Skip to main content
Text & Writing Tools

HTML Entity Encoder / Decoder

Encode special characters as HTML entities and decode entities back to text, with named, decimal or hex entities.

Type text to encode it, or paste HTML entities to decode them.

Decoding happens in a detached document, so pasted HTML is never rendered and scripts never run.

Escaping text for HTML does not make it safe for JavaScript or URLs - each context needs its own encoding.

What Are HTML Entities?

HTML entities are codes that stand for characters, written between an ampersand and a semicolon. < is a less-than sign, & is an ampersand and © is the copyright sign. You need them to show characters that HTML would otherwise treat as markup, and they are a safe way to write symbols in files that might not be saved as UTF-8.

When to Encode or Decode

  • Showing code examples on a web page, so <div> appears as text instead of being rendered.
  • Putting text with quotes or ampersands inside an HTML attribute.
  • Reading text from an API, a database or an RSS feed that arrives full of entities.

How to Use It

  1. Type text on the left to encode it, or paste entities on the right to decode them.
  2. Choose what to encode: only the five HTML special characters, those plus everything outside ASCII, or every character.
  3. Choose named entities (such as &pound;), decimal (&#163;) or hex (&#xA3;).

Example

Encoding <a href="/menu?item=fish&chips">Fish & Chips - £5 © 2026</a> with named entities gives &lt;a href=&quot;/menu?item=fish&amp;chips&quot;&gt;Fish &amp; Chips - &pound;5 &copy; 2026&lt;/a&gt;, which displays on a page as the original text instead of becoming a link.

Named or Numeric?

Named entities are easier to read, but only some characters have names. Numeric entities work for every Unicode character and in every HTML version. If your page is saved as UTF-8 - as almost all are today - you only need to encode the five special characters & < > " '.

Limitations

HTML escaping protects text inside HTML only. Text placed in JavaScript, CSS or a URL needs a different kind of encoding, so this is not a complete defence against cross-site scripting on its own. Decoding is done in an inert document, so pasted scripts never run. For URLs, use the URL Encoder / Decoder; to strip tags and keep the text, use HTML to Text.

Frequently Asked Questions

The ampersand (&), less-than (<) and greater-than (>) signs in text, and double or single quotes inside attribute values. Escaping all five is the safe default.

Named entities such as &copy; are easier to read but exist only for some characters. Numeric entities such as &#169; or &#xA9; work for every Unicode character.

Not if your page is saved and served as UTF-8, which is standard today - you can type the symbol directly. Entities are useful when the file encoding is uncertain.

Escaping text before putting it into HTML is an important part of preventing cross-site scripting, but text placed into JavaScript, CSS or URLs needs different encoding. Use your framework's escaping functions in code.
Share this tool: