Tools / URL Encoder
URL Encoder / Decoder
Type or paste raw text on the left and see the URL-encoded (percent-encoded) form on the right - or do it in reverse. Both fields update in real time as you type. Handy for crafting HTTP requests, decoding query parameters, and manipulating form data in web exploitation challenges.
Try an example
Common encodings reference
| Character | Encoded | Notes |
|---|---|---|
| %20 | Space (also + in form data) | |
| ! | %21 | Exclamation mark (left as-is by this tool) |
| " | %22 | Double quote |
| # | %23 | Hash / anchor |
| $ | %24 | Dollar sign |
| % | %25 | Percent (must be encoded) |
| & | %26 | Ampersand (param separator) |
| ' | %27 | Single quote (left as-is by this tool) |
| ( | %28 | Open paren (left as-is by this tool) |
| ) | %29 | Close paren (left as-is by this tool) |
| + | %2B | Plus (also means space in query) |
| , | %2C | Comma |
| / | %2F | Forward slash |
| : | %3A | Colon |
| ; | %3B | Semicolon |
| = | %3D | Equals (param assignment) |
| ? | %3F | Question mark (query start) |
| @ | %40 | At sign |
| [ | %5B | Open bracket |
| ] | %5D | Close bracket |
| { | %7B | Open brace |
| } | %7D | Close brace |
How percent-encoding works
URLs can only contain a safe subset of ASCII characters. Any character outside that set -- including spaces, special punctuation, and non-ASCII bytes - must be represented as a percent sign followed by two hex digits: %XX. For example, a space becomes %20, an equals sign becomes %3D, and an ampersand becomes %26.
In web CTF challenges, percent-encoding is often used to bypass input filters. Injecting %27 instead of a literal single quote can slip past naive keyword blocklists. Double-encoding (encoding the percent sign itself as %25) can bypass a second layer of filtering.
This tool uses the browser's built-in encodeURIComponent and decodeURIComponent functions, which follow RFC 3986. Characters that are unreserved (letters, digits, - _ . ~) are left as-is; everything else is encoded.
Useful for web exploitation challenges in picoCTF - including SQL injection, XSS filter bypasses, and open-redirect chains. Look for web challenges in the picoCTF 2021 Web Gauntlet 2 writeup for examples of encoding-based bypasses.
It is important to distinguish encodeURIComponent from encodeURI. The latter leaves structural URL characters like /, ?, #, and & unencoded because they are meaningful in a URL context. When injecting into a query parameter value, always use encodeURIComponent to ensure every special character is escaped - otherwise an unescaped & or = will break the parameter boundary.
Form data submitted via POST uses a slightly different encoding called application/x-www-form-urlencoded, which replaces spaces with + rather than %20. When crafting a raw HTTP request in a CTF, be aware of which encoding the server expects. If the server decodes + as a space in one context but as a literal plus in another, that discrepancy can be exploited to bypass server-side validation.
Unicode characters (non-ASCII) are first converted to their UTF-8 byte sequence, then each byte is percent-encoded. For example, the euro sign € is U+20AC, which in UTF-8 is three bytes 0xE2 0x82 0xAC, giving the URL encoding %E2%82%AC. Challenges that involve Unicode normalization attacks or path traversal on international hostnames sometimes rely on these multi-byte sequences.
Challenges where it helps
- Failure FailurepicoCTF 2026 · General Skills · Medium
- HashgatepicoCTF 2026 · Web Exploitation · Medium
- North-SouthpicoCTF 2026 · Web Exploitation · Medium
- paper-2picoCTF 2026 · Web Exploitation · Hard
- head-dumppicoCTF 2025 · Web Exploitation · Easy
- PachinkopicoCTF 2025 · Web Exploitation · Medium
- secure-email-servicepicoCTF 2025 · Web Exploitation · Hard
- elementspicoCTF 2024 · Web Exploitation · Hard
- IntroToBurppicoCTF 2024 · Web Exploitation · Easy
- TricksterpicoCTF 2024 · Web Exploitation · Medium
- cancri-sppicoCTF 2023 · Web Exploitation · Hard
- msfroggenerator2picoCTF 2023 · Web Exploitation · Hard
Browse the full challenge library for 16 more.
Guides that use this tool
- Esoteric Languages in CTF: Recognizing Code That Does Not Look Like CodeIdentify and run the esolangs that show up in CTF: Brainfuck, Whitespace, Rockstar, Befunge, Piet, JSFuck and Redcode, with a fingerprint table and an interpreter.
- PHP Type Juggling for CTF: Magic Hashes, Array Tricks, and What PHP 8 BrokeLoose comparison bugs in PHP, from 0e magic hashes to passing arrays into strcmp, plus which classic tricks PHP 8 killed and which ones still work in 2026.
- Race Conditions and TOCTOU for CTF: Winning the Window Between Check and UseHow to find, widen and win race conditions in CTF: symlink TOCTOU on SUID binaries, limit-overrun bugs in web apps, signal races, and mempool front-running.
- sqlmap for CTF: Every Flag That Matters, and What to Do When It Finds NothingA practical sqlmap workflow for CTF: request files, level and risk, technique selection, tamper scripts, second-order injection, and the failure checklist.
- WebAssembly Reversing for CTF: Reading WAT and Recovering Flags from .wasmFind the .wasm a page loads, disassemble it to WAT with wabt, read the stack machine, pull constants out of the data section, and debug it live in DevTools.
- Side-Channel Attacks for CTF: Timing, Power, Compression, and Cache OraclesRecover secrets from what a program leaks rather than what it outputs: timing leaks, correlation power analysis, compression oracles, and cache eviction channels.
Tools that pair with this one
- Base64 & Base32 DecoderDecode Base64 and Base32 strings with auto-detection. Multi-layer mode unwraps nested encodings automatically.
- SQL Injection Payload GeneratorGenerate SQL injection payloads for auth bypass, UNION extraction, blind SQLi, NoSQL operator injection, and sqlmap commands. Supports MySQL, PostgreSQL, SQLite, and MSSQL.
- JWT DecoderDecode JSON Web Tokens and inspect the header, payload, and signature. Useful for web exploitation challenges.
- Regex TesterTest regular expressions against a string with live match highlighting, flag toggles, and common CTF pattern shortcuts.
Or browse all 40 CTF tools.