What it does
HTML entities are codes that stand for characters, such as < for < and é for é. This tool escapes text into entities so it can be shown safely inside a web page, and decodes entities back into plain text, for example when you copy markup out of a CMS or an email template.
Encoding uses the full HTML5 list of more than 2,000 named references, and decoding understands named, decimal (©) and hexadecimal (©) references exactly as a browser does.
How to use
- Paste text or HTML into the Input box, upload a file, or click Sample.
- Choose Encode or Decode.
- When encoding, pick how much to encode:
- Only & < > ” ’: the minimum needed to put text into HTML or an attribute.
- Plus non-ASCII, named: also turns characters like é, © and — into named entities, and anything without a name into a numeric reference.
- Plus non-ASCII, numeric: same, but always numeric (
é), which is also valid XML. - Everything with a name: encodes even punctuation such as
.and/, useful when a system strips those characters.
- Copy or download the result. Use as input lets you decode it again to check the round trip.
Example
<p>Café & "crème brûlée"</p>
encoded with only the special characters becomes
<p>Café & "crème brûlée"</p>
and with non-ASCII named entities becomes
<p>Café & "crème brûlée"</p>
Common uses
Show a code snippet on a blog without the browser rendering it, put user text into an HTML email, fix double-escaped text such as &amp; (decode once), or make a file safe for a system that only accepts ASCII.
FAQ
› Which characters must be escaped in HTML?
In text, escape & and <. Inside attribute values, also escape the quote character that wraps the value. Escaping & < > " and ' everywhere, which is the default here, is always safe.
› Should I use named or numeric entities?
Both work in every modern browser. Named entities such as é are easier to read; numeric references such as é also work in XML and in older parsers that only know a few names. With a UTF-8 page you usually do not need to encode non-ASCII characters at all.
› Does decoding handle entities without a semicolon?
Yes. It follows the HTML specification, so legacy forms like © without a semicolon are decoded the way a browser would. Unknown names such as &foo; are left unchanged.
› Is escaping enough to prevent XSS?
Escaping is the right defense for text placed inside HTML elements and quoted attributes. It does not make untrusted input safe inside script blocks, style blocks, event handler attributes or URLs, which need context-specific encoding.