About this tool

This HTML encoder converts characters with special meaning in HTML, such as < > and &, into entities like &lt; and &amp;, and decodes entities back into plain text.

How to use it

  1. Paste the text or HTML into the input box.
  2. Click Encode to escape it, or Decode to turn entities back into characters.
  3. Click Copy to copy the output.

Good to know

  • Encoding escapes & as &amp;, < as &lt; and > as &gt;, which stops the browser from treating text as markup.
  • Decoding understands named entities (such as &copy;) and numeric ones (such as &#169; or &#xA9;).
  • Escaping user input before inserting it into HTML is a basic defence against cross-site scripting (XSS).
  • Characters inside attribute values also need quotes escaped, which templating engines usually handle for you.

Runs entirely in your browser — nothing you enter is uploaded or stored.

Frequently asked questions

When do I need to encode HTML?

Whenever you display text that might contain < > or & inside a web page — for example code samples or user comments — so it shows as text instead of being parsed as HTML.

Does encoding protect against XSS?

Escaping text before inserting it into HTML is a key part of XSS prevention, but you also need correct escaping for attributes, URLs and JavaScript contexts.

What is the difference between &amp; and &#38;?

Both represent the ampersand. &amp; is a named entity and &#38; is its numeric code; browsers treat them the same.

Is my content uploaded?

No. Encoding and decoding happen in your browser.