Skip to content
TabBench

URL Parser

Paste any URL to see its scheme, host, port, path, query parameters and fragment, with problems flagged: bad encoding, credentials, secrets in the query string and more.

Runs in your browser. Nothing you add is uploaded.

What the URL Parser does

A URL looks like one string but carries up to eight separate parts: a scheme, optional credentials, a host, a port, a path, a query string and a fragment. Paste any web address here and the parser splits it apart using your browser's own URL engine, so you see exactly what a real request would send. It also warns about the mistakes that cause subtle bugs: unencoded spaces, broken percent-escapes, passwords in the address and API tokens hiding in the query string.

How to parse a URL

  1. Paste a URL, or choose one of the examples, into the box. A missing https:// is added for you.
  2. Read the colour-coded anatomy to see which part is the host, the path, the query and the fragment.
  3. Check the Parts table and the list of decoded query parameters and path segments.
  4. Review “Things to check” for warnings about encoding, credentials or secrets.
  5. To change something, choose “Edit the parts of this URL”, adjust a field and copy the rebuilt URL.

The URL Parser runs entirely in your browser — nothing you enter is uploaded, stored, or logged.

When to use it

Debugging redirects and broken links

Comparing the parts of the URL that should have matched, such as the host, the trailing slash or a stray double slash, is often faster than staring at the whole address.

Inspecting an OAuth redirect

OAuth and single-page apps often return results in the fragment (#access_token=…) or in the query. The parser lists them separately and warns when a token sits in a place that is logged.

Cleaning tracking links

See every parameter a marketing link carries, then use the Query String Parser to strip the tracking ones before sharing.

Good to know

  • Host names are case-insensitive; paths and query strings are case-sensitive.
  • The fragment is never sent to the server, so you cannot read it in server logs.
  • Put secrets in headers or request bodies, not in URLs. URLs are stored in logs, history and Referer headers.
  • Spaces in a URL should be %20 (or + in a query string).
  • An internationalised domain is sent as Punycode (xn--…). Check look-alike characters in links you receive.

Frequently asked questions

Is the fragment (#) sent to the server?

No. The part after # stays in the browser. That is why single-page apps and OAuth responses can use it without the server ever seeing it.

What is the difference between a URL and a URI?

A URI identifies a resource; a URL is a URI that also says how to reach it, such as https://example.com/page. In everyday use the terms are interchangeable, and the web standard now calls everything a URL.

Why does the parser change my URL?

It normalises it the way browsers do: host names are lower-cased, default ports are dropped and spaces or non-ASCII characters are percent-encoded. The normalised URL is what actually gets requested.

What is the origin of a URL?

The scheme, host and port together, such as https://example.com:8443. Browsers use the origin for security rules, including CORS, cookies and the same-origin policy.

Is a trailing slash significant?

To a server it can be: /docs and /docs/ are different paths and may return different things or redirect. Pick one form and stay consistent, for SEO as well as for caching.

Why is the port missing from my URL?

Default ports (80 for http, 443 for https) are dropped when a URL is normalised because they are implied by the scheme. A non-default port such as :8443 is always kept.