HTML Encoder / Decoder
Escape text into HTML entities or decode named and numeric entities back to plain text — with the browser's own parser doing the decoding.
Common HTML entities
| Character | Named entity | Numeric | Notes |
|---|---|---|---|
| & | & | & | Must always be escaped in HTML text |
| < | < | < | Starts a tag if left raw |
| > | > | > | Escape for symmetry and safety |
| " | " | " | Required inside double-quoted attributes |
| ' | ' | ' | ' is safer — ' predates HTML5 support in old parsers |
| (non-breaking space) | |   | Keeps words on the same line |
| © | © | © | Copyright sign |
| — | — | — | Em dash |
| € | € | € | Euro sign |
| → | → | → | Right arrow |
The five at the top (&, <, >, ", ') are the security-relevant set: escaping them in untrusted text is the core defense against HTML injection. The rest exist mainly for convenience — in UTF-8 documents you can usually type the character directly instead.
How to use this tool
- Choose Encode to escape text for safe inclusion in HTML, or Decode to turn entities back into characters.
- Paste your text — the result updates live.
How it works
Encoding escapes the five HTML-significant characters — & < > " ' — into their entities, which prevents user text from being interpreted as markup. Decoding uses the browser's own HTML parser, so it handles every named entity (©, —, …) and numeric form (©, —) that browsers do.
Entity-escaping is output encoding for HTML contexts specifically — URLs need percent-encoding and JavaScript strings need JSON escaping instead.
Frequently asked questions
Which characters must be escaped in HTML?
At minimum & < and > in content, plus " and ' inside attribute values. This tool escapes all five.
Why does decoded text look different from the rendered page?
Whitespace — HTML collapses runs of spaces and newlines when rendering. The decoded text preserves them exactly.
Is this enough to prevent XSS?
Entity-encoding untrusted text before inserting it into HTML content is the core defense for that context — but attributes, URLs, CSS, and script contexts each need their own encoding. Use a templating engine or sanitizer for anything complex.