HTML Encoder & Decoder

Escape and unescape HTML entities live — with an XSS-safe, text-only preview. 100% client-side.

0 chars

Live previewRendered as plain text only — no innerHTML, so input can never execute

Preview appears here as you type

Common HTML entities (cheat sheet)

EntityCharacterMeaning
&&ampersand — escape first
&lt;<less-than, starts a tag
&gt;>greater-than, ends a tag
&quot;"double quote (attributes)
&apos;'single quote (attributes)
&nbsp; non-breaking space
&copy;©copyright sign

Quick Answer

HTML encoding converts characters that have special meaning in HTML — such as & < > " and ' — into character entities like &amp; &lt; and &gt;, so browsers display them as text instead of parsing them as markup. Use this free online HTML encoder to escape untrusted text before inserting it into HTML, or to decode entities back into plain characters. Non-ASCII letters and emoji can also be converted to numeric entities. Decoding is done with a pure character map — never innerHTML — so the tool itself is XSS-safe by construction.

How It Works

1

Choose Encode or Decode with the toggle at the top of the tool

2

When encoding, optionally enable numeric entities for non-ASCII characters and emoji

3

Paste your text — the result and the text-only preview update live as you type

4

Edit the output directly or click Copy to take the result to your clipboard

Key Facts

  • Escapes the five XML-critical characters: & < > " ' (as &amp; &lt; &gt; &quot; &apos;)
  • Optional numeric-entity mode converts non-ASCII and emoji (&eacute; → &#233;, 😀 → &#128512;)
  • Decoding uses a pure named-entity map plus numeric-entity regex — no innerHTML, no eval
  • The live preview renders decoded output as plain text only, so it can never execute markup
  • Escaping user input before inserting it into HTML is the primary defense against XSS
  • Ampersand must be escaped first so existing entities are not double-encoded
  • Handles both decimal (&#169;) and hexadecimal (&#xA9;) numeric entities when decoding
  • 100% client-side: your text never leaves the browser

Frequently Asked Questions

Which characters should I escape in HTML?

At minimum the five markup-significant characters: & becomes &amp;, < becomes &lt;, > becomes &gt;, " becomes &quot;, and ' becomes &apos; (or &#39;). Escaping & and < is mandatory for text content; quoting and escaping " and ' is essential whenever text goes into an attribute value. This tool always escapes all five so the output is safe in both element content and quoted attributes.

What are numeric character references like &#233;?

A numeric character reference encodes a character by its Unicode code point: &#233; is é (U+00E9) and &#x1F600; or &#128512; is 😀. Any Unicode character can be written this way even when no named entity exists, which is why email templates and older CMSes use them. This tool can convert all non-ASCII characters in your input to decimal numeric entities with one toggle.

How does this tool stay safe from XSS while decoding HTML?

Many online decoders render your input as real HTML, which can execute injected scripts. This tool never assigns anything to innerHTML. Decoding uses a pure JavaScript map for named entities plus a regular expression for &#NNN; and &#xHH; references, and the preview panel renders the result as plain text via React text nodes. There is no code path where your input becomes live markup.

Why do I need to escape HTML if I am not building web pages?

Escaped text is also the safe way to show markup examples in documentation, blog posts, emails, and code snippets — otherwise <div> disappears because the browser parses it as a real element. It is also required when generating XML and many JSON-in-HTML contexts (e.g. embedding data in a script tag safely).

Is it safe to paste text into this tool?

Yes. Encoding and decoding happen locally in your browser with plain JavaScript string operations. Nothing is sent to a server, logged, or stored — closing the tab discards everything. And because the tool never renders your input as HTML, pasting even hostile markup cannot execute anything.