application/x-www-form-urlencoded
The encoding an HTML form uses unless told otherwise: fields as name=value pairs joined with &, reserved characters percent-encoded and spaces written as +. It is also what OAuth 2.0 token endpoints expect.
Open in cURL Builder A request with this type is filled in.
Header
Content-Type: application/x-www-form-urlencodedAt a glance
- Extensions
- None: it describes a body, not a file
- Kind
- Text
- Parameters
- None
- In a browser
- Browsers send it from a form with
method="post"and noenctype.
With curl
curl https://api.example.com/login \ -d 'name=Ada+Lovelace' \ -d 'lang=en'
With fetch
await fetch('https://api.example.com/login', {
method: 'POST',
// URLSearchParams sets the Content-Type and encodes the values.
body: new URLSearchParams({ name: 'Ada Lovelace', lang: 'en' })
});Common mistakes
+means a spaceIn a form body
+decodes to a space, so a literal plus sign has to be sent as%2B.encodeURIComponentdoes that (and writes a space as%20, which decodes the same);encodeURIand a body built by hand leave+as it is.URLSearchParamsgets it right.No files
This encoding carries text only. A file input in a form without
enctype="multipart/form-data"sends just the file name.JSON APIs ignore it
An API that reads JSON answers
415to this type, or sees an empty body and answers400or422about missing fields. Check what the endpoint accepts.