Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

JavaScript’s encodeURIComponent() leaves a straight apostrophe (', U+0027) unchanged: encodeURIComponent("it's") returns it's, not it%27s. That is the function’s documented behavior, not a bug. If the system receiving your value requires apostrophes to be percent-encoded under a stricter RFC 3986 convention, apply an additional replacement.

Why the apostrophe stays unchanged

encodeURIComponent() encodes a string as one URI component; it is not intended to encode an entire URL. Its unescaped character set includes letters, digits, and - _ . ! ~ * ' ( ), so the straight ASCII apostrophe is deliberately left literal. See MDN’s encodeURIComponent() reference.

The function still encodes characters such as & that could otherwise be interpreted as URI structure inside a component. A literal apostrophe in the result does not mean the component was skipped or that encoding failed.

How to encode the apostrophe as %27

If your target system specifically requires RFC 3986-reserved characters to be percent-encoded, run the built-in function and then replace the relevant characters:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
function encodeRFC3986URIComponent(str) {
  return encodeURIComponent(str).replace(
    /[!'()*]/g,
    (c) => `%${c.charCodeAt(0).toString(16).toUpperCase()}`,
  );
}

encodeRFC3986URIComponent("it's"); // "it%27s"

This replacement encodes the apostrophe as %27 and also encodes !, (, ), and *. MDN documents this approach for stricter RFC 3986 component encoding: MDN’s RFC 3986 example. It is an added convention, not a correction to a defective built-in.

Which encoding should you use?

Approach Apostrophe result When to use it
encodeURIComponent(value) Remains ' Ordinary URI component encoding when the receiving system accepts the built-in function’s documented unescaped set.
RFC 3986 replacement helper Becomes %27 When the target system specifically requires the RFC 3986-reserved characters in the helper’s replacement set to be escaped.

Do not choose the stricter helper simply because %27 looks more encoded. Follow the receiving system’s stated requirements; behavior and expectations can differ between systems.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Two details that can cause confusion

Use the exact, case-sensitive function name

The built-in is encodeURIComponent(), with a capital C in Component. JavaScript names are case-sensitive, so encodeURIcomponent() is not the same spelling.

Distinguish a straight apostrophe from a typographic one

This behavior concerns the straight ASCII apostrophe, U+0027. It does not establish how every typographic quotation mark, such as U+2019 (’), will appear in a particular receiving system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Handle malformed surrogate input separately

encodeURIComponent() throws a URIError if its input contains a lone surrogate. MDN notes that String.prototype.toWellFormed() can replace lone surrogates before encoding; this is a separate issue from apostrophe escaping. See MDN’s lone-surrogate guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.