HTML Entity Encoder / Decoder
Escape <, >, & and quotes as HTML entities, or decode named and numeric entities (&, ©, 😀) back to text.
How to use
- 1Choose Encode or Decode.
- 2Paste your text or HTML and copy the result.
Frequently asked questions
Which characters must be escaped in HTML?
& and < always; > for safety; and " or ' inside attribute values. Everything else can be written as-is in UTF-8 pages.
What does 'Encode all non-ASCII' do?
Also turns characters like é or emoji into numeric entities (é), useful for systems that aren't UTF-8 safe.
Does escaping prevent XSS?
Escaping text inserted into HTML is one key defense, but attributes, URLs and scripts need context-specific handling too.