Processing percent-decoding & sequence analysis...
Invalid Percent-Encoded Sequence Detected
Invalid UTF-8 Byte Sequence Detected
%20, %2F) and may have been encoded multiple times.
| Percent Sequence | Decoded Character | UTF-8 Hex | Category | Description |
|---|
| Parameter Name | Decoded Value | Raw Value |
|---|
/--Recent Decoding History
URL Decoding Specification & Developer Guide
Percent Decoding vs Form URL Encoding
Standard URL Percent Decoding (RFC 3986) transforms %XX hex triplets back into raw bytes or UTF-8 characters. In RFC 3986, %20 explicitly represents a space character, while literal + signs are preserved as plus characters.
In contrast, Form URL Encoding (application/x-www-form-urlencoded) converts space characters to + signs. Select Form Decode (+ → space) mode when analyzing HTML form submissions or legacy query strings.
Single-Pass Decoding & Double-Encoding
Standards-compliant URL decoders perform exactly one logical pass per operation. For example, %2520 decodes to %20 on the first pass and does not automatically become a space character.
Our engine detects remaining percent sequences after the first pass and provides a "Decode Again" action to allow explicit multi-pass decoding without unexpected data corruption.
UTF-8 & Multibyte Character Encoding
Unicode characters outside the ASCII range (such as Hindi, Chinese, Cyrillic, and Emoji) are represented in URLs as multibyte UTF-8 byte sequences. For example, the Hindi text नमस्ते is encoded as 15 characters (%E0%A4%A8...). Our decoder groups and validates multibyte byte sequences without corruption.
Security & XSS Protection
Decoded URLs may contain malicious script tags (e.g. %3Cscript%3E). This tool strictly renders all decoded output as plain text using safe DOM node assignment (never innerHTML or eval()). Furthermore, protocol validation safeguards against dangerous scheme navigation.