Skip to main content
WizTools123
WizTools123
Free Online Tools

Tool Categories


Developer Tools New Tool

Free Online Query String and URL Builder with Parser

Paste a URL or a bare query string and get a table of keys and values, decoded and raw side by side, with repeated keys and array syntax recognised. Then edit the rows, edit the parts, and read the rebuilt URL with its length and a warning past 2000 characters.

Free Forever Nothing Uploaded Parse and build Nothing is fetched
Free Online Query String and URL Builder with Parser
Share this tool
Advertisement Slot (Top Banner) Google AdSense Unit • Responsive Banner
Query String & URL Builder Everything happens in this tab. Nothing you paste is sent anywhere.
A URL or a query string
The rebuilt URL

The URL in parts

Leave the host empty for a relative URL. Press Use as input to send the rebuilt URL back to the box above and pull it apart again.

Encoding
Parameters

0 characters 0 parameters

What was in it

Key Value, decoded Value, raw Worth noting
Buy Us A Coffee

Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.

Buy Us A Coffee
Sponsored Content (Below Tool) Google AdSense Placement

Which Characters Have to Be Encoded

The ones that mean something structural, plus everything outside ASCII.

CharacterEncodedWhy it matters in a query string
&%26Separates one parameter from the next. An unencoded ampersand inside a value splits it in two, which is the most common way a value arrives truncated.
=%3DSeparates a key from its value. Only the first one counts, so an unencoded equals sign later in a value is usually survivable but never safe.
?%3FStarts the query. Inside a value it is often tolerated, and often not.
#%23Starts the fragment. Everything after it is never sent to the server at all, so an unencoded hash silently throws away the rest of your URL.
+%2BRead as a space by most server side form parsers. A plus in a password, a phone number or a base64 value must be encoded or it arrives as a space.
%%25Starts an escape. A lone percent that is not followed by two hex digits makes the whole value fail to decode.
space%20Not allowed raw. Use %20, which is correct everywhere, or +, which is correct only in a query string.
/ : @%2F %3A %40Structural in the rest of the URL but usually harmless in a value. encodeURIComponent encodes the slash and the at sign and leaves the colon, which is why a value holding a path needs care.

Everything outside unreserved ASCII, which is letters, digits and - _ . ~, has to be percent encoded as its UTF-8 bytes. That is why an accented letter becomes two escapes and an emoji becomes four. The square brackets in a[]=1 are technically reserved and ought to be encoded too; almost every framework emits them literally because almost every server accepts them, and this page does the same so the output matches what your browser would send.

How to Parse and Build a URL

A few steps, and nothing is uploaded.

1
Paste a URL or a query string A full address, or just the part after the question mark. The parts and the parameter rows are filled in from it as you type.
2
Read the table Each key with its decoded value and its raw value side by side, and a note where a key repeats, uses array syntax, or has an escape that will not decode.
3
Edit it Change the parts, or add, remove and reorder the parameter rows. Choose whether a space becomes %20 or a plus, and how repeated keys are written.
4
Take the URL The output box holds the rebuilt address with everything encoded properly, and the length is counted underneath. Use as input sends it back round for another look.

What to Know About URL Encoding

Including the two encoders and which one you want.

encodeURIComponent for a piece, encodeURI for a whole URL, and using the wrong one is the single most common URL bug. encodeURIComponent escapes the structural characters & = ? # / as well, which is exactly right for one key or one value, because those characters have to survive as data. encodeURI deliberately leaves them alone so that an already assembled address is not destroyed, which makes it right for tidying up a complete URL and completely wrong for a value: run it on a value containing an ampersand and you have silently created two parameters. The rule that always works is to encode each key and each value separately with encodeURIComponent, then join them with & and = yourself, which is what this page does.
A plus sign means a space only by convention, and only in a query string. That convention comes from HTML form encoding, application/x-www-form-urlencoded, not from the URL standard, and it applies to the query alone. In a path, /my+file is a file with a plus in its name. Server side, PHP, Python and most frameworks turn a plus in the query into a space, while JavaScript's own decodeURIComponent does not, which is why a value looks right in the browser and wrong in the log. %20 is correct in every part of a URL and in every parser, so use it unless you are deliberately matching a form post.
Repeated keys are real and common, and there is no standard for what they mean. a=1&a=2 is perfectly legal, and every stack reads it differently: PHP keeps only the last value unless you write a[], Express and Rails build an array, ASP.NET joins them with a comma, and Go gives you the first unless you ask for the slice. So the table here shows repeats as repeats rather than quietly collapsing them, and the builder lets you pick which of the three common spellings to emit.
This page does not fetch anything, and it does not judge whether the URL works. Nothing is requested, so there is no check that the host resolves, that the path exists or that the server accepts your parameters. It also does not convert an international domain to punycode, does not normalise the path by resolving dot segments, and does not know your framework's array convention. It rearranges and encodes text, which is the part that goes wrong most often.

