Escapes & < > " ' — safe anywhere in HTML.
  • 100% Free
  • No Sign-Up
  • No Credit Card
  • No Free Trial
  • No Pro Tier
  • No Watermarks

Nothing is uploaded. Just open it and start.

Encode and decode HTML entities

Free, no sign-up, no credit card, no trial. Your text never leaves the browser — escape markup-significant characters to render text safely, unescape entities back to plain text, or convert accents and symbols to named, decimal or hexadecimal references.

Spec-exact both ways

Encode for HTML text, attributes or XML; decode exactly as browsers do, with odd references flagged.

Named, decimal & hex

Applied to every encoded character, markup included. Search all 2,125 named entities.

No double-encoding

Keep existing entities, decode again when needed, and see every change highlighted.

Private & client-side

Your text never leaves the browser. No server round trip, ever.

Frequently asked questions

What's the difference between “Markup only” and “Also non-ASCII”?
Markup only encodes the characters that can break HTML: & < > and, in attributes and XML, the two quotes. Also non-ASCII encodes accented letters, symbols and emoji as well (é, ©, →, 😀), for ASCII-only files or old systems.
What do Named, Decimal and Hex do?
They decide how every encoded character is written, the markup characters included: Named gives &lt; and &eacute;, Decimal &#60; and &#233;, Hex &#x3C; and &#xE9;. A character with no name is written as a number. All three decode back to the same text.
Which “Where it goes” should I pick?
HTML text escapes & < > for text between tags. HTML attribute also escapes " and ', so it's safe anywhere in HTML. XML escapes the same five but only uses XML's five names (&amp; &lt; &gt; &quot; &apos;), writing everything else as a number, because XML doesn't know &eacute;.
Does decoding match what browsers do?
Yes. It follows the HTML spec: &#0;, surrogates like &#xD800; and values past U+10FFFF become “�”, &#128; is € (Windows-1252), old names work without a semicolon (&copy 2026), and &notit; reads as ¬it; just as in a browser. Inside attributes &copy= stays as typed. Unusual references are listed.
How do I avoid double-encoding?
Tick “Don't double-encode” and references already in the text (&amp;, &#233;) are left alone. The page also warns when the text you're encoding already looks encoded, and after decoding offers “Decode again” if the result still holds entities.
Can I look up an entity?
Open Entity list and search all 2,125 named references by name (rarr), character (→), code (U+2192 or 8594) or an everyday word (arrow, copyright, space). Click a named, decimal or hex code to copy it.
Can it work on files and big inputs?
Yes. Drop or open an .html, .txt, .xml or .svg file and download the result. Large inputs are converted in the background so the page stays responsive, and the changed parts are highlighted and counted.
Why should I escape HTML entities?
Putting untrusted text into HTML without escaping < > & lets it break your markup or inject scripts (XSS). Escaping turns those characters into harmless references so the text shows literally. The output here is only ever shown as text, never run.
Is my text uploaded anywhere?
No. Encoding and decoding run entirely in your browser; files are read on your device. Only your chosen options are remembered. It's free with no sign-up.

Spotted a bug or have a suggestion?

Found something broken, have an idea, or just want to say thanks about any of our tools? Every message reaches a real person.