encoding guide
Diagnose Double URL Encoding One Known Layer at a Time
Trace percent signs through two encoding passes, reverse known layers, and account for plus signs and malformed percent sequences.
Published October 9, 2026 by SOLVEOZA Editorial
Quick answer
Encoding A/B as a component gives A%2FB. Encoding that result again gives A%252FB because the percent sign is encoded too. One decode returns A%2FB; a second known decode returns A/B.
Locate the component that was encoded
Work on an individual query value or path component, not a complete live URL with credentials or tokens. SOLVEOZA encodes a component using encodeURIComponent; reserved separators in a full URL will therefore also be encoded.
A percent sign followed by 25 can be a clue to an extra layer, but it is not proof. The original text might intentionally contain a literal percent sequence. Establish where encoding occurred in the data flow before deciding how many decoding operations to apply.
Trace an original toy value
Copy each output into a new row so the transformation history stays visible. This is a controlled example with exactly two encoding passes.
| Stage | Text |
|---|---|
| Original | A/B |
| Encode once | A%2FB |
| Encode twice | A%252FB |
| Decode once from twice-encoded value | A%2FB |
| Decode second known layer | A/B |
Stop when the intended representation is recovered
Paste A%252FB into URL Encoder / Decoder and select Decode. The first result is A%2FB. Decode that result once more only because the fixture's history establishes two layers. If the original intended text were literally A%2FB, the first result would already be correct.
Repeatedly decoding until no percent signs remain is not a safe general repair rule. It can change intended literal text or introduce separator characters. Keep a copy of the original and compare the result with the receiving system's expected representation.
Account for the tool's plus-sign convention
This tool replaces literal plus signs with spaces before percent-decoding. Thus A+B decodes to A B, whereas A%2BB decodes to A+B. This is useful for form-style values, but it differs from calling decodeURIComponent alone on a literal plus sign.
That difference also matters across passes. Decoding A%2BB once correctly produces A+B; blindly decoding again would produce A B. A plus sign in a path is not automatically a form-space marker. Choose a decoder with the appropriate context when literal plus preservation is required.
Treat malformed input as an error, not a repair request
A lone percent sign or incomplete percent triplet fails decoding in this tool. It reports an error instead of guessing the missing characters. Return to the original source or inspect where the text was truncated; adding arbitrary hex digits creates different data.
For a debugging record, retain a harmless example, the component boundary, each encoding step and the expected destination. Use synthetic strings like this one rather than pasting private URLs. This page explains representation, not a way to bypass URL validation or access controls.
Methodology
- Run two encoding and two decoding passes on A/B.
- Independently check literal plus, encoded plus and invalid percent input.
Limitations
- Do not repeatedly decode an unknown string without establishing its intended form.
- The decoder is not a context-aware parser for complete URLs.
- Literal plus signs are treated as spaces by this decoder.
Sources
Original toy strings were checked against SOLVEOZA's implementation; plus replacement is a tool-specific behavior.
- Component encoding (accessed 2026-10-09)
FAQ
Does %25 always mean accidental double encoding?
No. A literal percent sign in the original input also encodes as %25.
Why did my plus sign become a space?
The SOLVEOZA decoder applies a form-style plus-to-space replacement before percent-decoding.
Can the tool decode an incomplete percent escape?
No. It reports invalid percent-encoded input instead of guessing.
Should I encode a whole URL as one component?
Only if that whole URL is itself the value of another component. Otherwise handle its component boundaries explicitly.