HTML Entity Encoder & Decoder
Escape text for HTML or decode entities back to text, with named, decimal or hex references and correct handling of emoji and every named entity.
Runs in your browser. Nothing you add is uploaded.
What the HTML Entity Encoder & Decoder does
Some characters mean something to HTML: < starts a tag, & starts an entity and " ends an attribute. To show them as text, or to paste code into a web page, they have to be written as entities such as < and &. This converter encodes just those characters, every non-ASCII character as well, or everything, as named entities (&), decimal codes (&) or hexadecimal codes (&) — emoji included, as a single code each. Decoding understands every named entity in the HTML standard, leaves tags untouched, and tells you when text was encoded twice. It runs in your browser, so you can paste private snippets safely.
How to encode or decode HTML entities
- Choose Encode text for HTML or Decode entities.
- Paste your text or HTML into the input box.
- When encoding, choose which characters to encode — only & < > " ' is enough to show text safely in a page — and whether to write them as named, decimal or hex entities.
- Check the result. If decoding leaves entities like &amp; behind, use Decode again: the text was encoded twice.
- Copy the result into your page, template or email, or use it as the input to go the other way.
The HTML Entity Encoder & Decoder runs entirely in your browser — nothing you enter is uploaded, stored, or logged.
When to use it
Showing code on a web page
To display <div class="card"> in a tutorial, the angle brackets must be encoded or the browser will treat it as a real element and the example will disappear.
Reading escaped text from an API or database
Data that has been escaped more than once turns into strings like &amp;quot;. Decoding shows the real text and reveals where the double escaping happened.
Special characters in email templates
Some email clients handle raw non-ASCII symbols badly. Encoding characters such as ₹, © and — as numeric entities makes them display reliably.
Good to know
- In ordinary page text you only must escape & and <. Inside attribute values, also escape the quote character you used to wrap the value.
- Named entities are easier to read; numeric entities work for every Unicode character, including ones without a name.
- Escaping output is only one part of preventing XSS. Frameworks such as React escape text automatically; the danger is in code that inserts raw HTML.
- Do not encode text twice. If you see &lt; on a page, something escaped already-escaped text.
Frequently asked questions
Why do I need to escape HTML entities?
What is the difference between &, & and &?
Do I need entities for ₹ or emoji if my page is UTF-8?
Is the same as a space?
Related tools
Regex Builder
Build a regular expression from blocks, with live matches.
SQL Formatter
Format, beautify, and minify SQL queries for Postgres, MySQL, and SQLite.
JSON to YAML Converter
Convert bidirectional JSON to YAML and YAML to JSON with presets.
Chmod Permissions Calculator
Interactive 3x3 Linux permissions matrix, octal sync, and command generator.