Paste your text
Plain text to encode, or HTML with entities to decode.
Paste text to escape the characters HTML treats as special, or paste entities such as & and < to get plain text back. Named and numeric entities are supported.
100% private — your text is processed in your browser and never sent to any server.
Plain text to encode, or HTML with entities to decode.
Encode to entities, or decode entities into characters.
Use it in your HTML, an email template or a CMS field.
In HTML some characters have a job. The less-than sign opens a tag, the ampersand starts an entity and quotes end an attribute. If you want to show those characters as text, or put text that contains them into a page, you have to write them as entities: < for <, > for >, & for & and " for a double quote. Otherwise the browser interprets the text as markup, which can break the page or, worse, open the door to cross-site scripting when the text comes from a user.
Encoding replaces five characters: the ampersand, the two angle brackets, the double quote and the apostrophe. That is the standard set needed to place any text safely inside an element or an attribute value. The optional setting also converts every character above the basic ASCII range, such as accented letters, symbols and emoji, into a numeric entity like é. It is useful for old systems that cannot handle UTF-8, and for email templates that must survive strange encodings.
Decoding does the opposite. It turns named entities, such as &, or é, and numeric entities, such as ' or 😀, into the characters they stand for. It is what you need for text copied from HTML source, an RSS feed, an API response or a database export where everything shows up as &amp; and friends. If text was encoded twice, decode it a second time.
Decoding never turns text into live HTML: the result is only text, and any tags in the input are left as characters, so pasting untrusted content here cannot run anything.
Encoding is not a full defence against injection: when building pages from user input, use the escaping function of your framework and the right context for attributes, scripts and URLs. The tool encodes and decodes the text you paste; it does not sanitise HTML or remove tags. To pull addresses out of a text, use URL encode and decode.
More utilities that also run without leaving your browser.