HTML Entity Encode / Decode
Processed Client SideEscape special characters to HTML entities and unescape them back to plain text.
Bookmark this tool now — skip the search next time you need it.
About HTML Entity Encode / Decode
This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.
Convert characters that have special meaning in HTML into their entity equivalents, and convert entities back into plain characters. Escaping matters because a raw < or & in your content can be parsed as markup rather than displayed as text — which at best breaks your layout and at worst is how cross-site scripting works. The tool offers a minimal scope that escapes only the five characters that actually matter for HTML safety, and an extended scope that additionally converts non-ASCII characters to numeric entities for legacy systems and email templates that cannot be trusted with UTF-8.
Key features
- Encode and decode HTML entities in both directions
- Minimal scope escapes the five characters that matter — & < > " and the apostrophe — which is the correct set for safe output
- Extended scope also converts non-ASCII characters to entities for legacy pipelines and email HTML
- Recognises named entities such as and © as well as numeric and hex forms when decoding
- Live conversion as you type
- Syntax-highlighted panes, so escaped markup stays readable rather than turning into a wall of text
- One-click copy of the result
- Runs entirely in your browser with nothing uploaded
How to use it
- Pick Encode to escape text, or Decode to turn entities back into characters.
- Paste your text or HTML into the input pane.
- Choose Minimal for normal web output, or Extended when the target system cannot handle UTF-8.
- Read the converted result in the output pane.
- Click Copy output.
Tips & common mistakes
- Escape the ampersand first when doing this by hand, or you will double-escape everything that follows — this tool handles the ordering for you.
- Minimal is almost always the right scope for a modern site. Modern browsers handle UTF-8 natively, so converting every accented character to an entity just bloats your HTML.
- This is the right tool for showing code samples on a page: escape the snippet so the browser renders the tags as text instead of executing them.
- Escaping output is not a complete XSS defence on its own. Attribute values, URLs, and inline script each need their own escaping rules — HTML entity escaping only covers text content.
- A non-breaking space ( ) looks identical to a normal space but does not wrap or collapse. Decoding a block of pasted content is a fast way to find why a line refuses to break.
- If your page shows & instead of &, the content was escaped twice. Run it through Decode once to fix it.