HTML Entity Encoder & Decoder

Convert special characters to HTML entities and back. Handles named and numeric entities.

Result

In short

What is the HTML Entity Encoder & Decoder?

The HTML entity encoder and decoder turns characters such as ampersands, angle brackets and quotes into safe entity codes, and converts entities back into plain characters. It is useful when showing code samples on a web page or cleaning up copied text. Escaping output is one basic defence against injected markup.

How to use it

  1. Choose Encode or Decode.
  2. Paste your text or markup.
  3. For encoding, optionally tick the box to convert non-ASCII characters too.
  4. Copy the result.
Questions

HTML Entity Encoder & Decoder — FAQ

Which characters are encoded?

Ampersand, less-than, greater-than, double quote and apostrophe are always encoded. Other characters are encoded only if you tick the non-ASCII option.

Which entities can it decode?

The common named ones such as amp, lt, gt, quot, apos, nbsp, copy and reg, plus any decimal or hexadecimal numeric entity.

Is encoding enough to stop cross-site scripting?

It helps when output is placed in HTML text, but correct protection depends on context. Use your framework escaping and review security needs carefully.

More Developer & Web tools