HTML Entity Encoder / Decoder

Escape special characters to HTML entities (& < > " ') for safe display, or decode entities back to plain text — instantly, in your browser.

Advertisement

What are HTML entities?

Characters like <, > and & have special meaning in HTML. Entities — named codes like &amp;, &lt;, &gt;, &quot; and numeric codes like &#39; — let you display these characters as text instead of markup.

Why encode?

The most common reason is safety: if you insert untrusted text into a page without escaping < and &, a browser may execute it as HTML/JavaScript (cross-site scripting, XSS). Encoding is also how you show code samples on a blog or documentation page.

FAQ

What are HTML entities?
HTML entities are codes that represent reserved characters in HTML, such as &amp; for &, &lt; for < and &gt; for >. They let you display characters that would otherwise be interpreted as markup.
When should I encode HTML entities?
Encode whenever you display user input, code samples, or untrusted text inside a web page. Encoding < and & prevents the browser from treating the text as markup, which blocks most cross-site scripting (XSS) attacks.
What's the difference between the two encode modes?
Special characters only escapes just & < > " ' — all you need for safe HTML display. Escape all non-ASCII additionally converts every character above code point 127 (e.g. é, 中) into numeric entities like &#233; — useful for ASCII-only documents and legacy email systems.
Is my text sent to a server?
No. Encoding and decoding happen entirely in your browser with JavaScript. Nothing you type ever leaves your device.
Advertisement