A separator can also be part of a value
In https://example.com/search?q=tea&sort=new, the question mark begins the query and the ampersand separates two parameters. But in the search phrase tea & coffee, the ampersand is part of the text.
Encode that phrase as one component to produce tea%20%26%20coffee. The resulting query, q=tea%20%26%20coffee, keeps the complete phrase inside the q value.
Use component mode for individual values
Component encoding is the right starting point for one query value or one path segment. It converts characters that could otherwise become separators.
Do not encode the entire assembled URL as a component unless that whole URL is itself a value inside another URL. Turning every slash, colon and question mark into an escape would also encode the outer link’s structure.
Full-URL mode preserves existing structure
Full-URL encoding keeps reserved separators in place. It can encode spaces or non-ASCII text in an existing URI, but it cannot tell which ampersands were meant as data.
If an unencoded value already contains & or #, encoding the whole link afterward will not repair the ambiguity. Build the link from separately encoded values, or use a URL-building library that handles query parameters.
A plus sign is not always a space
Generic percent encoding represents a space as %20. HTML form query encoding can represent it as +. A literal plus can be represented as %2B.
ToolRook’s percent decoder does not automatically turn + into a space. For q=C%2B%2B, decoding the value yields C++. Decide whether a plus represents data or form spacing before replacing it.
Decode one layer at a time
If an existing %20 is encoded again, its percent sign becomes %25 and the result is %2520. This can be intentional when a URL is nested inside another URL, but it is often a sign that the same value passed through encoding twice.
Keep the original, decode one layer and inspect it. Do not repeatedly decode until a string looks readable: changing an encoded delimiter can change how a downstream application interprets it. Encoding is reversible and does not protect a password or token.
- An incomplete escape such as %2 can cause a decoding error.
- Encoding changes representation; it does not confirm that a destination is safe.
- When building software, use a URL or query-parameter API where possible and test the resulting link.
Put it into practice with a tool from the toolbox.
Explore tools