XML URL Encode / Decode

URL-encode XML or decode it from a URL.

0 chars
0 words
0 lines
0 chars
0 words
0 lines

XML URL Encoder and Decoder Online

Some systems pass whole XML documents through URLs: SAML requests and responses in redirect bindings, legacy HTTP GET APIs with an xml= parameter, callback URLs of payment providers, or deep links carrying a saved search. The XML URL encoder turns XML into a percent-encoded string that is safe to put in a query parameter, and the decoder turns such a value back into readable XML.

Encoding XML for a URL

In Encode mode the XML is checked for well-formedness and, with Minify before encoding on, comments and the whitespace between tags are removed first. That keeps the URL as short as possible — indentation alone can double the length of an encoded document because each space becomes %20 and each line break %0A. The result uses UTF-8 percent-encoding, so accented and non-Latin characters survive the trip.

Decoding XML from a URL

Paste the encoded value in Decode mode. Options control the details:

  • Treat + as space handles form-style encoding, where spaces are sent as +.
  • Format decoded XML pretty-prints the result with indentation. Turn it off to see the decoded text exactly as sent — useful when the payload is not XML after all, or when you need the byte-exact original.

URL length limits

The URL specification has no maximum, but browsers, proxies, and web servers do. Around 2,000 characters is a safe limit and many servers reject URLs longer than 8 KB. For larger documents send the XML in a POST body instead.

Note on SAML

A SAML SAMLRequest in the HTTP-Redirect binding is deflated and Base64-encoded before URL encoding. Decode it here first, then decode the Base64 and inflate — plain URL decoding alone will show Base64 text rather than XML.

Encode JSON the same way with JSON URL Encode/Decode. To embed XML in code rather than URLs, use XML Stringify; for Base64, use XML to Base64.

Frequently Asked Questions

Everything except letters, digits, and - _ . ! ~ * ' ( ) is percent-encoded, exactly like JavaScript's encodeURIComponent. So < becomes %3C, > %3E, " %22, spaces %20, and non-ASCII characters are encoded as UTF-8 bytes (é → %C3%A9).

HTML forms (application/x-www-form-urlencoded) and many server frameworks encode spaces as +. Keep the option on for values copied from form posts or query strings. Turn it off only if the data contains literal plus signs that were not encoded as %2B.

A % sign must be followed by two hexadecimal digits. Truncated URLs, values that were decoded twice, or a lone % in the text cause this error. If formatting is on, the decoded text must also be well-formed XML — turn “Format decoded XML” off to see the raw decoded text.