HTML Entities Encode & Decode

Escape special characters so text displays literally in HTML, or turn entities such as &, é and 🚀 back into characters.

Loading tool…

About the HTML Entities

Five characters matter when putting text into HTML: &, <, >, " and '. Escaping them to &amp;, &lt;, &gt;, &quot; and &#39; prevents the text from being read as markup — the basic defence against HTML injection and XSS when you build HTML by hand.

The encoder has three levels. Only & < > " ' is what you need for UTF-8 pages. Named where available also converts characters that have a well-known name — Latin-1 letters (&eacute;), Greek letters, typographic quotes and dashes (&mdash;), arrows, maths symbols, &euro; and &trade; — and uses numeric references for everything else. All non-ASCII as numeric produces pure-ASCII output like &#xE9; that survives any encoding.

Decoding uses the browser's own HTML parser, so it understands all 2,231 named references in the HTML Living Standard, decimal (&#233;) and hex (&#xE9;) forms, and legacy entities written without a semicolon, exactly as a page would render them.

How to use it

  1. Choose Encode or Decode.
  2. When encoding, choose how much to escape: basic, named, or numeric.
  3. Paste your text or HTML into the input.
  4. Copy the result.

Frequently asked questions

Do I need to encode characters like é or © if my page is UTF-8?
No. With <meta charset="utf-8"> you only need to escape & < > " '. Named or numeric entities are useful when the output may be re-encoded or must stay ASCII.
What is the difference between &amp;#39; and &amp;apos;?
Both mean an apostrophe. &apos; is defined in XML and HTML5 but not in HTML 4, so &#39; is the most compatible choice.
Is HTML-escaping enough to prevent XSS?
It is correct for text inside elements and quoted attributes. It is not enough inside <script>, style, unquoted attributes or URLs such as href="javascript:…", which need context-specific encoding.
Why does &amp;nbsp; decode to a character that looks like a space?
It is U+00A0, a non-breaking space. It looks like a space but is a different character, which can break string comparisons.

Related tools