%url-decoder.net

URL Parser

Split any URL into scheme, host, port, path, query and fragment, the same way browsers do. Parameters are decoded, checked and listed in a table.

Runs in your browser. Nothing is uploaded.

Anatomy

https://schemedev:s3cret@userinfoxn--mnchen-3ya.example.dehost:8443port/api/v2/files/report%20Q3.pdfpath?utm_source=newsletter&utm_medium=email&id=42&id=43&redirect=https%3A%2F%2Fevil.example%2F&empty=query#page=2fragment

Components

Scheme
https:
Username
dev
Password
••••••
Host
xn--mnchen-3ya.example.de (münchen.example.de)
Port
8443
Path
/api/v2/files/report%20Q3.pdf
Query
?utm_source=newsletter&utm_medium=email&id=42&id=43&redirect=https%3A%2F%2Fevil.example%2F&empty=
Fragment
#page=2
Origin
https://xn--mnchen-3ya.example.de:8443

Path segments (decoded)

  1. 1 api
  2. 2 v2
  3. 3 files
  4. 4 report Q3.pdf

Checks

  • OKValid absolute URL according to the WHATWG URL Standard.
  • WarnContains credentials in the userinfo part. Browsers hide them and many block such URLs.
  • InfoInternational domain name. Browsers send it as punycode: xn--mnchen-3ya.example.de.
  • Info2 tracking parameters: utm_source, utm_medium.
  • WarnParameter "redirect" holds another URL. Make sure the server validates it, or it can become an open redirect.
  • Info"id" appears 2 times. Servers differ on whether they keep the first, the last or every value.
KeyDecoded valueRawType
utm_sourcenewsletterutm_source=newslettertracking
utm_mediumemailutm_medium=emailtracking
id42id=42repeated
id43id=43repeated
redirecthttps://evil.example/redirect=https%3A%2F%2Fevil.example%2FURL
empty(empty)empty=empty

The parts of a URL

scheme://user:pass@host:port/path?query#fragment. Only the scheme is always required; a web URL also needs a host. The fragment is never sent to the server.

Each part has its own rules for which characters must be percent-encoded, which is why a value that is safe in a path can break a query string. Decode encoded parts with the URL Decoder.

How this parser works

It uses your browser's built-in URL class, which follows the WHATWG URL Standard. Results match what Chrome, Firefox and Safari do with the same address, including converting international domain names to punycode. Nothing is sent to a server.

Questions

What are the parts of a URL?

scheme://user:password@host:port/path?query#fragment. The scheme (such as https) is always required. A web URL also has a host. The port defaults to 443 for https and 80 for http. The query holds key=value parameters, and the fragment after # is never sent to the server.

Why does the host show xn-- characters?

International domain names such as münchen.de are converted to an ASCII form called punycode (xn--mnchen-3ya.de) before they are sent over the network. The parser shows both forms.

Why is a parameter flagged as a possible open redirect?

A parameter whose value is a full URL, such as ?next=https://…, is often used to send the visitor somewhere after login. If the server does not check that destination, attackers can use your domain to redirect people to a phishing site.

Does the parser validate URLs?

Yes. It uses the browser's own URL parser, which follows the WHATWG URL Standard. If the browser cannot parse the address, the tool says why, for example a missing scheme or an invalid port.

Behaviour checked against RFC 3986, the WHATWG URL Standard and MDN. Updated October 3, 2026