DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk4 min

URL Encoding: When to Use %20, +, and %2B in Query Strings

%20 encodes a space octet; + means space only in form-style data. Use the right serializer for the URL component and parse before decoding.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

%20 represents a space octet in percent-encoding. A plus sign represents a space only under the application/x-www-form-urlencoded convention; elsewhere, it may be a literal plus. If you are fixing a query-string bug, the key is to encode the value for the format your receiving API expects, then parse the URL before decoding its data.

What percent-encoding represents

Percent-encoding represents an octet as a three-character sequence: a percent sign followed by two hexadecimal digits. For example, %20 represents octet 0x20, the US-ASCII space. The sequence represents bytes, not an abstract character by itself. For text outside ASCII, the relevant format or scheme determines the character encoding used to produce those bytes.

As an Amazon Associate I earn from qualifying purchases.

RFC 3986 recommends UTF-8 for new URI schemes that carry non-ASCII text, followed by percent-encoding octets that are not in the unreserved set. Hexadecimal letters in percent triplets are case-insensitive, though the RFC recommends uppercase for consistency. RFC 3986, §§ 2.1 and 2.5

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is the difference between %20 and +?

Representation Meaning and scope What a parser may do
%20 Percent-encoding for the space octet. A percent-decoder converts the triplet to the represented octet; interpreting that octet as text depends on the applicable character encoding.
+ Represents a space in application/x-www-form-urlencoded data. In generic URI syntax, plus is not a universal space marker. A form-style parser maps plus to space. A parser for another URI component need not.
%2B Percent-encoding for a literal plus sign when plus would otherwise be treated as the form-style space convention. A matching percent-decoder restores the plus as data.

For example, a form-style serialization of the value C++ guide could be C%2B%2B+guide: the two literal plus signs are escaped, while the space uses plus. This illustrates the form convention; not every language or library emits identical output in every context. The WHATWG URL Standard defines browser-platform form serialization, and MDN explains the distinction between percent-encoding and form encoding. WHATWG URL Standard; MDN: Percent-encoding

Does plus mean space in a URL?

No—not in every URL. The plus-for-space behavior belongs to the form-style application/x-www-form-urlencoded convention. A plus in another URI component can remain a plus. This is why the same visible query text can produce different results when one system treats it as form-encoded name/value data and another applies only generic URI parsing. Follow the receiving endpoint’s contract and pair its expected parser with a matching serializer.

Encode the component or value, not the whole URL

A URL contains structural characters as well as data. The question mark introduces the query component, and the hash introduces a fragment. In common key/value query formats, ampersand separates pairs and equals sign separates a key from its value. If one of those characters is part of a value, it must be represented as data according to the chosen convention so it is not mistaken for a delimiter.

There is no single encoding rule for every place in a URL. A slash in a path may separate segments; in a query, RFC 3986 permits slash and question mark as query data. Encoding every reserved character everywhere can therefore alter meaning just as leaving data unescaped can. RFC 3986, §§ 2.2 and 3

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Whole URL: give a complete URL to a URL parser or builder, not to a function intended to encode one value.
  • Path data: encode data within the relevant path segment; preserve separators that are intended to divide segments.
  • Query parameter: pass raw key/value data to a query or form serializer instead of concatenating unescaped strings.

In browser JavaScript, the URL API parses URL structure and URLSearchParams works with query parameter pairs using browser URL/form rules. Other languages and frameworks may differ, so verify the API’s behavior and the server’s expected format. MDN: URL API; WHATWG URL Standard

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why API query strings turn plus signs into spaces

A common cause is a mismatch between the sender and receiver: the sender means a literal plus, but the receiver parses the value as form-encoded data and converts plus to space. If the receiver expects form-style parameters, serialize a literal plus as %2B. If it expects a different query format, use that format’s rules instead; plus is not intrinsically a space in generic URI syntax.

Another cause is manually joining strings. For example, inserting raw ampersands or equals signs into a value can make a parser treat them as pair separators or key/value boundaries. Use a serializer for the specific parameter format, and confirm that the endpoint expects key/value pairs at all: RFC 3986 defines generic query syntax but does not require every application to interpret a query as key=value&....

Parse first, then decode

Split a URI into its components and relevant subcomponents before decoding percent-encoded octets. If a program decodes first, %26 becomes & and %3D becomes =; data can then be mistaken for query syntax. RFC 3986 explicitly warns that decoding before parsing can cause decoded octets to be mistaken for delimiters. RFC 3986, § 2.4

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Apply encoding once when data crosses into the URL representation, and apply the matching decode after parsing the structure. Encoding already encoded text again can turn percent signs into %25; repeated decoding can make data acquire structural meaning. The exact failure depends on the API stack, so avoid layering unrelated encoders and decoders.

Quick Recap

SaleBestseller No. 1

A practical checklist for fixing a URL-encoding bug

  1. Identify the input: determine whether you have a complete URL, a path segment, a generic query component, or a form-style parameter value.
  2. Confirm the receiver’s contract: establish whether the endpoint parses application/x-www-form-urlencoded data or uses another query format.
  3. Use a matching serializer: supply raw values to a URL or parameter API rather than assembling query text by hand.
  4. Check reserved characters: ensure data such as &, =, ?, or # cannot be interpreted as structure in that context.
  5. Inspect the wire value: check whether a space is represented as %20 or form-style +, and whether a literal plus is %2B.
  6. Trace parsing order: verify that the receiver separates URL components and parameter pairs before decoding their values.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.