URL Decoder
Decode %XX percent-encoding — and form-encoded query strings where + means a space — including double-encoded and Safe Links-wrapped URLs.
How to use
- Paste the encoded URL or text.
- If it came from a form or query string where + means a space, choose “Query string (+ = space)”.
- Still seeing %25? It was encoded twice — press Auto-decode.
Steps
Output
Percent-encoding in one paragraph
URLs may only contain a limited set of ASCII characters. Anything else — spaces, reserved characters used as data, and all non-ASCII text — is written as bytes in the form %XX, where XX is the byte in hex (RFC 3986). Text is first encoded as UTF-8, so a single character such as å or € becomes two or three %XX groups. Decoding reverses this exactly; an invalid sequence such as a lone % is reported instead of being guessed.
Query strings, + and spaces
HTML forms send data as application/x-www-form-urlencoded, where a space becomes + rather than %20. Decoding such a query string as a URL leaves the + signs in place. The “Query string (+ = space)” step treats + as a space first and then decodes, which is what a web server does with form data.
Wrapped and double-encoded links
Email security gateways rewrite links: Microsoft Safe Links, for example, puts the original address inside the url= parameter, percent-encoded. Decoding once shows the original link; values inside it that were themselves encoded (such as %2540 for @) need a second pass, which Auto-decode applies until nothing changes.
Double encoding is also an evasion technique: a filter that decodes once sees %2e%2e%2f instead of ../. Looking at every layer is how you see what the server finally receives.
Common questions
What does %20 mean in a URL?
A percent sign followed by two hex digits is one byte. %20 is byte 0x20, a space. Characters outside ASCII take several bytes in UTF-8, so å becomes %C3%A5.
Should + be decoded as a space?
Only in form-encoded data such as HTML form submissions and most query strings. In a URL path, + is a literal plus sign. Pick “Query string (+ = space)” when the text came from a form or a ?key=value string.
Why is my URL still encoded after decoding?
It was encoded twice: %2520 decodes to %20, which decodes to a space. Double encoding is common in redirects and is also used to slip past filters. Auto-decode keeps going until nothing changes.
Known limitations
- Text is decoded as UTF-8, as modern browsers do. Very old pages that used Latin-1 percent-encoding will show an error for bytes that are not valid UTF-8.
- The page cannot follow redirects or open the URL; it only decodes the text.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- RFC 3986 — URI syntax and percent-encoding (opens in a new tab)
- WHATWG URL — application/x-www-form-urlencoded (opens in a new tab)
- Microsoft Defender — Safe Links (opens in a new tab)
- OWASP — double encoding (opens in a new tab)