HTML Entity Encoder / Decoder

Format
Scope
1 line · 0 B

HTML Entity Encoder / Decoder

Encode HTML special characters or decode entities back into text.

1 line · 0 B

Reference

2032

2032 of 2032 entities

UTF-8 · Text → Entities · named

About this HTML Entity Encoder / Decoder

Encode HTML special characters or decode entities back into text.

Your markup is processed locally in the browser. Nothing is uploaded or stored. Decoding recognizes the complete WHATWG named-entity table (2,032 entities), so any standard name converts correctly — not just the common ones.

Encoding scope

  • Special — escapes only & < > " ', the characters that can break HTML markup.
  • Non-ASCII — escapes those plus every character above the ASCII range (accents, symbols, emoji, CJK, …).
  • All named — escapes those plus any character that has a standard named entity (é, ©, →, …); characters without one are left as-is.
FAQ

Why do I need to encode characters like < and & for HTML?

Browsers parse < as the start of a tag. To display a literal < as text instead of markup, it must be encoded as &lt;.

What's the difference between named and numeric entities?

Named entities use descriptive names (&amp;, &copy;) — this converter recognizes and decodes the full WHATWG set of 2,032 standard names. Numeric entities (&#38;, &#169;) use a character code instead and work for any character, including the handful without a standard name.

Why did some characters come out as &#1234; instead of a name?

When Format is set to Named, a character without a standard entity name — many emoji and less-common symbols fall into this group — automatically falls back to a numeric reference instead. The output is still valid HTML; that character just has no name to use.

Is this the same as URL encoding?

No — HTML entity encoding protects characters inside HTML markup; URL encoding protects characters inside a URL. Use the URL Encoder for the latter.

Does encoding prevent XSS attacks?

It's one layer of defense — encoding user input before displaying it in HTML prevents that input from being interpreted as executable markup or script.

Does it support Unicode characters like emoji or accented letters?

Yes — encoding iterates by Unicode code point, not UTF-16 code unit, so multi-byte characters like emoji stay intact rather than being split. Set Scope to Non-ASCII to encode every non-ASCII character, or leave it on the default to encode only <, >, &, ", and '.

Is my text sent to a server?

No — encoding and decoding run entirely in your browser.

Related tools