October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

How to Encode and Decode URL Query Strings Safely

Use the receiving endpoint’s query-string convention, encode parameter values rather than the whole URL, and parse fields before decoding them once.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build a query string from separate parameter names and values, using the format the receiving server expects. Parse the query into fields before decoding each value, and decode each component only once. This avoids common errors such as turning a literal plus sign into a space or allowing encoded data to become a delimiter.

Why query-string encoding depends on the receiver

A URL query is not automatically an HTML form. Generic URI syntax, browser URL APIs, form-urlencoded data, and an API’s own parameter rules can serialize similar-looking values differently. Follow the endpoint’s documented contract and use a matching serializer and parser. RFC 3986 describes generic URI syntax; the WHATWG URL Standard defines browser URL APIs and form-urlencoded behavior; OpenAPI describes API parameter serialization.

Percent-encoding represents an octet as a percent sign followed by two hexadecimal digits, such as %2F. In RFC 3986, letters, digits, hyphen, period, underscore, and tilde are unreserved characters. Characters such as & and = can serve as query delimiters; when they are data inside a parameter value, encode them as required by the receiver so they are not mistaken for structure. See RFC 3986.

Does a plus sign mean a space?

It depends on the query format and parser. In form-urlencoded data, + represents a space. A literal plus sign in a value must therefore be written as %2B when the receiving parser uses form-urlencoded rules. In generic URI syntax, do not assume every parser gives a raw plus that meaning.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Pearson Computer Networking, 8E
  • brand: Pearson
  • Computer Networking, 8e

For example, a form-urlencoded value intended to be tea + milk can be serialized as tea+%2B+milk. The two plus signs stand for spaces; %2B stands for the literal plus. Python’s urllib.parse.urlencode() uses this convention by default. If an endpoint requires spaces as %20, choose a serializer configured for that behavior instead. The relevant Python behavior is documented in Python 3.14’s urllib.parse documentation.

Safe encoding and decoding sequence

  1. Keep parameters structured. Start with individual keys and values rather than assembling a query string by concatenating text.
  2. Serialize with the endpoint’s rules. Use its documented convention for spaces, repeated keys, arrays, and other parameter shapes.
  3. Encode data, not the whole URL. Use a query serializer or component encoder for parameter data. Encoding a complete URL can also encode structural characters such as ?, &, and =.
  4. Parse the query before decoding its fields. Identify keys and values using the query’s delimiters first. Decoding first can turn encoded data into delimiter characters and change how fields are interpreted.
  5. Decode each component once with a matching parser. Do not repeatedly decode or encode a string. RFC 3986 warns that doing so can change the interpretation of percent signs and encoded data.
  6. Validate the decoded value. Apply application checks to the value the application will actually use, not just its encoded spelling. Handle unexpected data, including NUL, according to the application’s requirements.

Choose a serializer that matches your implementation

Browser JavaScript

When the endpoint uses browser-compatible URL or form query semantics, use the platform URL and URLSearchParams APIs rather than manually joining strings. The WHATWG URL Standard defines their behavior, including form-urlencoded serialization.

Python

Use urllib.parse.urlencode() to serialize keys and values, and parse_qs() or parse_qsl() to parse query data. urlencode() accepts a mapping or ordered pairs; pass doseq=True to emit repeated key/value pairs for sequence values. Its default uses quote_plus(), which represents spaces as plus signs. Where the endpoint requires %20, use quote() through the quote_via option. Consult the Python documentation and the endpoint contract.

API clients

Check the API’s parameter style, whether values are exploded into repeated fields, and whether form-urlencoded serialization applies. OpenAPI 3.1.0 distinguishes generic query serialization from form-urlencoded rules and recommends WHATWG form rules where maximum browser compatibility is desired. See the OpenAPI 3.1.0 specification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common failures and how to avoid them

  • A space or plus changes unexpectedly: Check whether the receiving parser uses form-urlencoded rules. In that format, encode a literal plus as %2B; use the serializer’s space representation expected by the endpoint.
  • Encoded separators alter the fields: Parse or split the query before decoding field data. Otherwise a value such as %26 may become & before field boundaries have been identified.
  • A value appears double-encoded or changes after repeated decoding: Trace where each transformation occurs and ensure the component is encoded once for transport and decoded once by the matching parser. RFC 3986 Section 2.4 says implementations must not percent-encode or decode the same string more than once.
  • Arrays, duplicate keys, or empty values behave differently across systems: Do not assume universal behavior. Confirm the API’s contract; serializers and parsers can represent or handle these cases differently. Python, for example, supports ordered pairs and offers multiple parsing helpers.
  • Validation misses a dangerous or unexpected value: Validate the decoded value under the application’s rules, because encoded text may not reveal what the application will process.

Quick decision guide

Question What to check
Which query convention applies? Whether the endpoint expects generic URI query syntax, form-urlencoded data, or an API-defined serialization.
How are spaces represented? Whether the receiver expects + or %20.
How are multiple values represented? Whether duplicate keys, arrays, and empty values are supported and how they are serialized.
Does parsing match encoding? Whether the receiver uses the corresponding parser and decodes each component exactly once.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.