HTML Entity Encoder & Decoder
Escape text so a browser renders it instead of running it β and read entities back into the characters they stand for.
Runs entirely in your browser
Loading tool...
How to use
- Paste the text or the markup you need converted.
- Choose encode to make text safe to place in a page, or decode to read entities back.
- Pick how much to escape: markup characters alone, or everything outside ASCII.
- Copy the result β the round trip returns exactly what you started with.
Features
- Named entities where they read well, numeric where they do not.
- Emoji and other astral characters written as one reference, not two broken halves.
- Decodes named, decimal and hexadecimal references, including the accented names older pages use.
- Leaves an unrecognised entity untouched rather than deleting it.
- Runs entirely in your browser.
Frequently asked questions
- Which characters actually have to be escaped?
- Five: & < > " and '. Those are the ones that change how a browser parses the document; everything else is presentation. Escaping only those keeps the source readable β accents, Vietnamese and emoji stay as themselves β which is what you want in any page served as UTF-8, and that is nearly all of them.
- Why does my emoji come out as two strange numbers elsewhere?
- Because it is one character stored as two halves, and a tool that walks the string by index emits a reference for each half. Neither half is a character, so the browser renders nothing. This tool walks by code point, so π becomes 😀 β one reference the browser understands.
- Does this protect against XSS?
- Escaping is the mechanism, but where you put the result decides whether it is safe. Escaped text is safe as page content and as an attribute value in quotes; it is not safe inside a script block, a URL, or a style attribute, which have their own rules. Treat this as a text conversion tool, not a security control.
- What happens to something like AT&T?
- Encoding turns it into AT&T. Decoding leaves it alone, because &T; is not an entity β and a decoder that guessed would corrupt the text it was asked to read. The same applies to ¬real;, which comes back untouched.
Related tools
Percent-encode text for a URL, or decode a URL back into readable text.
Convert text to Base64 and back again.
Test a regular expression against your text: every match, its position and its groups.