HTML Entity Encoder and Decoder
Text
Encoded
ExampleAbout
HTML entities are named or numeric codes that represent characters with special meaning in HTML markup. Encoding characters like <, >, and & prevents browsers from interpreting them as tags or syntax, which is essential for displaying user-generated content safely and avoiding cross-site scripting (XSS) vulnerabilities.
How to use
1.
Choose Encode to escape < > & " and ', or Decode to convert entities back to plain text
2.
Type or paste into the input panel - the result updates as you type
3.
Turn on Also encode non-ASCII characters to encode characters like é and € too, then copy the result
Common uses
▸
Safely embedding user-generated content in an HTML page
▸
Encoding characters like <, >, and & for display in a browser
▸
Decoding HTML entities from scraped or copied web content
Similar tools
Frequently asked questions
When do I need to encode HTML entities?
Encode when inserting user-supplied text into HTML to prevent XSS attacks, or when you need to display characters like < > & " in HTML source without them being interpreted as markup.
What is the difference between encoding and escaping?
They mean the same thing in this context - converting characters like < to < so browsers render them as text rather than HTML.
Does it encode Unicode and named entities?
By default only the five characters that matter in markup are encoded: < > & " and '. Turn on "Also encode non-ASCII characters" to encode accented letters, symbols, and emoji too - using widely supported names such as é, ©, and € where they exist, and numeric references such as 😀 otherwise. Decoding understands the full HTML5 named entity set plus decimal and hex references.
Are spaces and common ASCII characters encoded?
No. Letters, digits, spaces, line breaks, and punctuation such as commas and periods are never encoded, so the output stays readable. With the default settings it is valid in XML as well as HTML; the optional non-ASCII encoding uses HTML named entities such as é, which plain XML does not define.
Is my text sent to a server?
Encoding and decoding run entirely in your browser. No data is uploaded or stored.