Key Features & Capabilities

What this tool does, and what it deliberately does not.

Raw beside decoded Both values in one table, which is where an encoding mistake shows up.
Repeats kept as repeats a=1&a=2 is shown as two rows, with array syntax recognised.
Editable rows Add, remove and reorder parameters, encoded correctly as you type.
Parts and whole Protocol, host, port, path and fragment, each editable, each updating the URL.
Length watched A count of characters and a warning past 2000, with the honest caveat.
Nothing is fetched No request is made. URLs often carry tokens, and none of this leaves your tab.

About the URL Builder

A query string is the simplest structure on the web and it goes wrong constantly. An ampersand inside a value cuts the value in half. A plus sign that should have been a plus arrives as a space. A percent that is not followed by two hex digits makes the whole parameter undecodable. None of these are visible by staring at the URL, because the damage is in the difference between what the text says and what a parser makes of it.

So this page shows both. Every parameter gets its decoded value and its raw value next to each other, and that pairing is usually the whole diagnosis: if the decoded value has a space where the raw value has a plus, you now know which convention is being applied. Repeated keys are left as repeats, because collapsing them is a decision the server makes, not the URL, and array spellings such as a[] and a[0] are labelled rather than flattened.

The building half is the same data going the other way. The parameter rows and the URL parts are what the output is generated from, each key and each value encoded on its own with encodeURIComponent and then joined by hand, which is the only assembly order that cannot corrupt a value. The length is counted because long URLs still break things quietly in old proxies and logging tools, and the warning at 2000 characters says plainly that modern browsers allow far more than that.

Frequently Asked Questions

Encoders, the plus sign, repeated keys and URL length.

Use encodeURIComponent on each key and each value separately, then join them yourself with ampersands and equals signs. encodeURI exists to tidy up a URL you have already assembled, so it deliberately leaves & = ? # / alone, which means running it on a value that contains an ampersand creates an extra parameter instead of escaping it. If you find yourself reaching for encodeURI on part of a URL, that is the bug.

In a query string, most server side parsers treat it as a space, because of the form encoding convention. In a path it is a literal plus. And JavaScript's own decodeURIComponent never converts it, so the same URL can decode differently in your browser and on your server. Encode a real plus as %2B and encode spaces as %20, and the ambiguity disappears.

Longer than you think, but not indefinitely. Current browsers handle tens of thousands of characters, and the old 2083 character limit came from Internet Explorer. The practical limits now are elsewhere: some servers cap the request line at 8KB, several proxies and load balancers cap it lower, and access logs and analytics tools often truncate. This page warns at 2000 characters as a sensible line in the sand rather than a rule, and says so.

Because your framework decided which one to keep. PHP keeps the last occurrence unless the key ends in square brackets, in which case it builds an array. Express and Rails build an array from plain repeats. ASP.NET joins them with a comma. There is no standard here, so check your own stack and then use the array spelling it expects, which the builder on this page can emit for you.

No. Everything on this page is text handling in your browser, with no request of any kind, which matters because URLs are one of the most common places a token or a session identifier leaks. You can confirm it in your browser network tab, or turn the network off and keep using the page.

Other Developer Tools

Advertisement Slot (Bottom Banner) Google AdSense Unit • Responsive Banner