XML Escape & Unescape

Make text safe to place inside XML elements and attributes, or convert <, &, ' and &#xNN; references back to characters.

Loading tool…

About the XML Escape/Unescape

XML defines exactly five predefined entities: &amp; (&), &lt; (<), &gt; (>), &quot; (") and &apos; ('). Unlike HTML there is no &nbsp; or &copy; unless a DTD declares it — a common cause of “undefined entity” parse errors when HTML snippets are pasted into XML, RSS or SVG.

In element text only & and < must be escaped (and > in the sequence ]]>); this tool always escapes all three. Inside attribute values the quote that delimits the value must also be escaped, which is what “Escape quotes” does. Tick “Non-ASCII as &#xNN;” when the document must be pure ASCII or its encoding is uncertain.

Unescaping converts the five entities and decimal or hex character references such as &#169; and &#xE9;. Any other named entity is left untouched and counted in the status line, because only the document's DTD could define it. Invalid code points such as &#xD800; are reported as errors.

How to use it

  1. Choose Escape or Unescape.
  2. Keep “Escape quotes” on if the text goes into an attribute value.
  3. Paste the text.
  4. Copy the escaped or unescaped output.

Frequently asked questions

Which characters must be escaped in XML?
& and < always. > when it follows ]]. " or ' inside an attribute delimited by the same quote. Everything else can be written literally in a UTF-8 document.
Why does my XML parser say “Entity 'nbsp' not defined”?
&nbsp; is an HTML entity. In XML write the numeric reference &#160; or the character itself.
Should I use CDATA instead of escaping?
CDATA (<![CDATA[ … ]]>) avoids escaping inside element text but cannot contain ]]> and cannot be used in attributes. Escaping works everywhere.
Can every character be written as a reference?
Only characters allowed in XML. XML 1.0 forbids most control characters (U+0000–U+001F except tab, LF, CR) even as &#x1; references.

Related tools