HTML Entity Encoder and Decoder

  • Free
  • No sign-up
  • Runs in your browser
  • Last updated 2026-10-07
Report a problem

Turn characters like < > & and é into HTML entities, or turn entities back into readable text.

Everything you enter is processed in your browser and is never sent to a server.

How to use

  1. Paste text, HTML or text that contains entities into the box. Use Load example to try it.
  2. To encode, choose how much to encode (only the characters that matter in HTML, or every non-ASCII character by name or by number) and press Encode. To decode, press Decode.
  3. Copy the result, or press Use result as input to run another step on it.

Examples

<a href="x">&</a>
→ &lt;a href=&quot;x&quot;&gt;&amp;&lt;/a&gt;
Encode with the minimal setting. The apostrophe becomes &#x27;.
café © <b>
→ caf&eacute; &copy; &lt;b&gt;
Encode with names for non-ASCII characters. With numbers it is caf&#xE9; &#xA9; &#x3C;b&#x3E;.
&lt;p&gt;caf&eacute; &#169; &#x1F600;
→ <p>café © 😀
Decode. Named, decimal and hexadecimal references all work.

How it works

Encoding and decoding use the open-source he library, which follows the character reference rules in the HTML Standard. It knows the full list of named references and decodes decimal references like &#169; and hexadecimal ones like &#xA9;.

With the minimal setting, only the characters that have a special meaning in HTML are replaced, so ordinary text such as accented letters is left as it is. With the named and numeric settings, every character outside basic ASCII is also replaced, which is useful when the text has to pass through a system that only handles ASCII.

Characters outside the basic range, such as emoji, are written as one reference for the whole character, for example &#x1F600;.

Sources

Frequently asked questions

Which characters must be escaped in HTML?
In text, & and < are the essential ones, and > by habit. Inside an attribute value in quotes, the quote character must be escaped as well. The minimal setting escapes & < > " ' and the backtick, which is safe for both places.
What is the difference between named and numeric entities?
A named entity such as &eacute; or &copy; is easier to read. A numeric one such as &#xE9; or &#233; works for every character, including those without a name. Browsers treat them the same.
Does decoding twice change the text?
Decoding is done once. &amp;amp; becomes &amp;, and decoding that result again gives &. Apply it as many times as the text was encoded.
Is escaping enough to prevent cross-site scripting?
Escaping is one part of it, and the right escaping depends on where the text goes: HTML text, an attribute, JavaScript or a URL each have their own rules. Use the escaping built into your template engine or framework rather than relying on a manual step.
Is my text uploaded?
No. Encoding and decoding run in your browser.

Last updated: