URL Decoder

Decode %XX percent-encoding — and form-encoded query strings where + means a space — including double-encoded and Safe Links-wrapped URLs.

Runs entirely in your browser. Your browser blocks this page from opening connections or loading anything from other sites. Nothing you enter is uploaded or saved.

requests since opened: 0
How to verify this yourself
  1. Open your browser’s developer tools (F12, or ⌥⌘I on Mac) → Network tab, then use the tool. No new requests appear.
  2. Or disconnect from the internet after the page loads — the tool keeps working, because it never needed the network.
  3. See the rule itself: in the Network tab, select this page’s document → Response Headers → content-security-policy contains connect-src 'none' and no 'unsafe-inline' for scripts.
  4. Press Test the lock: the page tries a harmless request and the browser blocks it (the Console shows the refusal).
How to use
  1. Paste the encoded URL or text.
  2. If it came from a form or query string where + means a space, choose “Query string (+ = space)”.
  3. Still seeing %25? It was encoded twice — press Auto-decode.

Steps

  1. 1.

Output

working…

Percent-encoding in one paragraph

URLs may only contain a limited set of ASCII characters. Anything else — spaces, reserved characters used as data, and all non-ASCII text — is written as bytes in the form %XX, where XX is the byte in hex (RFC 3986). Text is first encoded as UTF-8, so a single character such as å or € becomes two or three %XX groups. Decoding reverses this exactly; an invalid sequence such as a lone % is reported instead of being guessed.

Query strings, + and spaces

HTML forms send data as application/x-www-form-urlencoded, where a space becomes + rather than %20. Decoding such a query string as a URL leaves the + signs in place. The “Query string (+ = space)” step treats + as a space first and then decodes, which is what a web server does with form data.

Wrapped and double-encoded links

Email security gateways rewrite links: Microsoft Safe Links, for example, puts the original address inside the url= parameter, percent-encoded. Decoding once shows the original link; values inside it that were themselves encoded (such as %2540 for @) need a second pass, which Auto-decode applies until nothing changes.

Double encoding is also an evasion technique: a filter that decodes once sees %2e%2e%2f instead of ../. Looking at every layer is how you see what the server finally receives.

Common questions

What does %20 mean in a URL?

A percent sign followed by two hex digits is one byte. %20 is byte 0x20, a space. Characters outside ASCII take several bytes in UTF-8, so å becomes %C3%A5.

Should + be decoded as a space?

Only in form-encoded data such as HTML form submissions and most query strings. In a URL path, + is a literal plus sign. Pick “Query string (+ = space)” when the text came from a form or a ?key=value string.

Why is my URL still encoded after decoding?

It was encoded twice: %2520 decodes to %20, which decodes to a space. Double encoding is common in redirects and is also used to slip past filters. Auto-decode keeps going until nothing changes.

Known limitations

  • Text is decoded as UTF-8, as modern browsers do. Very old pages that used Latin-1 percent-encoding will show an error for bytes that are not valid UTF-8.
  • The page cannot follow redirects or open the URL; it only decodes the text.
  • Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works

tools v0.9.0 · build 7317bbb · 2026-10-07