Skip to content
TabBench

HTML Entity Encoder & Decoder

Escape text for HTML or decode entities back to text, with named, decimal or hex references and correct handling of emoji and every named entity.

Runs in your browser. Nothing you add is uploaded.

What the HTML Entity Encoder & Decoder does

Some characters mean something to HTML: < starts a tag, & starts an entity and " ends an attribute. To show them as text, or to paste code into a web page, they have to be written as entities such as &lt; and &amp;. This converter encodes just those characters, every non-ASCII character as well, or everything, as named entities (&amp;), decimal codes (&#38;) or hexadecimal codes (&#x26;) — emoji included, as a single code each. Decoding understands every named entity in the HTML standard, leaves tags untouched, and tells you when text was encoded twice. It runs in your browser, so you can paste private snippets safely.

How to encode or decode HTML entities

  1. Choose Encode text for HTML or Decode entities.
  2. Paste your text or HTML into the input box.
  3. When encoding, choose which characters to encode — only & < > " ' is enough to show text safely in a page — and whether to write them as named, decimal or hex entities.
  4. Check the result. If decoding leaves entities like &amp;amp; behind, use Decode again: the text was encoded twice.
  5. Copy the result into your page, template or email, or use it as the input to go the other way.

The HTML Entity Encoder & Decoder runs entirely in your browser — nothing you enter is uploaded, stored, or logged.

When to use it

Showing code on a web page

To display <div class="card"> in a tutorial, the angle brackets must be encoded or the browser will treat it as a real element and the example will disappear.

Reading escaped text from an API or database

Data that has been escaped more than once turns into strings like &amp;amp;quot;. Decoding shows the real text and reveals where the double escaping happened.

Special characters in email templates

Some email clients handle raw non-ASCII symbols badly. Encoding characters such as ₹, © and — as numeric entities makes them display reliably.

Good to know

  • In ordinary page text you only must escape & and <. Inside attribute values, also escape the quote character you used to wrap the value.
  • Named entities are easier to read; numeric entities work for every Unicode character, including ones without a name.
  • Escaping output is only one part of preventing XSS. Frameworks such as React escape text automatically; the danger is in code that inserts raw HTML.
  • Do not encode text twice. If you see &amp;lt; on a page, something escaped already-escaped text.

Frequently asked questions

Why do I need to escape HTML entities?

Escaping characters like <, >, and & prevents browser rendering confusion and protects against Cross-Site Scripting (XSS) vulnerabilities.

What is the difference between &amp;, &#38; and &#x26;?

They all produce the same & character. The first is a named entity, the second the character's decimal code point and the third its hexadecimal code point. Browsers treat them identically.

Do I need entities for ₹ or emoji if my page is UTF-8?

Not in a correctly served UTF-8 page, which almost every modern site is; you can type the characters directly. Entities are still useful in systems that mangle non-ASCII text, such as some email and legacy tools.

Is &nbsp; the same as a space?

No. &nbsp; is a non-breaking space: it looks like a space but stops the line from wrapping at that point, which is useful between a number and its unit, such as 10&nbsp;kg.