URL Decoder
Turn percent-encoded text back into what it says.
Runs entirely in your browser
Loading the tool…
Paste percent-encoded text and read what it says. This page opens facing that direction; the same tool encodes as well.
Percent encoding writes a byte as % followed by two hex digits, which
is how characters that would otherwise mean something structural get through a URL
intact. %20 is a space, %2F a slash, %3F a
question mark.
A plus sign is the ambiguity worth knowing about. In a query
string built by an HTML form, + means a space; everywhere else in a URL
it means a literal plus. Nothing in the text says which, so the option above is a
choice you have to make: tick it for anything that came out of a form or a query
string, leave it for a path.
Text encoded twice decodes in two passes, and %2520 is the sign of it:
that is %20 with its own percent encoded again, and it means something in
the chain encoded a value that was already encoded. Run the result back through to
finish the job.
How to use it
- Paste the encoded text. It decodes as you type.
- Tick the plus option if the text came from a form or a query string.
- Press Copy to take the result.
Questions
What does %20 mean?
A space. Percent encoding writes a byte as % followed by its two hex digits, and 0x20 is the space character. The other ones you will meet constantly are %2F for a slash, %3F for a question mark and %26 for an ampersand, all characters that would otherwise be read as structure.
Why do I see %2520 instead of a space?
Because the text was encoded twice. %2520 is %20 with its own percent sign encoded again, which happens when a value that was already encoded gets passed through an encoder a second time. Decoding it twice gives you back the space, and the real fix is upstream.
Does a plus sign mean a space?
In a query string from an HTML form, yes. Elsewhere in a URL it is a literal plus. Nothing in the text distinguishes them, which is why the option is a switch rather than something the page decides for you: tick it for form data, leave it off for a path.
Your data stays on your device
Everything above runs inside your browser as WebAssembly compiled from Rust. Nothing you type is uploaded, logged or stored on a server. You can load this page once, go offline, and it still works.
This page makes no requests at all, to anywhere. That is not a promise in the copy: it is a Content-Security-Policy header your browser enforces, and connect-src on it is none. Open the network tab and watch nothing happen.