Skip to content
HTML Encoder / Decoder

HTML Encoder / Decoder

Encode HTML entities (<, >, &, ", ') or decode them back to plain HTML. Useful for showing code snippets on a web page and putting text safely inside HTML attributes.

Encode HTML special characters Decode HTML entities back to text Encode non-ASCII as numeric entities Swap output back to input Copy and download output Import from URL or file Theme switcher Fullscreen editor mode

Input

Paste HTML or text to encode/decode

Output

Encoded or decoded result

Key Features

  • Encode HTML special characters
  • Decode HTML entities back to text
  • Encode non-ASCII as numeric entities
  • Swap output back to input
  • Copy and download output
  • Import from URL or file
  • Theme switcher
  • Fullscreen editor mode

How to Use

  1. Paste your text or HTML into the input editor.
  2. Pick the encoding mode.
  3. Click Encode or Decode.
  4. Copy or download the output.
  5. Pair with the HTML editor for round-trip editing.

How the encoder and decoder work

Paste text or HTML into the left editor and click Encode or Decode. The result appears on the right, and the line above the editors shows the size of both. Everything runs in your browser.

Encode replaces characters with entities. The mode menu controls which ones:

  • Basic encodes only the five characters that matter to the HTML parser: & to &amp;, < to &lt;, > to &gt;, " to &quot;, and ' to &#39;. All other characters, including accented letters and emoji, are left as they are.
  • All non-ASCII as numeric does the same, then turns every character outside plain ASCII into a decimal entity such as &#233;. The output contains only ASCII, so it survives systems that mangle UTF-8.
  • All named uses a named entity where the tool has one (17 common symbols such as &copy;, &euro;, &nbsp;, &hellip;, and the curly quotes), plus the five basic ones, and a decimal entity for any other non-ASCII character.

Decode goes the other way. The input is handed to the browser's built-in DOMParser, and the tool returns the text the parser produced. Because the browser does the work, every entity the HTML standard defines is supported: named (&lt;), decimal (&#60;), and hexadecimal (&#x3C;). Swap moves the output back into the input, which is handy for decoding in several passes.

Example: showing user input as text

A comment submitted through a form contains markup that must be displayed, not run:

<p>Great post! <script>alert("hi")</script> Tom's & Jerry's</p>

Encoded in Basic mode:

&lt;p&gt;Great post! &lt;script&gt;alert(&quot;hi&quot;)&lt;/script&gt; Tom&#39;s &amp; Jerry&#39;s&lt;/p&gt;

Placed in a page, that output displays the original characters literally and the script never executes. The same technique is how you publish code samples in a blog post or documentation page: encode the snippet, then wrap it in <pre><code>.

Example: comparing the three modes

Input: Café © 2026 “Menü” 20°C €5 👍

Basic leaves this line unchanged, because it contains none of the five special characters. All non-ASCII as numeric:

Caf&#233; &#169; 2026 &#8220;Men&#252;&#8221; 20&#176;C &#8364;5 &#128077;

All named:

Caf&#233; &copy; 2026 &ldquo;Men&#252;&rdquo; 20&deg;C &euro;5 &#128077;

If your page is served as UTF-8 (it should be, with <meta charset="utf-8">), Basic is all you need. The other two modes are for older systems, some email pipelines, and source files that must stay ASCII-only.

Common entity problems and fixes

Double encoding

A page that shows &amp;lt;b&amp;gt; or &amp;amp; to visitors has been encoded twice, often once when saving to a database and again when rendering. Decode once, click Swap, and decode again. Decode handles one level per click: &amp;lt;b&amp;gt; becomes &lt;b&gt; on the first pass and <b> on the second. The long-term fix is to store raw text and encode only when outputting HTML.

Missing semicolons

For historical reasons, browsers still recognize some entities without the closing semicolon. The text &notit; decodes to ¬it;, because &not is a legacy entity for the ¬ sign. A bare & followed by an unknown word, like AT&T, is left alone. Encoding every & as &amp; avoids both surprises.

Decoding real HTML

Decode returns text, not markup. <p>Tom &amp; Jerry</p> decodes to Tom & Jerry: the entity is converted, and the <p> tags are parsed and dropped. Comments are removed, text inside <script> is kept as plain text, and leading spaces or blank lines at the very start of the input are removed by the parser.

Limitations

  • Entity encoding is for HTML text and attributes only. It is not URL encoding (%20), JavaScript string escaping, or JSON escaping.
  • Encoded output uses decimal numeric entities. There is no option for hexadecimal output.
  • All named mode knows 17 named symbols beyond the basic five. Other characters that have a named entity in the HTML standard, such as é (&eacute;), are output as numbers instead.
  • Your input is not saved between visits, and Clear empties both editors without asking.

When to use a different tool

  • To write and preview the HTML that will contain your encoded text, use the HTML Editor.
  • To read a large block of decoded markup, format it with the HTML Beautifier.
  • To turn HTML into readable plain-text Markdown instead of stripping the tags, use HTML to Markdown.

Frequently asked questions

Which HTML characters need to be encoded?

In normal text, the ampersand (&) and the less-than sign (<) must always be encoded, and encoding the greater-than sign (>) is good practice. Inside an attribute value, the quote character that wraps the value must be encoded too: &quot; for double quotes and &#39; for single quotes. Basic mode encodes all five, so its output is safe in both places.

What is the difference between &lt; and &#60;?

Nothing, once the browser reads them: both produce the < character. &lt; is a named entity and easier to read. &#60; is a decimal numeric entity, and &#x3C; is the same value in hexadecimal. Numeric entities exist for every Unicode character, while named entities exist only for a fixed list. The decoder here accepts all three forms.

Why does my page show &amp;lt; instead of a < sign?

The text was encoded twice. The first pass turned < into &lt;, and a second pass turned the & of that entity into &amp;. Paste the text here, click Decode, then Swap and Decode again until the output is what you expect. To avoid it, encode once, at the moment you insert text into HTML, not when you store it.

Does encoding HTML entities protect against XSS?

Only in HTML text and inside quoted attribute values. It does not make a value safe inside a script block, an inline event handler such as onclick, a CSS value, or a URL: a link to javascript:alert(1) contains no characters that need encoding. Each of those contexts needs its own escaping, which is why template engines escape based on context.

Why did Decode remove my HTML tags?

Decode passes the input to the browser's HTML parser and returns only the resulting text. Entities become characters, but real tags such as <p> or <b> are parsed as elements and dropped, and so are comments. Decode text that contains entities, not live HTML. If you only want the text of an HTML fragment, this behavior is actually useful.

Is my text sent to a server?

No. Encoding is done with a small JavaScript function and decoding with the browser's built-in DOMParser, both in your browser. Import URL fetches the file directly from your browser. This tool does not save your input between visits.

Latest from Our Blog

Tips, tutorials, and insights about web development