URL Decoder

Turn percent-encoded text back into what it says.

Runs entirely in your browser

Loading the tool…


  

Paste percent-encoded text and read what it says. This page opens facing that direction; the same tool encodes as well.

Percent encoding writes a byte as % followed by two hex digits, which is how characters that would otherwise mean something structural get through a URL intact. %20 is a space, %2F a slash, %3F a question mark.

A plus sign is the ambiguity worth knowing about. In a query string built by an HTML form, + means a space; everywhere else in a URL it means a literal plus. Nothing in the text says which, so the option above is a choice you have to make: tick it for anything that came out of a form or a query string, leave it for a path.

Text encoded twice decodes in two passes, and %2520 is the sign of it: that is %20 with its own percent encoded again, and it means something in the chain encoded a value that was already encoded. Run the result back through to finish the job.

How to use it

  1. Paste the encoded text. It decodes as you type.
  2. Tick the plus option if the text came from a form or a query string.
  3. Press Copy to take the result.

Questions

What does %20 mean?

A space. Percent encoding writes a byte as % followed by its two hex digits, and 0x20 is the space character. The other ones you will meet constantly are %2F for a slash, %3F for a question mark and %26 for an ampersand, all characters that would otherwise be read as structure.

Why do I see %2520 instead of a space?

Because the text was encoded twice. %2520 is %20 with its own percent sign encoded again, which happens when a value that was already encoded gets passed through an encoder a second time. Decoding it twice gives you back the space, and the real fix is upstream.

Does a plus sign mean a space?

In a query string from an HTML form, yes. Elsewhere in a URL it is a literal plus. Nothing in the text distinguishes them, which is why the option is a switch rather than something the page decides for you: tick it for form data, leave it off for a path.

Your data stays on your device

Everything above runs inside your browser as WebAssembly compiled from Rust. Nothing you type is uploaded, logged or stored on a server. You can load this page once, go offline, and it still works.

This page makes no requests at all, to anywhere. That is not a promise in the copy: it is a Content-Security-Policy header your browser enforces, and connect-src on it is none. Open the network tab and watch nothing happen.