Security & Privacy Tools
100% Client-Side Executed locally inside your browser. Zero data sent to any remote server.

URL & Query String Encoder / Decoder

Percent-encode and decode URLs, query parameters, and webhooks safely

Zero Server Uploads • 100% Browser-Native Cryptography

Key derivation and AES-GCM-256 authenticated encryption execute locally inside your browser sandbox using W3C Web Cryptography APIs (crypto.subtle). Secret passphrases and raw payloads never touch any remote server.

Method:
Input String55 chars
Processed URL Output

About URL & Query String Encoder / Decoder

Safely percent-encode special characters in URLs, query strings, and webhook payloads, or decode %20, %2F, and %3F sequences back into clean human-readable text.

Key Capabilities & Features

  • Dual mode: encodeURIComponent (query parameters) and encodeURI (full URLs)
  • Handles international multi-byte UTF-8 character sequences
  • Instant swap between input and output
  • Real-time live conversion
  • 1-Click copy to clipboard

How to Use URL & Query String Encoder / Decoder

1

Select Action

Choose Percent-Encode or Decode Percent-Encoding.

2

Input URL

Paste the web address, query parameter, or webhook string.

3

Copy Result

Copy the encoded or decoded URL output.

Privacy & In-Browser Execution Guarantee

Executed locally inside your browser. Zero data sent to any remote server.

Frequently Asked Questions

What is the difference between encodeURI and encodeURIComponent?

encodeURI preserves protocol markers like 'https://' and '/', whereas encodeURIComponent encodes all special characters, making it ideal for query string parameters.

Why do spaces become %20 instead of +?

%20 is the official RFC 3986 percent-encoding standard for URLs, whereas '+' is traditionally used only in HTML application/x-www-form-urlencoded forms.

What causes URI malformed decode errors?

A malformed error occurs when an isolated '%' character is not followed by two valid hexadecimal digits, violating percent-encoding syntax.