Skip to content

URL encode

EncodeExperimentalLimited support. Verify anything critical.

URL encode is a developer utility that safely escapes special characters in a string so they can be securely transmitted in a URL. Behind the scenes, it utilizes the standard encodeURIComponent algorithm to convert any character outside the safe list (A-Z, a-z, 0-9, and -_.!~*'()) into valid UTF-8 hexadecimal pairs (percent-encoding). Best of all, all processing happens completely locally in your browser, guaranteeing that your user data never leaves your device and ensuring absolute privacy.

Skip to the tool

This tool processes text on your device. The text is not uploaded.

  • Characters are escaped to UTF-8 hex pairs.
  • This tool escapes the full string. If you encode an entire URL (with its scheme and host), you will break the URL.

How to use URL encode

What is URL encode?

URL encode is a developer utility that safely escapes special characters in a string so they can be securely transmitted in a URL. Behind the scenes, it utilizes the standard encodeURIComponent algorithm to convert any character outside the safe list (A-Z, a-z, 0-9, and -_.!~*'()) into valid UTF-8 hexadecimal pairs (percent-encoding). Best of all, all processing happens completely locally in your browser, guaranteeing that your user data never leaves your device and ensuring absolute privacy.

Technical Overview & URL Specification

URL encoding (often referred to as percent-encoding) is an essential mechanism for embedding arbitrary data within a Uniform Resource Identifier (URI) safely, adhering strictly to RFC 3986.

Algorithmic Escaping Strategy

  1. Character Identification: The tool scans the provided input string character by character.
  2. Safe Character Preservation: Unreserved characters remain exactly as they are. These strictly include:
    • Alphanumeric ASCII: A-Z, a-z, 0-9
    • Specific punctuation marks: hyphen (-), underscore (_), period (.), exclamation mark (!), tilde (~), asterisk (*), single quote ('), and parentheses (()).
  3. Percent-Encoding Replacement: Any character that falls outside of this safe list is converted into its UTF-8 byte sequence. Each byte is then formatted as a percentage sign followed by two uppercase hexadecimal digits (for example, a space becomes %20, and an ampersand & becomes %26).
Practical Developer Scenarios
  • API Query Parameter Construction: Safely formatting dynamic user input—such as email addresses, search terms, or JSON strings—into RESTful GET request query strings without breaking the request.
  • Form Data Serialization: Preparing form payloads containing special characters before transmitting them via application/x-www-form-urlencoded POST requests.
  • OAuth Callback State Variables: Escaping state objects and callback URLs before sending them to third-party authorization providers.
  • Deep Linking: Formatting complex data strings to be passed securely to mobile application deep links without compromising the URI schema.
Best Practices and Common Pitfalls

Do Not Encode Full URLs

This tool encodes the entire input string provided. If you paste a complete URL (like https://example.com/?q=search), characters such as the colon, slashes, and question mark will also be encoded. This will effectively break the URL. Always isolate and encode individual query parameter values rather than the entire string.

Handling Spaces and Reserved Characters

Reserved characters like &, =, ?, and # have structural meaning in URLs. If your data contains these characters (for instance, searching for “R&D”), failing to encode them will truncate or corrupt the URL. Spaces are handled by converting them to their percent-encoded hexadecimal format (%20). While some legacy forms accept + for spaces, %20 is the universally accepted standard for modern URI components.

Security Considerations

When handling sensitive strings, such as API keys or personal user data, it is critical to ensure your tooling does not log or transmit this information externally. Because our URL encode tool executes entirely on your local machine, there is zero risk of data interception or third-party logging during the encoding process.

Code Examples

JavaScript / TypeScript

// Encode a specific query parameter value (Safe, Recommended)
const rawSearchTerm = "shoes & accessories";
const encodedParam = encodeURIComponent(rawSearchTerm); 
// Result: "shoes%20%26%20accessories"

// Warning: encodeURIComponent breaks full URLs
const fullUrl = "https://example.com/?q=" + encodedParam;

Python 3

import urllib.parse

def encode_url_parameter(value: str) -> str:
    # Uses quote to apply percent-encoding to the string
    return urllib.parse.quote(value, safe="~()*!.'")

How it works

  1. Enter what you haveType or pick your text. Nothing is submitted anywhere.
  2. It runs in this tabThe calculation happens on your device, using your browser's own data.
  3. Take the resultRead the text, then copy, download, or share a link.

Reimplemented locally. Not derived from IT-Tools source.

Basis
independent
Licence
MIT
Last reviewed

Frequently asked questions

Why should I encode URL parameters?

Reserved characters like '&', '=', '?', and '#' have structural meaning in URLs. If your query string data contains these characters (e.g. searching for 'R&D'), it will truncate or break the URL unless properly percent-encoded as '%26'.

Is this safe for full URLs?

No. This tool encodes the entire input string. If you paste a full URL (like 'https://example.com/'), the colon and slashes will be encoded, breaking the link. Only use this for individual parameter values.

How are spaces handled?

Spaces are converted to their percent-encoded hexadecimal format ('%20'). While some application/x-www-form-urlencoded forms accept '+' for spaces, '%20' is the universal standard for URI components.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close