Standards-Compliant RFC 3986 & WHATWG Parser

URL Parser

Deconstruct complex URLs into standard components: Scheme, Credentials, Host, IPv4/IPv6 classification, Port, Origin, Path segments, Query parameters, and Hash fragment.

Load Preset Example:

Parsing URL components & structure...

SCHEME

https

Web Transport
HOST / DOMAIN

example.com

Domain Name
PORT

443

Default Port
PATH

/

0 Segments
Standards URL Component Breakdown
ComponentValueType / Status
Scheme / ProtocolhttpsScheme
UsernameuserCredentials
Password••••••••Sensitive
Hostname / Addressexample.com
Unicode: • Punycode:
Domain
Port Number443Default
Originhttps://example.comCalculated Origin
Pathname/Path String
Query String(None)Query
Fragment / Hash(None)Fragment
No query string parameters were found in the URL.
Parameter KeyDecoded ValueRaw ValueFlags / Status
Path contains root segment only (/).
IndexRaw SegmentDecoded SegmentStatus
Complete parsed JSON data structure (credentials redacted for safe copy):
Recent URL Parsing History
No recent parsed URLs saved.

URL Component Architecture & Developer Reference

RFC 3986 URI Components

A Uniform Resource Identifier (URI) consists of five main components: scheme://user:pass@host:port/path?query#fragment.

Our parser uses standards-compliant URI decomposition to cleanly isolate structural boundaries without falling back on simplistic string-splitting heuristics.

Explicit vs Default Port Numbers

Network protocols assign default port numbers (e.g. 80 for HTTP, 443 for HTTPS, 21 for FTP).

Our engine distinguishes explicitly user-entered ports (such as :8443) from default scheme ports, ensuring default ports are never presented as explicit input.

Duplicate & Empty Query Parameters

Query parameter strings often contain duplicate keys (e.g. ?tag=seo&tag=developer), empty values (?foo=), or flags without equals signs (?debug).

The parameter extraction engine preserves all duplicate parameter occurrences without overwriting keys or dropping value-less flags.

Credential Masking & Security

Embedded URL passwords (e.g. https://user:pass@domain) pose security risks if logged or shared. Passwords are automatically masked with bullets (••••••••) in the UI and automatically redacted from exported JSON logs and history storage.