About the HTML Entities
Five characters matter when putting text into HTML: &, <, >, " and '. Escaping them to &, <, >, " and ' prevents the text from being read as markup — the basic defence against HTML injection and XSS when you build HTML by hand.
The encoder has three levels. Only & < > " ' is what you need for UTF-8 pages. Named where available also converts characters that have a well-known name — Latin-1 letters (é), Greek letters, typographic quotes and dashes (—), arrows, maths symbols, € and ™ — and uses numeric references for everything else. All non-ASCII as numeric produces pure-ASCII output like é that survives any encoding.
Decoding uses the browser's own HTML parser, so it understands all 2,231 named references in the HTML Living Standard, decimal (é) and hex (é) forms, and legacy entities written without a semicolon, exactly as a page would render them.
How to use it
- Choose Encode or Decode.
- When encoding, choose how much to escape: basic, named, or numeric.
- Paste your text or HTML into the input.
- Copy the result.