HTML Entity Encode / Decode
Escape text for HTML, or turn entity codes back into readable characters.
How to use the HTML Entity Encode / Decode
- Paste plain text to escape it, or HTML that contains entity codes to decode it.
- The direction is picked automatically; you can force encode or decode.
- For encoding, choose which characters to convert and the entity style.
- Copy the result or save it as a file.
Examples
About this tool
In HTML, a few characters have a special job: < and > start and end tags, & starts an entity, and quotes wrap attribute values. To show those characters on a page, for example in a code sample or a product name with an ampersand, they must be written as entities like < and &. Forgetting to do so breaks layouts and, with user-supplied text, can open a security hole.
This tool does the conversion both ways. Encoding escapes the five special characters and, if you like, every character outside plain ASCII, using names such as é where one exists. Decoding understands named, decimal and hexadecimal references and follows the same rules as browsers, including their handling of old Windows codes.
If you are pasting into an email template or a system that mangles accented letters, choose "every non-ASCII character" with decimal style. Numeric references work everywhere, even in old software that does not know the newer entity names.
Frequently asked questions
Do I need to encode accented letters like é?
Not if your page is saved and served as UTF-8, which nearly all modern pages are. Encoding only the five special characters is enough. Encode everything only for systems that cannot handle UTF-8.
Why did & not become &amp;?
Because "Leave existing entities alone" is on. It stops text that is already escaped from being escaped twice, which is the cause of the stray &amp; often seen on web pages.
Is this enough to protect against cross-site scripting?
Escaping the five special characters makes text safe to place between tags and inside quoted attributes. It is not enough inside script blocks, style blocks or unquoted attributes, which need different escaping.
Is the HTML I paste sent anywhere?
No. Encoding and decoding run in this browser tab, so templates, snippets and private content stay on your computer.