Skip to main content

URL Parser

Paste a URL and see its scheme, host, port, path, query parameters and fragment separated out, with every parameter listed as a decoded key and value.

Break a URL into the parts a browser sees: scheme, credentials, host, port, path, query string and fragment, plus a decoded table of every query parameter. Useful when a URL is long enough that reading it by eye stops being reliable.

URL Parser

// URL Parser: Features

What gets separated out

The tool reports the protocol, any username and password embedded in the authority, the hostname, the port, the path, the raw query string, the fragment and the origin. Below that, every query parameter appears as its own row with the key and the decoded value, so a tracking URL carrying a dozen parameters becomes a list you can actually read. Parsing uses the browser's own URL implementation, so what you see is what your browser sees.

When a URL stops being readable

Marketing links accumulate UTM parameters, click identifiers and session tokens until they run to several hundred characters. OAuth redirects carry a state value, a nonce, a code challenge and a return path, all percent-encoded. A failing API call has its parameters in an order that makes the one you care about hard to find. In each case the question is usually simple, such as which value a particular key actually has, and the answer is faster to read from a table than to pick out of a single long line.

Origin, host and hostname are not the same thing

These three are routinely confused and the distinction matters for CORS and for cookies. The hostname is the domain alone, for example example.com. The host includes the port when one is present, so example.com:8443. The origin is the scheme, host and port together, https://example.com:8443, and it is the origin that a browser compares when deciding whether a cross-origin request is allowed. A mismatch in any of the three parts makes two URLs different origins, which is why an https page cannot quietly call an http endpoint on the same domain.

The fragment never reaches the server

Everything after the hash is handled entirely by the browser and is not included in the HTTP request. That is why a single-page application can change the fragment without a page load, and why putting a token in the fragment keeps it out of server logs, which some OAuth flows rely on deliberately. If a value you expect to arrive server-side is missing, check whether it ended up after a hash rather than in the query string.

Signed URLs and tokens stay on your machine

Parsing runs in your browser and the URL never leaves the page. Signed URLs, internal endpoints, redirect targets carrying tokens and links from a bug report can all be pasted here safely. To convert individual values between their encoded and readable forms, the URL Encoder handles percent encoding in both directions.

// URL Parser: FAQ

What does the parser show me?

The scheme, any embedded username and password, hostname, port, path, raw query string, fragment and origin, followed by a table of every query parameter with its decoded value. It uses the browser's built-in URL parser, so the breakdown matches how your browser would interpret the same address.

Why does my URL show as invalid?

Most often because the scheme is missing. A bare string such as example.com/path is not a URL as far as the parser is concerned; prefix it with https:// and it will parse. Other causes are a space that was not encoded, an unbalanced bracket in an IPv6 literal, or a truncated string copied from a line-wrapped log.

What is the difference between host, hostname and origin?

The hostname is the domain on its own. The host adds the port if one is specified. The origin is the scheme plus the host, and it is what browsers use for same-origin decisions, CORS checks and cookie scoping. Two URLs that differ in scheme, hostname or port are different origins even if they look nearly identical.

Are the query parameter values decoded?

Yes. The raw query string is shown as it appears in the URL, and the parameter table shows each value after percent decoding, so a value containing spaces or non-Latin characters is readable. If you need to see or produce the encoded form of a single value, use the URL Encoder.

What happens with repeated parameter keys?

Each occurrence is listed as its own row, in the order it appears. URLs are allowed to repeat a key, and frameworks disagree about what that means: some take the first value, some the last, and some collect all of them into a list. Seeing the repetitions explicitly is often the first step in explaining why a server read a different value than you expected.

Why is the part after the hash not in my server logs?

Because the browser never sends it. The fragment is a client-side concept, used for in-page anchors and for routing in single-page applications. If a parameter you need server-side is sitting after a hash, it has to move into the query string before the server can see it.

Can it handle URLs with a username and password?

Yes. The form https://user:pass@example.com is parsed and the credentials are shown separately. Be aware that browsers have restricted this form over the years because of its use in phishing, and that credentials in a URL are easily leaked through logs, history and referrer headers, so it is not a pattern to adopt deliberately.

Does it work with non-http schemes?

Schemes such as mailto:, tel:, ftp: and custom application schemes will parse, but the breakdown is less meaningful because those schemes do not use the same authority and path structure. The tool is designed around http and https URLs, which is where the component breakdown is genuinely useful.

Is it safe to paste a signed or tokenised URL?

Yes. Everything is parsed in your browser and the URL is never transmitted, stored or logged. As with any tool, treat a URL you have displayed on a shared screen or in a recording as exposed, and rotate the credential if it was a live one.

Is the URL I parse sent to a server?

No. The parsing runs entirely as JavaScript in the page, and closing the tab discards whatever you pasted.

// How to Use URL Parser

  1. Paste the URL

    Put the full URL, including its scheme, into the input box. Long tracking links, OAuth redirect targets and API endpoints with many parameters are all fine, and parsing happens as you type.

  2. Read the component breakdown

    The components panel separates scheme, host, port, path, query and fragment. Use it to confirm the origin when you are debugging a CORS failure, or to check that a path is what you expected.

  3. Scan the parameter table

    Every query parameter is listed with its decoded value, in the order it appears in the URL. Repeated keys appear as separate rows, which makes it obvious when a parameter has been set more than once.

Category Encoding