Search tools

Search for a command to run...

HTML Entity Encoder / Decoder

Escape <, >, & and quotes as HTML entities, or decode named and numeric entities (&amp;, &#169;, &#x1F600;) back to text.

How to use

  1. 1Choose Encode or Decode.
  2. 2Paste your text or HTML and copy the result.

Frequently asked questions

Which characters must be escaped in HTML?

& and < always; > for safety; and " or ' inside attribute values. Everything else can be written as-is in UTF-8 pages.

What does 'Encode all non-ASCII' do?

Also turns characters like é or emoji into numeric entities (&#233;), useful for systems that aren't UTF-8 safe.

Does escaping prevent XSS?

Escaping text inserted into HTML is one key defense, but attributes, URLs and scripts need context-specific handling too.