October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
HTTP

What Are Query Strings? URL Parameters, Syntax, Encoding, and JavaScript

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A query string is the part of a URL that starts with ? after the path. It carries application-defined input—usually parameters written as name=value pairs separated by &. In https://example.com/products?category=books&sort=price#results, the query string is ?category=books&sort=price; #results is a separate fragment handled after the resource is delivered.

Query strings let an application filter, search, sort, paginate, select a representation, or otherwise tailor a response. Their names and meanings are not universal: the server or client code that receives them defines what they do.

Where the query string begins and ends

Read a URL from left to right. The scheme and authority identify how and where to connect, the path identifies a hierarchical location, the query carries non-hierarchical input, and the fragment identifies a position or state within the returned representation.

URL component Example Typical role
Scheme https:// Communication scheme
Authority example.com Host and optional port or credentials
Path /products Hierarchical resource location
Query ?category=books&sort=price Application input or selection
Fragment #results Position or client-side state in the returned resource

The query starts at the first ? after the path. It ends at the first #, because # starts the fragment, or at the end of the URI if no fragment exists. A URL can have a path without a query, a query without a fragment, or all three.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How query-string syntax works

Parameter pairs

The common notation is key=value. In the example, category=books and sort=price are two parameter pairs. The ampersand separates pairs, while the first equals sign conventionally separates a parameter name from its value.

This is a widespread convention, not a rule that gives every parameter a universal meaning. One application may define sort=price; another may ignore it. Names such as q, page, or utm_source only have meaning when the receiving application documents them.

Missing, empty, and repeated values

Applications may distinguish ?draft, ?draft=, and an absent draft parameter—or treat them alike. Repeated keys such as ?tag=css&tag=api, parameter ordering, and whether a plus sign means a space depend on the parser and the application’s conventions. Do not assume that two servers interpret these forms identically.

Query-only URLs and delimiters

A URL may contain a query with no path beyond the root, such as https://example.com/?q=books. If a value itself contains delimiter characters, encode it so the parser does not mistake data for URL structure.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What servers do with query parameters

When a browser requests a URL, the server receives the query as part of the request target. The application can then choose a response based on those parameters.

  • Filtering: /products?category=books can select only books.
  • Searching: /search?q=router can pass a search term.
  • Sorting: /products?sort=price can request a price order.
  • Pagination: /articles?page=2 can select another page.
  • Representation or view selection: an application may use a parameter to choose a format, language, or layout.

These behaviors are implementation-specific. A standards-compliant URL does not guarantee that a server accepts a particular parameter, validates it, or applies it safely. Treat undocumented parameters as unknown input.

Query strings versus paths and fragments

Path or query?

Use the path when a value is part of the resource’s hierarchical identity, such as /users/42. Use a query when the value is an input that modifies a collection or representation, such as /users?role=admin. This is a design convention rather than a mechanical requirement; the application’s documented URL design is authoritative.

Query or fragment?

A query is sent to the server and can affect the HTTP response. A fragment is separated by # and is not included in the request target sent to the server. Browsers commonly use fragments for an in-page anchor such as #results, and client-side applications may use them for local state. If the server must know the value while generating the response, it belongs in the query (or path), not only in the fragment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Encoding spaces and reserved characters

RFC 3986 defines the query grammar as a sequence of allowed path characters plus / and ?. Characters that have delimiter roles must be percent-encoded when they are literal data. For example, a search value containing a space can be represented as router%20setup, producing ?q=router%20setup. A literal ampersand in a value should be encoded as %26; otherwise it can be mistaken for the separator between parameters.

Do not hand-concatenate untrusted text into a URL. Encode parameter names and values with a URL API or a library, and follow the receiving application’s rules for form encoding. A plus sign, duplicate keys, key ordering, and an omitted value can have application-specific meanings.

Reading and editing query strings in JavaScript

Inspecting the raw query

The browser URL object exposes the complete parameter string through url.search, including its leading ?. Use url.searchParams when you need individual values.

const url = new URL("https://example.com/products?category=books&sort=price#results"""" );

console.log(url.search);                 // "?category=books&sort=price"
console.log(url.searchParams.get("category")); // "books"
console.log(url.searchParams.get("sort"));     // "price"
console.log(url.hash);                   // "#results"

In a browser page, new URL(location.href) parses the current address. In server-side JavaScript, pass the complete URL explicitly or provide a base URL when parsing a relative reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adding, replacing, and deleting parameters

const url = new URL("https://example.com/products?category=books&sort=price");

url.searchParams.set("page", "2");       // adds or replaces page
url.searchParams.set("sort", "rating");  // replaces price
url.searchParams.delete("category");

console.log(url.toString());
// https://example.com/products?sort=rating&page=2

set() replaces existing values for a key. If an application intentionally accepts multiple values, use append() and read them with getAll():

const url = new URL("https://example.com/articles");
url.searchParams.append("tag", "css");
url.searchParams.append("tag", "api");

console.log(url.searchParams.getAll("tag")); // ["css", "api"]

Serialization details, including exact escaping and ordering, should be verified against the browser or runtime version you support. For raw display use search; for parameter-level operations use URLSearchParams.

Working with query strings in common tools

cURL

Quote a complete URL so the shell does not treat & as a command separator:

curl 'https://example.com/products?category=books&sort=price'

For generated values, let cURL encode the URL parameter:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G 'https://example.com/search' 
  --data-urlencode 'q=router setup' 
  --data-urlencode 'page=2'

Python

Use the standard URL helpers instead of concatenating unescaped text:

from urllib.parse import urlencode
from urllib.request import urlopen

params = {"q": "router setup", "page": 2}
url = "https://example.com/search?" + urlencode(params)
with urlopen(url, timeout=30) as response:
    body = response.read()
print(url)

Node.js

const url = new URL('https://example.com/search');
url.searchParams.set('q', 'router setup');
url.searchParams.set('page', '2');

const response = await fetch(url);
console.log(response.status);
console.log(await response.text());

Designing dependable query parameters

  • Document names and types: state whether page is an integer, whether sort accepts only a fixed set, and what happens when a key is absent.
  • Validate on the server: reject impossible ranges and unsupported values rather than trusting the browser.
  • Encode at the boundary: keep values as data internally and serialize them only when constructing the URL.
  • Choose a repeated-key policy: document whether tag=a&tag=b, comma-separated values, or only one value is accepted.
  • Consider privacy: URLs can appear in browser history, server logs, analytics, bookmarks, and referrer data. Do not place secrets, passwords, or sensitive personal data in a query string.
  • Define canonical forms: if caches or signatures depend on the URL, document parameter ordering, casing, defaults, and duplicate-key handling.

Troubleshooting query-string problems

The server says a parameter is missing

Inspect the final URL, not the source variables. Check that the first ? exists, that the parameter name is spelled as documented, and that a shell or template did not remove text after an unquoted ampersand. In JavaScript, log url.href after all edits.

A value is split at an ampersand or equals sign

The value was probably concatenated without encoding. Construct it with URLSearchParams, Python’s urlencode, or cURL’s --data-urlencode. A literal & should appear encoded inside a value.

The browser shows the right URL but the server does not change

Confirm that the value is in the query rather than only after #. Fragments are handled separately and are not sent as part of the request target. Also check whether the application actually documents that parameter and whether a cached response is masking a change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Duplicate parameters behave unexpectedly

Check the receiving application’s rule. Some parsers keep the first value, some keep the last, and others return a list. Use getAll() when multiple values are intentional and document the expected order.

Changing parameter order changes a cache or signature

Although two URLs may represent the same conceptual request to a human, infrastructure can treat their byte-for-byte URLs as different keys. Establish a canonical order and encoding policy before generating cache keys, signed links, or deduplicated requests.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is to capture a URL that contains query parameters rather than build a browser automation pipeline, ScreenshotNeo provides a single screenshot API request. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and the response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.

See the ScreenshotNeo API documentation for the full option set. This cURL call captures a URL containing query parameters:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url="https://example.com/products?category=books&sort=price" -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com/products?category=books&sort=price"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com/products?category=books&sort=price' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Every feature is included on every plan, including full-page and element captures, device and retina settings, custom CSS or JavaScript, waits, request blocking, headers and cookies, PDFs, signed links, async webhooks, bulk capture of up to 100 URLs per call, caching with a chosen TTL, and a usage API. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

FAQ

Is everything after a question mark a query string?

Only the portion from the first query delimiter to the next # (or the end of the URL) is the query. A later question mark can be data within that component if it is not introducing a fragment.

Can query strings be used with POST requests?

Yes. A query is part of the request URL regardless of the HTTP method. An application may also receive a separate request body; the two inputs have different processing and security considerations.

Should query parameters be case-sensitive?

Assume names and values are case-sensitive unless the target application’s documentation says otherwise. URL syntax does not make all application parameters equivalent by changing case.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does copying a URL sometimes lose a parameter?

Copying the address normally preserves the query, but application code, redirects, link cleaners, or an unencoded delimiter can rewrite it. Compare the copied URL with the final address shown after navigation.

Frequently Asked Questions

Can query strings be used with POST requests?

Yes. A query is part of the URL regardless of the HTTP method; a POST request may also carry a separate body.

Should query parameter names be case-sensitive?

Treat names and values as case-sensitive unless the receiving application’s documentation explicitly defines case-insensitive behavior.

Why can two differently ordered queries return the same data?

The application may treat parameter order as irrelevant, even though caches, signatures, or logs can still distinguish the complete URL text.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Query strings are application-defined parameters between a URL’s path and fragment. Use the path for hierarchy, the query for server-visible inputs, the fragment for client-side position, and URL APIs or libraries to encode and manipulate values safely.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.