Developer
URL encoding explained
Reviewed by the Tabreon team · Last updated: September 2026
Quick answer
URL encoding (also called percent-encoding) replaces characters that aren't allowed in a URL — like spaces, &, or non-ASCII characters — with a percent sign followed by their hex code, so the URL stays valid.
Why this matters
Without URL encoding, characters like `&` or `?` inside a query parameter would be misread as part of the URL's structure instead of as data, breaking the link.
Definition
URLs can only safely contain a limited set of characters (letters, digits, and a handful of symbols). Any other character — spaces, accented letters, reserved symbols like `&`, `=`, `?`, `#` used outside their structural role — must be percent-encoded: replaced with `%` followed by the character's two-digit hexadecimal byte value.
How it works
The encoder converts each character that needs escaping into its UTF-8 byte representation, then writes each byte as `%XX` in hexadecimal. A space, for example, becomes `%20` (or `+` in query-string form). Decoding reverses the process, converting each `%XX` sequence back into its original character.
Common characters and their encoded form
| Character | Encoded | |
|---|---|---|
| Space | %20 (or + in a query string) | |
| Ampersand | & | %26 |
| Question mark | ? | %3F |
| Hash | # | %23 |
| Forward slash | / | %2F |
Common mistakes
- Manually concatenating user input into a URL without encoding it, breaking the URL if the input contains `&`, `?`, or `#`.
- Double-encoding a value that's already encoded, turning `%20` into `%2520`.
- Confusing `+` and `%20` for spaces — `+` is only a space in query-string context, not in a URL path.
Best practices
- Always encode dynamic values (like user input) before inserting them into a URL, rather than hand-assembling strings.
- Decode a URL exactly once when reading it — decoding twice can corrupt values that legitimately contain a `%` character.
Frequently asked questions
Related tools
Related guides
Sources
- RFC 3986 — Uniform Resource Identifier (URI): Generic Syntax