HTML Entity Encode & Decode

Escape and unescape HTML characters.

Free. Runs in your browser: nothing you enter or open is uploaded.

Encoded

  

All named entities this tool knows
CharacterNameNumber

Decoding understands every numeric reference and the named entities in the list above: all of HTML 4 plus a few common HTML 5 additions. A name it does not know is left exactly as written and counted.

How to use it

  1. Choose Encode or Decode.
  2. When encoding, choose whether to escape only the five special characters or every non-ASCII character too, and whether to use names or numbers.
  3. Paste your text and copy the result.

Questions

Which characters must be escaped in HTML?

The ampersand and the less than sign in text, plus the quote character that wraps an attribute value. Escaping > and both kinds of quote as well is a safe habit.

Do I need entities for accents and emoji?

Not on a page saved as UTF-8, which is nearly every page today. Entities for them are only needed when a system mangles non-ASCII text, such as some email tools and old databases.

Named or numeric entities?

Both work in every browser. Names such as © are easier to read; numbers such as © work for every character, including the ones without a name, and in XML.

Does escaping make user input safe?

Escaping text before putting it in HTML is the core defence against cross-site scripting, but the right escaping depends on where the text goes: a URL, a script or a style need their own rules.