Skip to content

HTML Entity Encoder

Convert characters to HTML entities so they display as text, and decode entities back.

HTML Entity Encoder

Convert characters to HTML entities and back.

Encoding options

What HTML Entity Encoder does

If you want a page to display <div> as words rather than to interpret it as markup, the angle brackets must be written as entities. The same applies to the ampersand, which otherwise begins an entity of its own.

Encoding here is what you do when you want a character to be seen. It is a display concern, not a security control.

  • Encode the characters that carry meaning in HTML
  • Optionally escape quotes and non-ASCII characters as numeric entities
  • Decode any entity the browser recognises, named or numeric

How to use HTML Entity Encoder

  1. 1

    Paste your text or markup

    Paste the content you want escaped or unescaped.

  2. 2

    Encode or decode

    Encoding escapes markup characters. Decoding turns entities back into the characters they represent.

  3. 3

    Copy the result

    Paste it into your template, documentation or CMS field.

Example

Showing a code sample as text

Input

<a href="/x">Link</a> & more

Output

&lt;a href=&quot;/x&quot;&gt;Link&lt;/a&gt; &amp; more

Limits and known behaviour

  • Escaping here is for display. It is not a substitute for the contextual output encoding a web framework applies, and it does not make untrusted input safe to inject into a page.
  • Escaping requirements differ by context: inside an attribute, inside a script block and inside a URL all have different rules.
  • Decoding uses the browser's own entity table, so it resolves any entity your browser knows.

Privacy and data handling

Runs entirely in your browser

  • Everything you type is processed by JavaScript in this page; no request carries it anywhere.
  • Nothing is stored between visits.

Site-wide data handling, including analytics and advertising, is described in the privacy policy.

Frequently asked questions

Does escaping here protect against cross-site scripting?

No. Escaping a string once, by hand, in a tool, is not a security control. Protection comes from your framework escaping values at render time in the correct context. Treat this tool as a way to display markup, not as a defence.

Do I need to escape every character?

No. In normal text content, &, < and > are the ones that matter; quotes matter inside attribute values.