submissions use the application/x-www-form-urlencoded format, which replaces spaces with plus signs rather than %20. Our tool normalizes these into standard spaces automatically.
What causes a "URI malformed" error during URL decoding?
A "URI malformed" error occurs when a percent symbol (%) is not followed by two valid hexadecimal digits (0-9, A-F), or when a multibyte UTF-8 sequence is truncated. Our tool applies resilient parsing to prevent crashes.
How do I decode a double-encoded URL?
Enable the "Recursive decode" checkbox. The engine will iteratively unroll nested percent sequences (such as %2520 into spaces) until the underlying plaintext is reached.
Can this tool extract query parameters from a URL?
Yes. When you paste an encoded URL containing a query string (?key=value), the tool automatically parses and displays each parameter key and decoded value in an interactive table beneath the output.
Is my URL data logged or stored on a server?
No. All URL parsing, parameter extraction, and percent-decoding execute 100% locally inside your browser's runtime memory using JavaScript. No URLs, query parameters, or tokens are ever sent across a network or saved to any database.