HTML Entity Encoder and Decoder
Encode text to safe HTML entities (escape), or decode HTML entities back to plain text — both directions update automatically.
How to use the HTML entity encoder
- Type in the "Plain text" field to see the HTML entity version automatically.
- Or paste HTML entities into the other field to decode them back.
- Both fields update each other live.
What are HTML entities?
HTML entities replace characters that have special meaning in HTML — like <, >, &, and quotation marks — with a safe text representation (for example, < becomes <). This prevents the text from being misinterpreted as HTML code when inserted into a web page, and is an important part of avoiding XSS vulnerabilities when displaying user content on a page.
The tool also handles numeric entities like A (decimal) and A (hexadecimal) when decoding.
Frequently asked questions
Why do I need to escape HTML characters?
Because characters like "<" and "&" have special meaning in HTML — without escaping, the browser would interpret them as the start of a tag or entity instead of plain text, which can also open the door to security issues like XSS.
Which entities get decoded?
The most common named entities (&, <, >, ", ', ) as well as all numeric entities in both decimal and hexadecimal format.
Is my text sent to a server?
No, all encoding/decoding happens locally in your own browser.