HTML Entity Encoder / Decoder
Encode special characters to HTML entities or decode them back.
How to use
- Paste your text or HTML.
- Choose Encode or Decode.
- Copy the result.
How the HTML Entity Encoder / Decoder works
Converts characters with special meaning in HTML into entities, and back again — the basic defence against breaking your markup or opening an injection hole.
The five characters that matter structurally are replaced by their named entities; decoding maps them back.
& → & < → < > → > " → " ' → '
Worked example
<script>alert(1)</script> becomes <script>alert(1)</script>, which renders as visible text rather than executing.
Things worth knowing
- Encode the ampersand first. Doing it last would double-encode the entities you just created.
- This is the mechanism behind escaping untrusted output, but a client-side tool is not a security control — escape on the server, at the point of rendering.
Frequently asked questions
When do I need to encode HTML?
When displaying user text or code on a page, encoding prevents characters like < and > from breaking the markup.
Is it private?
Yes — everything is processed in your browser.
Why does my page show &amp; instead of &?
Double encoding — the text was escaped twice. Escape exactly once, at output time.
Do I need to encode every non-ASCII character?
No. With a UTF-8 charset declared, accented and non-Latin characters can be written directly.