HTML Encode/Decode
Convert characters into HTML entities and vice-versa.
💡 Common Use Cases
- Safely display user-generated content in HTML
- Encode code snippets for display in web pages
- Prevent XSS vulnerabilities in web apps
- Decode HTML entities from scraped content
Encode and decode HTML entities — safely display any character
HTML treats certain characters as structural. The less-than sign (<) opens a tag. The greater-than sign (>) closes one. The ampersand (&) introduces an entity. The double-quote (") wraps attribute values. If you want to display these characters as visible text rather than have the browser interpret them as markup, you need to encode them as HTML entities. This HTML Encode / Decode tool converts text between literal characters and their entity equivalents.
How to use it
Drop your HTML snippet, code sample, or entity-encoded string into the editor. Choose Encode (convert special characters to entities) or Decode (convert entities back to literal characters). Click the button. The output is your text in the converted form, ready to copy.
The essential HTML entities
<— less-than sign (<)>— greater-than sign (>)&— ampersand (&)"— double-quote (")'or'— apostrophe (') — non-breaking space©— copyright (©)®— registered trademark (®)™— trademark (™)€— euro (€)£— pound (£)—— em dash (—)–— en dash (–)…— ellipsis (…)
There are over a thousand named entities in HTML for everything from mathematical operators to chess pieces. You can also use numeric entities like   (the decimal code for a non-breaking space) or hexadecimal entities like   (the same character in hex).
When encoding is essential
Displaying code examples in documentation. If your blog post or docs site has HTML code samples, every < and > in the sample needs to be encoded as < and >, otherwise the browser will treat the sample as actual HTML and render it instead of displaying it.
Displaying user-generated content. Any text you accept from users and display on a page must be HTML-encoded before rendering — otherwise an attacker could submit malicious HTML or JavaScript that gets executed in other users' browsers. This is the basic defence against cross-site scripting (XSS).
Including special characters in attribute values. An HTML attribute like title="Tom & Jerry" needs the ampersand encoded as &.
Email HTML. Newsletter templates need special characters in subject lines and preview text encoded to display consistently across email clients.
Pasting from external sources. Content copied from a word processor or formatted email often contains characters like smart quotes ("curly" quotation marks), em dashes, and ellipses that should be displayed in your HTML — encoding them as entities ensures they appear correctly in older browsers and email clients that may not handle Unicode well.
When decoding is what you need
Reading text scraped from HTML. Web pages and HTML emails are full of entity-encoded characters. If you are processing scraped content for analysis or display in a non-HTML context, decoding turns — back into a clean em dash, into a regular space, etc.
Cleaning database records. Some legacy systems store text in HTML-encoded form. Decoding before export gives you clean plain text.
Translation and localisation. Translators working with HTML-encoded source text often prefer to decode first to see what they are translating, then re-encode the translated version.
Email body extraction. The text body of an HTML email is full of entities. Decoding produces a readable plain-text version.
HTML encoding vs URL encoding
These are two different systems for two different purposes. HTML encoding represents special characters in HTML so they display correctly without being interpreted as markup. URL encoding represents special characters in URLs so they do not interfere with URL structure. The encoding mechanisms look different (& vs %26) and have different scopes. Do not confuse them — encoding HTML content with URL encoding (or vice versa) will produce broken output.
Encoding modes
The tool offers different encoding aggressiveness levels:
- Minimal: only the strictly necessary characters (<, >, &, ", ') — safe for display
- Named entities: encode the strict set plus commonly-named entities like , ©, etc.
- All non-ASCII: encode every non-ASCII character as a numeric entity — produces ASCII-only output that displays correctly in legacy systems
Privacy
All encoding and decoding happens in your browser. Your text never leaves your device — no upload, no logging, no storage. Safe for confidential code, customer data, internal documents, and any other content you would not want sitting on a third-party server.