Developer Toolbox

application/x-www-form-urlencoded

The encoding an HTML form uses unless told otherwise: fields as name=value pairs joined with &, reserved characters percent-encoded and spaces written as +. It is also what OAuth 2.0 token endpoints expect.

Open in cURL Builder A request with this type is filled in.

Header

Content-Type: application/x-www-form-urlencoded

At a glance

Extensions
None: it describes a body, not a file
Kind
Text
Parameters
None
In a browser
Browsers send it from a form with method="post" and no enctype.

With curl

curl https://api.example.com/login \
  -d 'name=Ada+Lovelace' \
  -d 'lang=en'

With fetch

await fetch('https://api.example.com/login', {
  method: 'POST',
  // URLSearchParams sets the Content-Type and encodes the values.
  body: new URLSearchParams({ name: 'Ada Lovelace', lang: 'en' })
});

Common mistakes

  • + means a space

    In a form body + decodes to a space, so a literal plus sign has to be sent as %2B. encodeURIComponent does that (and writes a space as %20, which decodes the same); encodeURI and a body built by hand leave + as it is. URLSearchParams gets it right.

  • No files

    This encoding carries text only. A file input in a form without enctype="multipart/form-data" sends just the file name.

  • JSON APIs ignore it

    An API that reads JSON answers 415 to this type, or sees an empty body and answers 400 or 422 about missing fields. Check what the endpoint accepts.