HTML Encoder/Decoder
This HTML encoder converts characters with special meaning in HTML, such as < > and &, into entities like < and &, and decodes entities back into plain text.
About this tool
This HTML encoder converts characters with special meaning in HTML, such as < > and &, into entities like < and &, and decodes entities back into plain text.
How to use it
- Paste the text or HTML into the input box.
- Click Encode to escape it, or Decode to turn entities back into characters.
- Click Copy to copy the output.
Good to know
- Encoding escapes & as &, < as < and > as >, which stops the browser from treating text as markup.
- Decoding understands named entities (such as ©) and numeric ones (such as © or ©).
- Escaping user input before inserting it into HTML is a basic defence against cross-site scripting (XSS).
- Characters inside attribute values also need quotes escaped, which templating engines usually handle for you.
Runs entirely in your browser — nothing you enter is uploaded or stored.
Frequently asked questions
When do I need to encode HTML?
Whenever you display text that might contain < > or & inside a web page — for example code samples or user comments — so it shows as text instead of being parsed as HTML.
Does encoding protect against XSS?
Escaping text before inserting it into HTML is a key part of XSS prevention, but you also need correct escaping for attributes, URLs and JavaScript contexts.
What is the difference between & and &?
Both represent the ampersand. & is a named entity and & is its numeric code; browsers treat them the same.
Is my content uploaded?
No. Encoding and decoding happen in your browser.