URL Parser
Break a URL into its parts and edit the query string. Runs in your browser — the URL never leaves your device.
Components
Query parameters
| Name | Decoded value | Raw |
|---|
This URL has no query string.
Rebuilt URL
How to Parse a URL
- Paste a URL into the box.
- Read the parts table — protocol, host, port, path, query and fragment.
- Check the query parameters, raw and decoded.
- Edit, add or remove parameters and watch the URL rebuild.
- Copy the result.
Parsing uses the browser's own URL API. The URL never leaves your device.
The parts of a URL
Taking the sample apart, since the names are used inconsistently everywhere:
https://shop.example.com:8443/en-gb/products?q=keyboard&page=2#reviews └─┬─┘ └───────┬───────┘ └┬─┘└──────┬──────┘ └───────┬───────┘ └──┬──┘ scheme host port pathname search hash
| Part | Worth knowing |
|---|---|
| scheme | https or http. Without one the string is not a URL at all, which is the single most common reason parsing fails. |
| host | The hostname. "origin" means scheme + host + port together — the unit that browser security is actually built on. |
| port | Omitted when it is the default for the scheme (443 for https, 80 for http). A URL showing no port is still using one. |
| pathname | Always starts with a slash. Percent-encoded in the raw URL; a space here is %20, never a plus. |
| search | Everything after ?, sent to the server and routinely written to its logs. Do not put secrets here. |
| hash | Everything after #. Never sent to the server — the browser keeps it. Which is why it was the old home of OAuth tokens. |
Plus signs, spaces, and the bug that will not die
In a query string, + has historically meant a space — that is the
application/x-www-form-urlencoded convention, not a rule of URLs. In the path,
+ means a literal plus sign. Same character, two meanings, decided entirely by
which side of the ? it sits on.
This is why an email address survives a round trip until someone has a + in it
and [email protected] arrives as user [email protected]. The fix
is to encode it as %2B. The raw column in the table above is where you will
spot this: if the decoded value has a space your raw value never had, a plus is the culprit.
To encode or decode a value by hand, the URL Encoder does exactly that and shows both directions.
Specifications
- Accepts
- A URL — type or paste
- Gives you
- On-screen result · copy to clipboard
- Where it runs
- Your browser — the file is never uploaded
- Sign-up
- None
- Cost
- Free, with no usage limits
FAQ
Is the URL sent anywhere?
No. Parsing uses the browser's own URL API, in your tab. That matters more than it sounds: the URLs developers paste into a parser routinely carry session tokens, signed S3 links and API keys in the query string.
Why are my parameter values decoded?
The table shows both. The decoded value is what your application receives after percent-decoding; the raw value is what actually travels in the URL. When a parameter misbehaves, the difference between those two columns is usually where the bug is.
Can a URL have the same parameter twice?
Yes, and it is legal — ?tag=a&tag=b is how most frameworks express a list. The table shows every occurrence as its own row rather than collapsing them, because a duplicate you did not expect is worth seeing. Note that some backends keep only the first and some only the last.
What is the difference between hash and query?
The query string (after ?) is sent to the server. The fragment (after #) never leaves the browser — servers never see it. Putting a token in a fragment keeps it out of server logs, which is exactly why OAuth implicit flow used to do it.
Why does my URL fail to parse?
Almost always a missing scheme: "example.com/path" is not a URL, "https://example.com/path" is. Spaces are the other common cause — they must be encoded as %20 before the string is a valid URL.
Can I remove tracking parameters?
Yes. Clear UTM strips the five utm_* parameters plus the common click identifiers (fbclid, gclid and friends) and rebuilds the URL. Handy before pasting a link into a document or a chat.