How it works
- 01
Paste the encoded text
A whole URL or one parameter value. It stays in this tab.
- 02
Read it back
The panes update as you type. A bad sequence is pointed at, never guessed at.
- 03
Check the parameters
The query string is split into a table, and each value can be copied on its own.
Double-encoding, and how to spot it
Text that still has percent signs in it after one pass was encoded twice. %2520 is a percent sign that was itself escaped. It decodes to %20, and then to a space. This happens when a URL travels through two systems that each escape it to be safe.
Decode repeatedly is off by default, because it destroys text that really contains a percent sequence. The safe habit is one pass at a time until the output stops changing. The footer of the Decoded pane says how many passes ran. With the switch on, the tool stops after 10.
- Accepts
- Any percent-encoded text: whole URLs or single values.
- Query split
- Done before decoding, so an escaped & stays in its value.
- Encoding
- UTF-8 by default. Latin-1 is there for older systems.
- Bad input
- A stray % or a cut-off sequence is reported, not guessed.
Reading the parameter table
When the query string is readable in the input, the table splits it first and decodes each piece after. That order matters. A value can hold an escaped ampersand, and a splitter that decodes first turns it into a real one and cuts the value in half. When the whole URL was encoded, the separators only appear after one pass, so the table decodes once and then splits.
Repeated keys each get their own row, because servers disagree about which one wins. Each value is decoded on its own, so a parameter holding a whole encoded URL comes back readable in its row.