InTheTab We never get your data

URL encode and decode without uploading

Percent-encodes text so it can safely go into a URL path or query string, and decodes it back. Everything runs in this tab.

How to URL encode or decode

  1. Paste your text. A value to encode, or a percent-encoded string to decode.
  2. Click Encode or Decode. The result appears on the right.
  3. Copy the result. If the input can’t be decoded, the error appears under the buttons.

Good to know

  • Encode works like encodeURIComponent. It is exactly that function. Letters, digits and - _ . ! ~ * ' ( ) are left alone; everything else becomes %XX bytes of UTF-8, so é becomes %C3%A9.
  • It encodes one value, not a whole URL. / ? & = # : are encoded too, which is what you want for a single query parameter or path segment. Paste a full URL and its https:// becomes https%3A%2F%2F. To build a query string, encode each value on its own and join them with & and =.
  • Spaces become %20, not +. Both work in query strings, and %20 also works in paths.
  • Decode doesn’t turn + into a space. It uses decodeURIComponent, which leaves + as it is. For HTML form data (application/x-www-form-urlencoded), replace + with spaces first.
  • Broken sequences are errors. A lone %, a cut-off %E0%A4 or bytes that aren’t valid UTF-8 give URI malformed.

Your data stays on your device

URLs carry more than they seem: session tokens, signed links, email addresses, redirect targets with API keys inside. Here, encoding and decoding happen inside this browser tab with your browser’s built-in functions.

The page’s security policy tells your browser to block uploads, so your data can’t leave your device even by accident. You can check: open your browser’s developer tools, watch the Network tab, and encode something. How InTheTab works

You’ll also see a few small requests to Google Analytics. That’s our visit counter, and it never receives your files. Privacy policy

Questions

What is percent encoding?

It’s how URLs carry characters that would otherwise break them or have a special meaning. Each byte becomes % plus two hex digits, so a space is %20 and & is %26.

Should I use encodeURI or encodeURIComponent?

encodeURIComponent, which this tool uses, for any single value you put into a URL. encodeURI leaves / ? & = # alone, so it’s only for tidying a complete URL, and it won’t protect a value containing those characters.

Why do I get “URI malformed”?

The input has a % that isn’t followed by two hex digits, or the encoded bytes don’t form valid UTF-8 text. Often a literal % that was never encoded, like 100%.

Is it safe to decode links with tokens in them?

Yes. Nothing is uploaded. We never get your files or text: the site has no accounts, and its only analytics, Google Analytics, counts visits without ever seeing what you add here.