Glossary

URL encoding

Percent-escaping the characters that would otherwise change a URL’s meaning.

URL encoding replaces characters that have structural meaning in a URL, or that cannot appear in one at all, with a percent sign and two hex digits. A space becomes %20, an ampersand %26. Without it, a value containing & would be read as the start of the next query parameter.

The distinction that causes most bugs is between encoding a whole URL and encoding one value inside it. Encoding a full URL must leave the separators ://?&= intact, or it stops being a URL. Encoding a single parameter value must escape those same characters, or the value breaks out of its parameter.

A second trap is double encoding. Encoding an already-encoded string turns %20 into %2520, and the recipient decodes it once to %20 rather than to a space. If you see %25 in a URL that should not contain a literal percent sign, something has been encoded twice.