HTML Entity Encoder/Decoder
Encode special characters to HTML entities and vice versa.
How to use this tool
- Enter your text in the input area.
- Select 'Encode' to convert special characters to HTML entities.
- Select 'Decode' to convert HTML entities back to characters.
- Click the button to process your text.
- Copy the result to your clipboard.
About this tool
HTML Entity Encoder/Decoder is an online, free tool that converts special characters to their HTML entity equivalents. No registration required! It handles characters like <, >, &, and quotes. This is essential for displaying code in HTML, preventing XSS attacks, and ensuring special characters render correctly in web pages. The decoder reverses this process, converting entities back to readable characters.
Frequently asked questions
What are HTML entities?
Escape sequences that let you display a character HTML would otherwise treat as markup. < renders a less-than sign, > a greater-than sign, & an ampersand and " a double quote. Without them the browser reads those characters as the start of a tag or an entity.
Why do I need to encode HTML?
Two reasons. To display code or literal angle brackets on a page without the browser trying to render them as elements, and to make untrusted input safe. Encoding user-supplied text before putting it in a page is the fundamental defence against cross-site scripting, because an encoded script tag is text rather than an instruction.
Is encoding HTML enough to stop XSS on its own?
It is the core of the defence but not the whole of it, because the correct escaping depends on where the value lands. Text inside an element, an attribute value, a URL and a block of JavaScript each need different treatment. Encode for the context you are actually writing into, and prefer your framework's own escaping where one exists.
Which characters really have to be encoded?
In element text, the ampersand and the less-than sign are the ones that matter. Inside a quoted attribute you also need the matching quote character. Encoding more than that is harmless, which is why tools tend to escape the full set of five.
What does the decoder do?
It converts entities back into the characters they stand for, which is how you make sense of escaped markup pulled out of a database, a log file or an API response that double-encoded its output.
Is my text sent to a server?
No. Both directions run in your browser and nothing is uploaded, stored or logged.

