Standards-Compliant RFC 3986 Engine

URL Decoder

Decode percent-encoded URL triplets (e.g. %20, %2F, %26), multibyte UTF-8 characters, and form-urlencoded data safely and accurately.

Load Preset Example:
0 Chars • 0 Encoded Triplets

Processing percent-decoding & sequence analysis...

Decoded Readable OutputStandard
Input Length
0
Characters
Output Length
0
Characters
Encoded Triplets
0
Sequences
Size Change
0%
Reduction
No percent-encoded sequences (%XX) were found in the input.
Percent SequenceDecoded CharacterUTF-8 HexCategoryDescription
No query parameters were found in the input text.
Parameter NameDecoded ValueRaw Value
Input is not a complete URL structure.
SCHEME
-
HOST
-
PORT
Default
PATH
/
QUERY STRING
-
FRAGMENT
-
Recent Decoding History
No recent decoding history saved.

URL Decoding Specification & Developer Guide

Percent Decoding vs Form URL Encoding

Standard URL Percent Decoding (RFC 3986) transforms %XX hex triplets back into raw bytes or UTF-8 characters. In RFC 3986, %20 explicitly represents a space character, while literal + signs are preserved as plus characters.

In contrast, Form URL Encoding (application/x-www-form-urlencoded) converts space characters to + signs. Select Form Decode (+ → space) mode when analyzing HTML form submissions or legacy query strings.

Single-Pass Decoding & Double-Encoding

Standards-compliant URL decoders perform exactly one logical pass per operation. For example, %2520 decodes to %20 on the first pass and does not automatically become a space character.

Our engine detects remaining percent sequences after the first pass and provides a "Decode Again" action to allow explicit multi-pass decoding without unexpected data corruption.

UTF-8 & Multibyte Character Encoding

Unicode characters outside the ASCII range (such as Hindi, Chinese, Cyrillic, and Emoji) are represented in URLs as multibyte UTF-8 byte sequences. For example, the Hindi text नमस्ते is encoded as 15 characters (%E0%A4%A8...). Our decoder groups and validates multibyte byte sequences without corruption.

Security & XSS Protection

Decoded URLs may contain malicious script tags (e.g. %3Cscript%3E). This tool strictly renders all decoded output as plain text using safe DOM node assignment (never innerHTML or eval()). Furthermore, protocol validation safeguards against dangerous scheme navigation.