HTML Encoder and Decoder

Escape &, <, >, " and ' as HTML entities (optionally every non-ASCII character too), or decode named and numeric HTML entities back to plain text.

Last updated
&&amp;
<&lt;
>&gt;
"&quot;
'&#39;
©&copy;
®&reg;
™&trade;
(space)&nbsp;
—&mdash;

About the HTML Encoder/Decoder

The characters <, >, &, " and ' have special meaning in HTML. To show them as text, for example a code sample in a blog post or a user's comment inside a template, they have to be written as entities: < becomes &lt;, & becomes &amp;, and so on. Encode mode does this as you type, so <p class="note">Tom & Jerry</p> turns into &lt;p class=&quot;note&quot;&gt;Tom &amp; Jerry&lt;/p&gt;. Put that in a page and the browser shows the tag as text instead of creating a paragraph.

Tick "Also encode non-ASCII characters" to replace every character outside basic ASCII with an entity as well. A few common ones get names (© becomes &copy;, — becomes &mdash;, € becomes &euro;) and the rest use their Unicode code point, so ₹ becomes &#8377; and an emoji becomes a single numeric entity. This helps when a file must be plain ASCII, such as an email template whose character encoding you cannot control. Pages served as UTF-8, which is most of the web, do not need it.

Decode mode goes the other way using your browser's own HTML parser, so it understands every named entity HTML defines (&hearts;, &rsquo;, &nbsp; and the rest) as well as decimal (&#8377;) and hexadecimal (&#x20B9;) forms. That is useful for reading text copied from page source or from an API that returns escaped HTML. To tidy the markup itself, use the HTML Beautifier; for URL percent-encoding, use the Character Encoding Converter.

How to use the HTML Encoder/Decoder

  1. 1

    Choose Encode or Decode

    Click Encode to turn special characters into entities, or Decode to turn entities back into characters.

  2. 2

    Paste your text

    Type or paste into the Input box. The Output box updates with every change.

  3. 3

    Decide on non-ASCII characters

    In Encode mode, tick "Also encode non-ASCII characters" if accented letters, symbols and emoji should become entities too.

  4. 4

    Copy or swap

    Press Copy above the output. The arrow button moves the output into the input and switches mode, which is a quick way to check the round trip.

What it can do

Escapes the five HTML specials

& < > " and ' become &amp; &lt; &gt; &quot; and &#39;, which is safe in element text and in quoted attribute values.

Optional non-ASCII entities

Characters are encoded by Unicode code point, so an emoji becomes one entity rather than two broken halves.

Decodes every standard entity

Named, decimal and hexadecimal entities are decoded by the browser's HTML parser, which treats the input as text, so no tags are created and no scripts run.

Entity reference table

Ten everyday entities, from &amp; to &mdash;, are listed below the editor for quick lookup.

Limitations

  • Escaping is not a complete defence against cross-site scripting. It protects element text and quoted attributes, but not text placed inside <script> or <style> blocks, unquoted attributes or URLs such as javascript: links.
  • The encoder names only a dozen common characters; every other non-ASCII character becomes a decimal entity, never a hexadecimal one.
  • Spaces and line breaks are left as they are; the encoder does not insert &nbsp; or <br>.
  • Each decode removes one level of escaping. Double-escaped text such as &amp;lt; needs a second pass.

Privacy

Encoding and decoding run in your browser; the text you paste is not sent to FlexyPdf's servers.

Frequently asked questions

Which characters have to be escaped in HTML?

In normal text, < and & must be escaped. Inside an attribute value you also need to escape the quote character that wraps the value. Escaping all five special characters everywhere, as this tool does, is the simplest safe habit.

Why does the apostrophe become &#39; instead of &apos;?

Both mean the same character, but &apos; was not part of HTML 4, so some older software does not recognise it. The numeric form &#39; works everywhere.

Will encoding user input make my site safe from XSS?

It handles the most common case, putting text into HTML content or quoted attributes. It is not enough for JavaScript, CSS or URL contexts. In a real application, use your framework's built-in escaping or a maintained sanitising library rather than copying output from a web page.

Why was ₹ turned into &#8377;?

With "Also encode non-ASCII characters" ticked, characters without a short name are written as their Unicode code point. The rupee sign is U+20B9, which is 8377 in decimal. Untick the option to leave such characters unchanged.

After decoding I still see &lt; in my text. Why?

The text was escaped twice, so &lt; was stored as &amp;lt;. Decoding removes one layer; press the arrow button to move the result back into the input and decode again.

Ratings & Reviews

—
No ratings yet
5
0
4
0
3
0
2
0
1
0

Rate HTML Encoder/Decoder

Help others by sharing your experience. Your rating is shown without your name.

0/600