Skip to content
Toolbench

HTML Entity Encoder & Decoder

Escape text so a browser renders it instead of running it β€” and read entities back into the characters they stand for.

Runs entirely in your browser

Loading tool...

How to use

  1. Paste the text or the markup you need converted.
  2. Choose encode to make text safe to place in a page, or decode to read entities back.
  3. Pick how much to escape: markup characters alone, or everything outside ASCII.
  4. Copy the result β€” the round trip returns exactly what you started with.

Features

  • Named entities where they read well, numeric where they do not.
  • Emoji and other astral characters written as one reference, not two broken halves.
  • Decodes named, decimal and hexadecimal references, including the accented names older pages use.
  • Leaves an unrecognised entity untouched rather than deleting it.
  • Runs entirely in your browser.

Frequently asked questions

Which characters actually have to be escaped?
Five: & < > " and '. Those are the ones that change how a browser parses the document; everything else is presentation. Escaping only those keeps the source readable β€” accents, Vietnamese and emoji stay as themselves β€” which is what you want in any page served as UTF-8, and that is nearly all of them.
Why does my emoji come out as two strange numbers elsewhere?
Because it is one character stored as two halves, and a tool that walks the string by index emits a reference for each half. Neither half is a character, so the browser renders nothing. This tool walks by code point, so πŸ˜€ becomes &#128512; β€” one reference the browser understands.
Does this protect against XSS?
Escaping is the mechanism, but where you put the result decides whether it is safe. Escaped text is safe as page content and as an attribute value in quotes; it is not safe inside a script block, a URL, or a style attribute, which have their own rules. Treat this as a text conversion tool, not a security control.
What happens to something like AT&T?
Encoding turns it into AT&amp;T. Decoding leaves it alone, because &T; is not an entity β€” and a decoder that guessed would corrupt the text it was asked to read. The same applies to &notreal;, which comes back untouched.

Percent-encode text for a URL, or decode a URL back into readable text.

Convert text to Base64 and back again.

Test a regular expression against your text: every match, its position and its groups.

HTML Entity Encoder & Decoder β€” Escape and Unescape