Free Online Query String and URL Builder with Parser
Paste a URL or a bare query string and get a table of keys and values, decoded and raw side by side, with repeated keys and array syntax recognised. Then edit the rows, edit the parts, and read the rebuilt URL with its length and a warning past 2000 characters.
Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.
Which Characters Have to Be Encoded
The ones that mean something structural, plus everything outside ASCII.
| Character | Encoded | Why it matters in a query string |
|---|---|---|
& | %26 | Separates one parameter from the next. An unencoded ampersand inside a value splits it in two, which is the most common way a value arrives truncated. |
= | %3D | Separates a key from its value. Only the first one counts, so an unencoded equals sign later in a value is usually survivable but never safe. |
? | %3F | Starts the query. Inside a value it is often tolerated, and often not. |
# | %23 | Starts the fragment. Everything after it is never sent to the server at all, so an unencoded hash silently throws away the rest of your URL. |
+ | %2B | Read as a space by most server side form parsers. A plus in a password, a phone number or a base64 value must be encoded or it arrives as a space. |
% | %25 | Starts an escape. A lone percent that is not followed by two hex digits makes the whole value fail to decode. |
space | %20 | Not allowed raw. Use %20, which is correct everywhere, or +, which is correct only in a query string. |
/ : @ | %2F %3A %40 | Structural in the rest of the URL but usually harmless in a value. encodeURIComponent encodes the slash and the at sign and leaves the colon, which is why a value holding a path needs care. |
Everything outside unreserved ASCII, which is letters, digits and
- _ . ~, has to be percent encoded as its UTF-8 bytes. That is why an accented
letter becomes two escapes and an emoji becomes four. The square brackets in
a[]=1 are technically reserved and ought to be encoded too; almost every
framework emits them literally because almost every server accepts them, and this page does
the same so the output matches what your browser would send.
How to Parse and Build a URL
A few steps, and nothing is uploaded.
What to Know About URL Encoding
Including the two encoders and which one you want.
encodeURIComponent escapes the structural characters & = ? # / as well, which is exactly right for one key or one value, because those characters have to survive as data. encodeURI deliberately leaves them alone so that an already assembled address is not destroyed, which makes it right for tidying up a complete URL and completely wrong for a value: run it on a value containing an ampersand and you have silently created two parameters. The rule that always works is to encode each key and each value separately with encodeURIComponent, then join them with & and = yourself, which is what this page does.
application/x-www-form-urlencoded, not from the URL standard, and it applies to the query alone. In a path, /my+file is a file with a plus in its name. Server side, PHP, Python and most frameworks turn a plus in the query into a space, while JavaScript's own decodeURIComponent does not, which is why a value looks right in the browser and wrong in the log. %20 is correct in every part of a URL and in every parser, so use it unless you are deliberately matching a form post.
a=1&a=2 is perfectly legal, and every stack reads it differently: PHP keeps only the last value unless you write a[], Express and Rails build an array, ASP.NET joins them with a comma, and Go gives you the first unless you ask for the slice. So the table here shows repeats as repeats rather than quietly collapsing them, and the builder lets you pick which of the three common spellings to emit.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
About the URL Builder
A query string is the simplest structure on the web and it goes wrong constantly. An ampersand inside a value cuts the value in half. A plus sign that should have been a plus arrives as a space. A percent that is not followed by two hex digits makes the whole parameter undecodable. None of these are visible by staring at the URL, because the damage is in the difference between what the text says and what a parser makes of it.
So this page shows both. Every parameter gets its decoded value and its raw value next to each other, and that pairing is usually the whole diagnosis: if the decoded value has a space where the raw value has a plus, you now know which convention is being applied. Repeated keys are left as repeats, because collapsing them is a decision the server makes, not the URL, and array spellings such as a[] and a[0] are labelled rather than flattened.
The building half is the same data going the other way. The parameter rows and the URL parts are what the output is generated from, each key and each value encoded on its own with encodeURIComponent and then joined by hand, which is the only assembly order that cannot corrupt a value. The length is counted because long URLs still break things quietly in old proxies and logging tools, and the warning at 2000 characters says plainly that modern browsers allow far more than that.
Frequently Asked Questions
Encoders, the plus sign, repeated keys and URL length.
encodeURIComponent on each key and each value separately, then join them yourself with ampersands and equals signs. encodeURI exists to tidy up a URL you have already assembled, so it deliberately leaves & = ? # / alone, which means running it on a value that contains an ampersand creates an extra parameter instead of escaping it. If you find yourself reaching for encodeURI on part of a URL, that is the bug.decodeURIComponent never converts it, so the same URL can decode differently in your browser and on your server. Encode a real plus as %2B and encode spaces as %20, and the ambiguity disappears.