About the HTML Entity Encoder / Decoder
In HTML, characters such as <, > and & have special meaning. If you want to show them as text, for example when publishing code snippets in a blog post, they must be written as HTML entities like < and &. The HTML Entity Encoder / Decoder converts them automatically.
Encoding user-supplied content is also a key defense against cross-site scripting (XSS). Enable Encode all non-ASCII characters to convert emojis and international letters into numeric entities for systems that only support ASCII. Decode mode understands named entities (like © and ), decimal and hexadecimal numeric entities.
How to use the HTML Entity Encoder / Decoder
- Choose Encode or Decode.
- Paste your HTML or entity-encoded text.
- Optionally encode all non-ASCII characters.
- Copy the output.
Frequently asked questions
Which characters must be escaped in HTML?
At minimum, & and < in text, plus quotes inside attribute values. This tool also escapes > and apostrophes for safety.
Does decoding run any scripts?
No. Decoding uses a textarea element, which never executes HTML or scripts.
What is ?
A non-breaking space, which prevents a line break between two words and is not collapsed like normal spaces.
