HTML Entity Encoder / Decoder
Escape text to safe HTML entities, or decode entities back to text.
About this tool
Convert characters that have special meaning in HTML — <, >, &, quotes — into their entity form so text can sit inside an HTML page as literal text, or decode entities back to plain characters. It runs entirely in your browser.
How an entity is written. An ampersand, a name or number, and a semicolon: < for <, & for &, © for the © symbol. Numeric entities reference a Unicode code point in decimal (—) or hex (—), both giving an em dash (—). Numeric entities always work; named ones depend on the name being in the HTML spec's list.
Why it matters. In HTML, < opens a tag and & opens an entity. If you drop arbitrary text — a code sample, a user comment, a product name with a < in it — straight into a page, the browser tries to parse those characters as markup. At best the layout breaks; at worst, text like <script>…</script> executes. Escaping the five characters & < > " ' in any untrusted text before it goes into the page is the baseline defence against HTML injection (XSS).
Encode context matters. The five-character escape is right for text that lands in element content or a double-quoted attribute. Text going into a URL, a <script> block, inline CSS, or an unquoted attribute needs different escaping — HTML entities alone aren't enough there. When in doubt, put attribute values in double quotes and escape the five.
Decoding is safe. Decode mode only turns entity text back into characters for you to read — it doesn't render or run anything. Pasting untrusted HTML in to decode it carries no risk here.
Displaying code on a page. To show HTML source as text (in a tutorial, a docs page, a blog post), every < and & in the sample has to be escaped, usually inside a <pre><code> block. This tool's Encode mode does exactly that transformation.
HTML entities are not percent-encoding and not Base64 — the guide to the three encodings shows how to tell them apart and when each is used. For escaping a value inside a URL, use the URL encoder; to tidy the surrounding markup, the HTML formatter.
Frequently asked questions
- Why would I encode text for HTML?
- So arbitrary or user-supplied text displays as literal text instead of being parsed as tags or attributes — which prevents broken layout and script injection.
- Which entities are handled?
- Encoding escapes the core five:
& < > " '. Decoding also resolves common named entities like and©and any numeric entity ('or'). - Is decoding untrusted HTML safe here?
- Yes. Decode only converts entity text to characters for display; nothing is rendered or executed.
- Does escaping the five characters fully protect against XSS?
- For text in element content or a quoted attribute, largely yes. Text going into a script block, a URL, a style, or an unquoted attribute needs context-specific escaping in addition.
- What's the difference between
'and'? - Both mean an apostrophe.
'is numeric and works everywhere;'is defined in HTML5 but not in older HTML, so the numeric form is safer. - Why did a space turn into
somewhere? is a non-breaking space — a different character from a regular space. Some editors insert it; decode mode turns it back into a visible space here.