URL Decoder
Decode percent-encoded URLs and query strings back to readable text. Malformed sequences are located instead of crashing.
Processed locally in your browser. Your text is not uploaded.
What this tool does
Turn strings such as https%3A%2F%2Fexample.com%2Fcaf%C3%A9%20menu back into readable text. This is handy when debugging redirect URLs, analytics parameters, OAuth callbacks, log files and webhook payloads.
Real-world input is often damaged: a truncated copy-paste, a literal % that was never encoded, or bytes that are not valid UTF-8. Instead of failing silently, the decoder points to the first bad sequence with its position and still shows a best-effort result in which every valid sequence is decoded and broken ones are left untouched.
Choose component mode (decodes everything) or whole-URL mode (keeps escapes for reserved characters such as %2F and %3F so the URL structure is not changed), and optionally treat + as a space for form-encoded data. Decoding happens locally in your browser.
How to use it
- 1Paste the encoded text or URL into the input box.
- 2Pick “Component” to decode everything, or “Whole URL” to keep reserved characters like %2F encoded.
- 3Turn on “Treat + as a space” if the data came from an HTML form or query string.
- 4If an error appears, check the position it mentions. Copy or download the decoded text.
Supported formats
Percent-encoded text in (UTF-8 byte sequences), plain text out.
Privacy
This tool runs in your browser. The data you provide is processed on your device and is not sent to our servers.
Limitations
- Percent sequences must contain UTF-8 bytes. Legacy encodings such as Latin-1 (%E9 for é) are reported as invalid UTF-8.
- A literal + is only converted to a space when you enable that option, because in URL paths + means plus.
- Decoding twice can change meaning (%2520 becomes %20, then a space). Decode once unless you know the data was double-encoded.
- Only the first malformed sequence is reported, though every one is left unchanged in the best-effort output.
FAQ
What does “malformed percent sequence” mean?
A % sign must be followed by exactly two hex digits. Text like “50% off” or a string cut off in the middle (…%2) breaks that rule. The decoder shows where, and leaves those characters as they are in the best-effort result.
Why is %2F not decoded in whole-URL mode?
Decoding it would change a path separator inside a value into a real one and alter the URL's meaning. Component mode decodes it.
What is invalid UTF-8?
Percent-encoded bytes that do not form a valid character, for example a lone %FF or an incomplete multi-byte sequence. They usually come from legacy encodings or truncated data.
Related tools
URL Encoder
Percent-encode text for safe use in URLs and query strings. Choose full-component or whole-URL mode. Runs in your browser.
Base64 Decoder
Decode Base64 and URL-safe Base64 to text with UTF-8 support. Clear errors for invalid characters, length and padding.
JSON Formatter
Format, beautify and sort JSON with syntax highlighting. Pinpoints errors by line and column. Runs locally in your browser.
JSON Validator
Check whether JSON is valid and see the exact line and column of the first error, with a caret under the problem character.