Skip to content
Tool4SaaS
HomeAboutContactBlog
Tool4SaaS

185 fast, local utilities for developers and creators. No sign-ups — most tools run in your browser (see /privacy).

hello@tool4saas.com

Categories

  • Text & Documents

  • Business & Writing

  • Developer Tools

  • Converters

  • Generators

  • Images & Design

  • PDF Tools

  • Calculators

  • Finance & Money

  • Health & Fitness

  • SEO & Marketing

  • Time & Date

Popular Tools

  • Invoice Generator

  • QR Code Generator

  • Word Counter

  • Password Generator

  • JSON Formatter

  • Mortgage Calculator

  • EMI Calculator

  • SIP Calculator

  • View all tools →

Company

  • All Tools

  • About Us

  • Author

  • Methodology

  • Blog

  • Contact Us

Guides

  • Invoice Generator Guide

  • QR Code Generator Guide

  • Resume Builder Guide

  • Mortgage Calculator Guide

  • Password Generator Guide

  • Word Counter Guide

  • llms.txt (for AI)

© 2026 Tool4SaaS. All rights reserved.

  • Privacy Policy

  • ·
  • Terms of Service

  • ·
  • ·
  1. Home
  2. /
  3. Blog
  4. /
  5. Developer Guide
  6. /
  7. URL Encoding: Spaces, Symbols and Double-Escape Bugs

URL Encoding: Spaces, Symbols and Double-Escape Bugs

URL encoding rules: %20 vs + per context, reserved-character table, double-escape diagnosis + i18n and length limits. Free encoder/parser.

By Tool4SaaS Editorial Team · Published 2026-10-07 · Updated 2026-10-07 · 3 min read

Try it now — URL Encoder / Decoder, free in your browser

Encode & decode URL components · No signup · No watermark · Free forever.

Open URL Encoder / Decoder →
On this page
  • %20 vs +
  • Reserved characters
  • Limits and i18n

Share link, pasted: https://shop.com/search?q=red shoes&sort=price. Clicked: search for “red”, sort parameter eaten. The unencoded space and raw & split the query in two — a bug invisible in every test with single-word queries. URL encoding is boundary plumbing: %20 vs +, reserved vs unreserved, single vs double encoding. This guide fixes the five encoding bugs behind most “works with test data” link failures.

Part of the developer toolkit guide. Encode and parse with the URL encoder and URL parser.

Spaces: %20 in paths, + in forms

The #1 encoding bug: spaces mean different things per context. In URL paths and most APIs, space → %20 (red%20shoes). In HTML form bodies (application/x-www-form-urlencoded), space → +. Servers decoding form-style + in paths turn “C++” into “C ” — a real bug I have fixed twice. Rule: encode for the context you send to, and test with multi-word values containing & and #, not just “hello world”. café → caf%C3%A9 always (UTF-8 bytes, never Latin-1).

Reserved characters: encode values, never structure

CharMeaning unencodedIn values, send
&Parameter separator%26
=Key/value split%3D
#Fragment start (never sent!)%23
?Query start%3F
%Escape introducer%25 (never double-encode)

Encode values, not structure: ?q=red%20shoes&sort=price keeps separators literal and content encoded. Double-encoding (%2520) happens when two layers each encode — trace which layer owns encoding and make it exactly one. Debug with the parser: paste the broken URL and watch where parameters actually split.

Limits, i18n and the 2000-character cliff

Practical ceilings: ~2000 characters total (older proxies/IE truncate beyond), ~40 non-ASCII symbols before readability collapses, UTF-8 everywhere (emoji = 4 bytes each — budget URL length accordingly). Internationalized domain names punycode-encode (müller.de → xn--mller-kva.de) while paths percent-encode — different mechanisms, both required. For share links with 200+ characters of state, stop encoding and POST the payload or use a short-link store: URLs are addresses, not databases. Fragments (#section) never reach servers — don't put access tokens where only JavaScript can see them (and prefer not to put tokens in URLs at all; see token hygiene).

General guidance only. Test encoded URLs by clicking through, not just copying — intermediaries (chat apps, email clients) re-encode unpredictably.

Related free tools

URL Parser →Base64 Encode / Decode →

Frequently asked questions

%20 in paths and most APIs like red%20shoes, plus only in form bodies with application/x-www-form-urlencoded. Servers decoding form-style plus in paths turn C++ into spaced letters, a bug fixed twice. Test with multi-word values containing ampersands and hashes, encoding café as caf%C3%A9 via UTF-8 bytes.

As %26 since unencoded ampersands split parameters and eat sort values. Same logic applies to equals as %3D and hash as %23 inside values, while keeping structural separators literal like ?q=red%20shoes&sort=price. Debug with the parser by pasting broken URLs to see actual splits for reliable query handling.

%2520 occurs when two layers each encode once, turning intended %20 into literal text. Trace ownership so exactly one layer encodes and decode once to diagnose. Never double-encode percent itself except as %25 in values, and ensure UTF-8 bytes underlie every non-ASCII conversion for consistency.

About 2000 characters practical ceiling since older proxies and IE truncate beyond, with 40 non-ASCII symbols before readability collapses. Budget UTF-8 bytes carefully since emoji cost four bytes each. Beyond that length or with 200+ characters of state, POST payloads or use short-link stores instead.

Fragments never transmit since browsers strip them before sending, leaving only JavaScript able to read them. Don't put tokens or state after hash symbols where servers cannot see them. Prefer avoiding tokens in URLs entirely per token hygiene, and use short links or POST for sensitive state.

Done reading — open the URL Encoder / Decoder

Encode & decode URL components — free in your browser, no signup.

Open URL Encoder / Decoder →

Keep reading in this guide

Pillar guide

Debug API Responses Locally: JSON, Base64, JWT, Regex Guide

In this silo

Base64 URL-Safe vs Standard: Padding and Modes

In this silo

Regex Flags and Capture Groups That Work

In this silo

Check JWT Expiry Without Trusting the Token