Skip to content
{//}nullpath

HTML Encode / Decode

0 requests sent since load
Input

convert

output

options

Output

About HTML encoding

HTML encoding (escaping) replaces characters that have special meaning in HTML —&, <,>, and optionally quotes — with their entity equivalents so they render as literal text rather than being interpreted as markup. Decoding uses the browser's own HTML parser, so every named entity (&nbsp;, &copy;, etc.) and numeric reference (&#169;) is handled correctly.

When to use it

Escaping is the fix for injecting user-controlled text into markup — the same vector that causes cross-site scripting (XSS). Escape anything a visitor can type before it lands inside an HTML element or attribute, whether you are rendering comments, building email templates, or echoing values into a search box. The tool is also useful for displaying code snippets literally, for pasting markup into a CMS field without the editor interpreting it, and for unescaping entity soup that came out of a database or a third-party API.

How this tool works

Encoding is a deterministic character-by-character replacement: choose Named for readable output (&amp;) or Numeric for forms that are valid in any XML context (&#38;). Enable Encode quotes when the text will sit inside a double- or single-quoted attribute. Decoding creates a temporary in-memory element and reads its text content back, so every entity the browser understands — including hundreds of named HTML entities — resolves without maintaining a lookup table.

Edge cases and limitations

Watch out for double encoding: text that already contains &amp;will be re-escaped to &amp;amp; if you run it through the encoder again — decode first, then encode. The encoder targets the five core HTML special characters only; other named entities are not produced on encode (but all are understood on decode). Quoting is off by default because it is only required inside attribute values, not element content. Escaping neutralises markup but never removes it, so it is a rendering safeguard, not a content filter.

Example

<div class="note">Hi & welcome</div>encoded becomes&lt;div class="note"&gt;Hi &amp; welcome&lt;/div&gt;.

Related tools

The same escaping rules apply to XML — the XML formatterwill show how entities survive a parse/serialize round-trip. When the destination is a URL rather than markup, use the URL encoder.

FAQ

Named vs numeric entities?

Named entities (&amp;) are more readable; numeric (&#38;) work in any XML context. Both decode identically.

Is my data sent anywhere?

No. Encoding uses a plain regex replacement; decoding uses a temporary in-memory DOM element — no network requests.