HTML Entity Encoder and Decoder

Escape text so it shows as-is inside HTML, or turn entities like & and é back into characters. Choose minimal escaping, or also convert accented letters and symbols.

Updated
Runs in your browser. Your data is not uploaded.
Direction
Converts as you type.

How to use the HTML Entity Encoder

  1. Pick the Direction: Encode or Decode.
  2. For encoding, choose what to Encode: only the five special characters, or also every non-ASCII character as named, decimal, or hex entities.
  3. Paste your text into Input and copy the Result. Swap sends the result back through in the other direction.

How it works

  • Minimal encoding replaces the five characters that can break HTML: & → &amp;, < → &lt;, > → &gt;, " → &quot;, ' → &#39;. That is enough for UTF-8 pages.
  • Named uses the HTML 4 names every browser and email client knows, such as &eacute; and &euro;, and a decimal entity for anything else.
  • Decimal and hex write the Unicode code point: é is &#233; or &#xE9;. Emoji use one entity, not two.
  • Decoding uses your browser's own HTML parser in an inactive document, so all 2,231 HTML5 named entities are recognised and nothing is rendered or run.

Examples

  • <a href="x"> encodes to &lt;a href=&quot;x&quot;&gt;.
  • Café & crème with named entities becomes Caf&eacute; &amp; cr&egrave;me.
  • 5 &euro; &copy; &#x1F600; decodes to 5 € © 😀.

Limitations

  • Encoding for HTML text is not the same as escaping for JavaScript strings, URLs, or CSS. Use the URL Encoder for URLs.
  • Unknown names such as &foo; are left as they are, and the tool lists them.
  • On a UTF-8 page you don't need to encode accented letters at all. Named and numeric forms are mainly for emails and old systems.

Frequently asked questions

What are HTML entities?

Codes that stand for characters, written as &name; or &#number;. Browsers show the character, so you can include < or & in text without breaking the markup.

Which characters must be escaped in HTML?

& and < in text, and the quote that surrounds an attribute value. Escaping all five (& < > " ') is the safe habit.

Does escaping protect against XSS?

Escaping text before putting it into HTML is the main defence, but only in HTML text and quoted attributes. JavaScript, URLs, and CSS need their own escaping.

Is my text uploaded?

No. Encoding and decoding happen in your browser.

Often used together with the HTML Entity Encoder / Decoder.