Skip to content

URL decode

EncodeExperimentalLimited support. Verify anything critical.

URL decode is a powerful developer tool that reverses percent-encoding (such as that produced by encodeURIComponent), translating encoded hexadecimal sequences back into their original characters. It strictly validates the input, ensuring that malformed sequences—such as a bare or incomplete percent sign—are properly caught rather than leaving invalid data. Crucially, all processing happens locally within your browser sandbox; this guarantees absolute privacy, as your query values, tokens, and sensitive strings never leave your device or get uploaded to any external server.

Skip to the tool

This tool processes text on your device. The text is not uploaded.

  • Malformed sequences throw.
  • This is not a URL validator.

How to use URL decode

What is URL decode?

URL decode is a powerful developer tool that reverses percent-encoding (such as that produced by encodeURIComponent), translating encoded hexadecimal sequences back into their original characters. It strictly validates the input, ensuring that malformed sequences—such as a bare or incomplete percent sign—are properly caught rather than leaving invalid data. Crucially, all processing happens locally within your browser sandbox; this guarantees absolute privacy, as your query values, tokens, and sensitive strings never leave your device or get uploaded to any external server.

Technical overview & inversion mechanics

URL decoding (often referred to as percent-decoding) systematically reverses the RFC 3986 encoding process. It restores percent-escaped hexadecimal triplets (%XX) into their original UTF-8 characters and bytes.

Step-by-step decoding pipeline

  1. Token scanning: The parser scans the input string sequentially for the % escape character.
  2. Hex pair validation: When % is encountered, the subsequent two characters are validated against acceptable hexadecimal digits (0-9, a-f, A-F). If invalid, the process safely fails.
  3. Byte conversion: The validated two-digit hexadecimal string is parsed into an 8-bit unsigned integer byte.
  4. UTF-8 stream assembly: Multi-byte sequence bytes (for instance, 2, 3, or 4-byte UTF-8 sequences representing international characters or emojis) are grouped and parsed through a UTF-8 character decoder to yield clean Unicode text.
Practical developer use cases
  • Debugging API query logs: Easily parse incoming request logs where critical parameters like search terms, filter expressions, or JSON strings are percent-encoded.
  • Auditing analytics & campaign URLs: Decode UTM campaign tags, referral URLs, and affiliate query parameters to verify marketing tracking data.
  • Deep link inspection: Inspect mobile deep links and OAuth redirect callback URLs to confirm state parameters and authorization tokens are correct.
  • Web scraping & data extraction: Restore escaped URLs extracted from web page href attributes, sitemaps, or structured data feeds.
Best practices
  • Understand plus sign handling: Standard decodeURIComponent treats + as a literal plus sign. When decoding application/x-www-form-urlencoded payloads where pluses represent spaces, normalize them prior to percent-decoding.
  • Pre-flight validation: Ensure you are decoding actual encoded components rather than full URLs blindly, as some characters (like & and =) might alter the structure of a query string once decoded.
  • Handle errors gracefully: Since invalid percent sequences will raise an explicit error, ensure any automated decoding scripts wrap the execution in a try...catch block.
Security considerations
  • Local privacy guarantee: Because decoding executes client-side, it is safe to use this tool with sensitive authorization codes, API keys, or personal identifiable information (PII). No data is transmitted externally.
  • Beware of double-decoding: Avoid running URL decode multiple times on the same input unless explicitly required, as it could unintentionally expose injection vectors if the data is subsequently rendered without escaping.
Frequently asked questions
  • How does URL decoding handle invalid percent sequences? The decoder strictly validates every %XX hexadecimal pair. If an incomplete escape (e.g., a trailing %) or a non-hex character (e.g., %ZZ) is detected, an explicit error is raised and the previous output is cleared to prevent data corruption.

  • Does this tool convert plus signs (+) into spaces? No, it follows standard decodeURIComponent behavior, which treats + as a literal plus sign. Normalization of plus signs to spaces should occur before percent-decoding if you are processing form data.

  • Can URL decode reconstruct multi-byte international characters? Yes. Consecutive percent-encoded byte sequences (such as %E2%9C%93 for ✓) are perfectly reassembled into complete multi-byte UTF-8 code points.

  • Is this decoding process secure and private? Absolutely. All string operations execute purely client-side in your local browser sandbox. No query parameters, OAuth tokens, or sensitive strings are ever sent to an external processing server.

Code examples

JavaScript / TypeScript

function urlDecodeComponent(encodedValue: string): string {
  try {
    return decodeURIComponent(encodedValue);
  } catch (e) {
    console.error("Malformed URI sequence", e);
    return "";
  }
}

Python 3

import urllib.parse

def url_decode(encoded_value: str) -> str:
    # Uses unquote which safely handles percent-decoding
    return urllib.parse.unquote(encoded_value)

PHP

<?php
$encoded_value = "a%3Db%26c";
$decoded = urldecode($encoded_value);
echo $decoded; // Outputs: a=b&c
?>

Bash (via Python)

python3 -c "import sys, urllib.parse; print(urllib.parse.unquote(sys.argv[1]))" "a%3Db%26c"

How it works

  1. Enter what you haveType or pick your text. Nothing is submitted anywhere.
  2. It runs in this tabThe calculation happens on your device, using your browser's own data.
  3. Take the resultRead the text, then copy, download, or share a link.

Reimplemented locally. Not derived from IT-Tools source.

Basis
independent
Licence
MIT
Last reviewed

Frequently asked questions

How does URL decoding handle invalid percent sequences?

The decoder strictly validates every '%XX' hexadecimal pair. If an incomplete escape (e.g. trailing '%') or non-hex character (e.g. '%ZZ') is detected, an explicit error is raised and previous output is cleared.

Does this tool convert plus signs (+) into spaces?

Standard decodeURIComponent treats '+' as a literal plus sign. If decoding application/x-www-form-urlencoded form data where pluses represent spaces, pluses can be normalized prior to percent-decoding.

Can URL decode reconstruct multi-byte international characters?

Yes. Consecutive percent-encoded byte sequences (such as '%E2%9C%93' for '✓') are reassembled into complete multi-byte UTF-8 code points.

Is this decoding process secure and private?

Yes. All string operations execute client-side in your local browser sandbox. No query parameters, tokens, or sensitive strings are transmitted to external servers.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close