HTML Entity Encoder / Decoder
Encode special characters as HTML entities and decode entities back to text, with named, decimal or hex entities.
Type text to encode it, or paste HTML entities to decode them.
Decoding happens in a detached document, so pasted HTML is never rendered and scripts never run.
More Text & Writing Tools
View all 28Escaping text for HTML does not make it safe for JavaScript or URLs - each context needs its own encoding.
What Are HTML Entities?
HTML entities are codes that stand for characters, written between an ampersand and a semicolon. < is a less-than sign, & is an ampersand and © is the copyright sign. You need them to show characters that HTML would otherwise treat as markup, and they are a safe way to write symbols in files that might not be saved as UTF-8.
When to Encode or Decode
- Showing code examples on a web page, so
<div>appears as text instead of being rendered. - Putting text with quotes or ampersands inside an HTML attribute.
- Reading text from an API, a database or an RSS feed that arrives full of entities.
How to Use It
- Type text on the left to encode it, or paste entities on the right to decode them.
- Choose what to encode: only the five HTML special characters, those plus everything outside ASCII, or every character.
- Choose named entities (such as
£), decimal (£) or hex (£).
Example
Encoding <a href="/menu?item=fish&chips">Fish & Chips - £5 © 2026</a> with named entities gives <a href="/menu?item=fish&chips">Fish & Chips - £5 © 2026</a>, which displays on a page as the original text instead of becoming a link.
Named or Numeric?
Named entities are easier to read, but only some characters have names. Numeric entities work for every Unicode character and in every HTML version. If your page is saved as UTF-8 - as almost all are today - you only need to encode the five special characters & < > " '.
Limitations
HTML escaping protects text inside HTML only. Text placed in JavaScript, CSS or a URL needs a different kind of encoding, so this is not a complete defence against cross-site scripting on its own. Decoding is done in an inert document, so pasted scripts never run. For URLs, use the URL Encoder / Decoder; to strip tags and keep the text, use HTML to Text.
Frequently Asked Questions
Explore More Tools
Keep going with related categories and our most used tools.