URL decoder
For links that arrive as %20%26%3A soup: paste, and read what it actually says. Form-style plus signs and double encoding are both handled.
Guide
How to use it
- Paste the encoded text, decoding is live.
- Plus signs are read as spaces (form convention), and the hint notes when a second decode pass looks needed (%25 sequences visible).
- Malformed input, a % not followed by two hex digits, is flagged rather than half-decoded, usually a truncated paste.
Examples
What you will be decoding
Email and ad links wrap destinations in redirects with the real URL percent-encoded in a parameter. Decoding reveals where a link actually goes before you click, a legitimate paranoia.
Server logs store request paths encoded, decoding /search%3Fq%3Dwinter%20boots back to readable form makes the log tell its story.
A visible %25 means double encoding (the % itself got encoded). One more decode pass unwinds it, redirect chains through multiple services are the usual culprit.
Method
How it works
Decoding reverses percent-escapes to UTF-8 characters via decodeURIComponent, with two practical mercies: + reads as space first (form-encoded data everywhere), and hard failures (truncated escapes) report as errors instead of throwing away your paste.
Nothing decodes to executable anything, this is text formatting, and inspecting a suspicious link’s true destination here is safer than clicking to find out.
FAQ
Frequently asked questions
The decoder says invalid, why?
A lone % without two hex digits after it, nearly always a link truncated mid-escape by a chat app. Find the full link and re-paste.
Why are there still %25 things after decoding?
Double encoding: decode the output again. Chains of redirects encode each other’s work, two passes is common, three is a story.
Are + signs spaces or pluses?
In query strings, spaces (form convention), which is how this decoder reads them. A literal plus should have arrived as %2B.
Can decoding a URL be dangerous?
Reading text is safe, visiting it is the risk. Decode to inspect, then judge the destination like the adult the phisher hopes you are not.
Does it handle unicode?
Fully: %C3%A9 becomes é, multi-byte sequences reassemble correctly, and emoji survive the round trip.
Is the pasted link sent anywhere?
No, decoding is local, links containing tokens and session IDs stay on your machine.
More tools