HTML entities: encode and decode

Paste text to escape the characters HTML treats as special, or paste entities such as & and < to get plain text back. Named and numeric entities are supported.

  • Free
  • No sign-up
  • Runs in your browser
html-encode-decode

100% private — your text is processed in your browser and never sent to any server.

How it works

Paste your text

Plain text to encode, or HTML with entities to decode.

Choose the direction

Encode to entities, or decode entities into characters.

Copy the result

Use it in your HTML, an email template or a CMS field.

Why HTML needs entities

In HTML some characters have a job. The less-than sign opens a tag, the ampersand starts an entity and quotes end an attribute. If you want to show those characters as text, or put text that contains them into a page, you have to write them as entities: &lt; for <, &gt; for >, &amp; for & and &quot; for a double quote. Otherwise the browser interprets the text as markup, which can break the page or, worse, open the door to cross-site scripting when the text comes from a user.

Encoding

Encoding replaces five characters: the ampersand, the two angle brackets, the double quote and the apostrophe. That is the standard set needed to place any text safely inside an element or an attribute value. The optional setting also converts every character above the basic ASCII range, such as accented letters, symbols and emoji, into a numeric entity like &#233;. It is useful for old systems that cannot handle UTF-8, and for email templates that must survive strange encodings.

Decoding

Decoding does the opposite. It turns named entities, such as &amp;, &nbsp; or &eacute;, and numeric entities, such as &#39; or &#x1F600;, into the characters they stand for. It is what you need for text copied from HTML source, an RSS feed, an API response or a database export where everything shows up as &amp;amp; and friends. If text was encoded twice, decode it a second time.

Safe by design

Decoding never turns text into live HTML: the result is only text, and any tags in the input are left as characters, so pasting untrusted content here cannot run anything.

What it does not do

Encoding is not a full defence against injection: when building pages from user input, use the escaping function of your framework and the right context for attributes, scripts and URLs. The tool encodes and decodes the text you paste; it does not sanitise HTML or remove tags. To pull addresses out of a text, use URL encode and decode.

Frequently asked questions

How do I escape HTML characters?
Paste the text, choose "Encode" and copy the result. The characters &, <, >, " and ' are replaced with entities.
How do I turn & and < back into normal characters?
Choose "Decode". Named and numeric entities are converted into the characters they represent.
Why do I see &amp; in my text?
The text was encoded twice. Decode it a second time to get the single ampersand.
What is the difference between   and a normal space?
  is a non-breaking space: the browser will not wrap a line at it. Decoding gives you that special space character.
Does decoding run the HTML I paste?
No. The result is only text. Tags in the input stay as characters and nothing is executed.
Is my text uploaded anywhere?
No. Encoding and decoding happen in your browser.