URI Component Encoder

If you have ever passed a value like name=John & Jane into a URL without encoding it, you know the pain: the & is read as a new parameter and the server sees garbage. This tool percent-encodes any string for safe use as a URI component following RFC 3986, turning every reserved character into a %HH pair (spaces included). Paste a fragment, a query value or a redirect target and get back something safe to concatenate into any URL.

How to encode a URI component

  1. 1

    Paste your value

    Drop in a single query-parameter value, path segment or fragment string.

  2. 2

    Pick encode or decode

    Switch direction to turn percent-escapes back into the original characters.

  3. 3

    Run it

    The tool UTF-8 encodes each character, then replaces every reserved byte with %HH.

  4. 4

    Copy the result

    Drop the output directly into your URL template or API client.

What gets escaped

This encoder follows RFC 3986: only the unreserved set passes through untouched, A-Z a-z 0-9 - _ . ~. Everything else becomes percent-encoded UTF-8, including the space and the sub-delimiters ! * ' ( ) that JavaScript’s encodeURIComponent would leave alone.

Character Encoded as
space %20
! %21
# %23
& %26
' %27
( %28
) %29
* %2A
+ %2B
/ %2F
= %3D
? %3F
é %C3%A9

Component vs full URI

This encoder is stricter than encodeURI, which leaves : / ? # [ ] @ ! $ & ' ( ) * + , ; = alone because those characters are structural in a URL. For a value you are concatenating into a query string you want the strict form, which is exactly what this tool produces, it even escapes ! ' ( ) *, going one step beyond JavaScript’s encodeURIComponent.

const url = `/search?q=${encodeURIComponent(userInput)}`;

Common pitfalls

  • Double encoding: encoding something that is already encoded gives you %2520 instead of %20. Always decode first if you are unsure about the source.
  • Plus signs in forms: HTML form submission encodes spaces as +, not %20. Decoders that follow RFC 3986 strictly (this one included) will not turn + back into a space. Use a form-aware decoder for those cases.
  • Path separators: encoding / here turns it into %2F. If you need to keep real path structure, join the segments first and encode each one separately.

Frequently Asked Questions

It is RFC 3986 percent-encoding, the strict form. It escapes :, /, ?, # and the other reserved characters (plus !, ', (, ) and *) because a component should not carry URL structure inside it. That makes it stricter than JavaScript’s encodeURIComponent and much stricter than encodeURI.

%20 is the RFC 3986 way. + for space is a legacy from application/x-www-form-urlencoded body encoding. For query strings in URLs, %20 is always safe; + is only expected on the server when it was produced by a form POST.

Each character is UTF-8 encoded first, then every byte is escaped. A character like 日 becomes %E6%97%A5 (three bytes).

No. The value is percent-encoded on the server to build your result and is not stored or logged; nothing you paste is retained once the response is sent.

Related Tools

Tool available in other languages