/

HTML Entity Encode / Decode

Processed Client Side

Escape special characters to HTML entities and unescape them back to plain text.

Input · 5 lines
5 lines · 162 chars
Length: 162Lines: 5Size: 172 BytesCursor: 1:1
Output
Encoded
Length: 252Lines: 5Size: 262 BytesCursor: 1:1

Bookmark this tool now — skip the search next time you need it.

About HTML Entity Encode / Decode

This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.

Convert characters that have special meaning in HTML into their entity equivalents, and convert entities back into plain characters. Escaping matters because a raw < or & in your content can be parsed as markup rather than displayed as text — which at best breaks your layout and at worst is how cross-site scripting works. The tool offers a minimal scope that escapes only the five characters that actually matter for HTML safety, and an extended scope that additionally converts non-ASCII characters to numeric entities for legacy systems and email templates that cannot be trusted with UTF-8.

Key features

  • Encode and decode HTML entities in both directions
  • Minimal scope escapes the five characters that matter — & < > " and the apostrophe — which is the correct set for safe output
  • Extended scope also converts non-ASCII characters to entities for legacy pipelines and email HTML
  • Recognises named entities such as &nbsp; and &copy; as well as numeric and hex forms when decoding
  • Live conversion as you type
  • Syntax-highlighted panes, so escaped markup stays readable rather than turning into a wall of text
  • One-click copy of the result
  • Runs entirely in your browser with nothing uploaded

How to use it

  1. Pick Encode to escape text, or Decode to turn entities back into characters.
  2. Paste your text or HTML into the input pane.
  3. Choose Minimal for normal web output, or Extended when the target system cannot handle UTF-8.
  4. Read the converted result in the output pane.
  5. Click Copy output.

Tips & common mistakes

  • Escape the ampersand first when doing this by hand, or you will double-escape everything that follows — this tool handles the ordering for you.
  • Minimal is almost always the right scope for a modern site. Modern browsers handle UTF-8 natively, so converting every accented character to an entity just bloats your HTML.
  • This is the right tool for showing code samples on a page: escape the snippet so the browser renders the tags as text instead of executing them.
  • Escaping output is not a complete XSS defence on its own. Attribute values, URLs, and inline script each need their own escaping rules — HTML entity escaping only covers text content.
  • A non-breaking space (&nbsp;) looks identical to a normal space but does not wrap or collapse. Decoding a block of pasted content is a fast way to find why a line refuses to break.
  • If your page shows &amp; instead of &, the content was escaped twice. Run it through Decode once to fix it.

Related tools

Browse all 4 Encoding tools

Frequently asked questions

10

Paste your text into the input and all special characters are replaced by HTML entities (like &amp;amp;, &amp;lt;, &amp;gt;) in the output instantly.

Always encode user-supplied text before inserting it into HTML. This prevents XSS (cross-site scripting) attacks by ensuring characters like < and > are not interpreted as HTML tags.

Minimal mode encodes only the five characters critical for HTML safety: & < > " '. Extended mode also encodes typographic characters like em dashes, curly quotes, and accented letters.

Both represent the same character — &amp;amp; (named) and &amp;#38; (numeric decimal) both mean an ampersand. Named entities are more readable; both are equally valid in HTML.

No — HTML encoding only makes text safe for HTML output. SQL injection prevention requires parameterised queries or prepared statements at the database layer.

Five: the ampersand, less-than, greater-than, double quote, and apostrophe. Minimal mode escapes exactly those, which is the correct set for safe HTML output on a modern UTF-8 page.

The content was escaped twice — the ampersand of an existing entity was escaped again. Run the text through Decode once to fix it.

Not on its own. HTML entity escaping covers text content, but attribute values, URLs, and inline script each need their own escaping rules. Use it as one layer alongside a content security policy and framework-level output escaping.

Escape the snippet with this tool before putting it in your HTML. That makes the browser render the tags as visible text instead of parsing them as markup.

It is a non-breaking space, written as &nbsp;, which looks identical to a normal space but behaves differently. Decoding a block of pasted content is a quick way to find them.