HTML Entity Encoder / Decoder
Escape text for HTML with named or numeric entities, or turn entities back into characters.
Escape text for HTML, or turn entities back into characters
HTML Entity Encoder / Decoder has two modes. Encode replaces characters that have a special meaning in HTML — & < > " and ' — with character references such as <, so text shows up as text instead of being read as markup. It can also replace every non-ASCII character, which helps when a file or system can’t be trusted to keep accents, symbols or emoji intact.
Decode does the reverse: it turns references like é, é or é back into the characters they stand for. The output updates as you type, and everything happens in your browser.
How to encode or decode HTML entities
- Choose Encode or Decode at the top.
- Type or paste your text into the input box. The result appears below straight away.
- When encoding, choose which characters to replace: only the five special characters (the default), or also everything outside basic ASCII.
- Choose the reference format: named where a common name exists, decimal, or hexadecimal.
- Click Copy output, or use Swap to move the output into the input and switch modes — a quick way to check that decoding gives back your original text.
How each format writes a character
- Named: about 250 common names are used — accented Latin letters, typographic quotes and dashes, ©, ® and ™, arrows, maths symbols and Greek letters. A character without one of those names is written as a decimal reference, and the apostrophe is always '.
- Decimal: the character’s Unicode number, for example é for é.
- Hexadecimal: the same number in base 16 with capital letters, for example é.
- Emoji: each emoji or other character outside the Basic Multilingual Plane becomes a single reference such as 😀, never two surrogate halves.
Common reasons to escape or unescape HTML
- Showing code on a web page: encode a snippet so readers see the tags instead of the browser running them.
- Attribute values: escape quotes and ampersands before putting text into title, alt or data attributes by hand.
- ASCII-only systems: encode non-ASCII characters for templates, emails or legacy systems that mangle UTF-8.
- Reading escaped text: decode content copied from page source, a feed or a database export so it’s readable again.
Tips for clean results
- Encode once: encoding text that is already encoded turns & into &amp;. If the output looks doubled, decode first.
- Special characters are enough for UTF-8 pages: a page served as UTF-8 displays accents and emoji directly, so the default option keeps the text readable.
- URLs need a different kind of escaping: spaces and symbols in a web address use percent-encoding; the URL Encoder / Decoder handles that.
Character references in HTML
Named and numeric references
HTML lets you write any character as &#number; (decimal), &#xnumber; (hexadecimal) or, for a long list of characters, &name;. The numeric forms work for every Unicode character; the named forms are easier to read but exist only for some.
How decoding works here
Decode mode hands your text to the browser’s own HTML parser in a mode where tags stay plain text, then reads back the characters. That means it knows every name defined in HTML and follows the same rules as a web page, including references written without the closing semicolon. Nothing is rendered or run: tags such as <script> come out as text.
HTML Entity Encoder / Decoder: common questions
Which characters does the default option escape?
Exactly five: & < > " and '. That is enough to make text safe inside HTML elements and inside attribute values in either kind of quotes.
Why does an emoji become one reference and not two?
In JavaScript an emoji is stored as two surrogate code units, and some encoders turn each half into its own reference, which browsers can’t join back together. This tool works on whole Unicode code points, so 😀 becomes 😀 (or 😀).
Why did an unknown entity stay unchanged when decoding?
Text such as &nosuch; isn’t a defined name, so browsers show it as written, and so does this tool. Check the spelling; names are case-sensitive, so É and é are different letters.
Is encoding the same as making user input safe for my website?
Escaping the five special characters is the core of preventing HTML injection in text and quoted attributes, but it doesn’t cover URLs, JavaScript or CSS contexts. Use your framework’s built-in escaping for each context.
Is there a size limit or is my text sent anywhere?
There is no fixed limit, but very large text makes the live output slower. Nothing leaves your browser. Other developer tools such as the Base64 Encoder also work locally.

