HTML Entity Encode/Decode
Escape text to HTML entities or decode named and numeric entities back to plain text. Runs entirely in your browser; nothing you type is ever sent anywhere.
Quick Learn
HTML entity encoding replaces characters that have special meaning in HTML markup — &, <, >, ", ' — with a named or numeric escape sequence, so they render as literal text instead of being parsed as a tag, attribute boundary, or the start of another entity. & renders as &, < renders as <, and so on. Without this, user-submitted text containing < or & could break page layout or, worse, be interpreted as actual markup.
Entities come in two forms: named (&, ©, …) and numeric (& or & for the same &). Named entities are easier to read in source; numeric entities work for any Unicode character, even ones without a memorable name, using either decimal (&#NNNN;) or hexadecimal (&#xHHHH;) code points. This tool's decoder accepts both forms interchangeably, since real-world HTML mixes them freely — copy-pasted content, CMS exports, and RSS feeds often use whichever form the original tool happened to emit.
Best Practices
- •Encoding user input before rendering it as HTML is a basic XSS defense — but it's not a substitute for a proper templating engine or sanitizer that handles attribute contexts, URLs, and JavaScript contexts differently.
- •Only the five characters & < > " ' are strictly required for safe HTML embedding — encoding everything else (accented letters, emoji) as numeric entities is unnecessary today, since UTF-8 is universally supported.
- •Encode & first, before any other character — encoding < to < and then encoding the & in that output would double-encode it into &lt;, corrupting the entity.
- •When decoding content from an unknown source, treat the output as untrusted text, not as safe-to-render HTML — decoding entities does not itself make the content safe.
More Encoding Tools
Base64 Encode/Decode
Convert text to and from Base64, with correct UTF-8 handling.
URL Encode/Decode
Percent-encode or decode a query string, path segment, or full URL.
Hex ↔ Text Converter
Convert text to hexadecimal bytes and back, for byte-level debugging.
Unicode Escape/Unescape
Convert text to \uXXXX escapes and back, including emoji and surrogate pairs.
Gzip Compress/Decompress
Compress text with gzip or deflate, or decompress a Base64-encoded blob.
Frequently Asked Questions
Want the engineering deep-dives behind tools like this one?