Skip to main content
ToolsBay

Runs in your browser — nothing is uploaded · verify

HTML Entity Encoder — free, and it runs in your browser

Escape characters to HTML entities, or decode entities back to text.

  • Escape text so it displays as text rather than being interpreted as markup.
  • Decode entities back into readable characters when you are reading a feed.
  • The five characters that matter in markup — ampersand, less-than, greater-than and both quote marks — are always covered.

Raw text

Tab indents · Esc then Tab to leave1 line

Escaped output

1 line
  • 70 tools

    Free, with no account and no watermark

  • 0 bytes

    Of your files or text uploaded — this tool runs in the tab

  • No queue

    The work happens in this tab, not in a line behind other users

Three steps, nothing to install

HTML Entity Encoder in three steps

  1. TEXT123456Paste it in — it never leaves the tab

    Paste your text or markup

    A code sample you need to show on a page, or an entity-riddled string out of an XML feed.

  2. TEXTENTITIESConverted on your own device

    Escape or unescape

    Angle brackets, ampersands and quotes become entities, so a code sample shows as code instead of executing.

  3. Copy ENTITIES

    Copy the safe version

    Ready to paste into a template, a CMS field or a documentation page.

Why use HTML Entity Encoder

  • The ampersand goes first

    Escape the angle brackets before the ampersands and you double-escape everything you just wrote. Order is the whole difficulty of doing this by hand.

  • Named and numeric both decode

    Real-world feeds mix named entities with decimal and hexadecimal references. All three are recognised, so the text comes back readable.

  • Your text stays in the page

    What you paste is not transmitted or stored, so an API response full of customer records, a token or an internal query never leaves your machine.

Frequently asked questions

Five: & < > " and '. The ampersand must be escaped first or you double-escape everything else. Quotes matter because unescaped ones let text break out of an HTML attribute — the exact failure escaping exists to prevent.

Why HTML entities exist

HTML gives special meaning to a handful of characters. A < starts a tag, an & starts an entity reference, and a quote closes an attribute value. To display those characters as text rather than have the browser act on them, they have to be written as references — &lt;, &amp;, &quot;.

Getting this wrong is how cross-site scripting happens. If user-supplied text containing <script> is written into a page unescaped, the browser runs it. Escaping turns it into inert text that displays as typed.

The three reference formats

  • Named — &copy;, &nbsp;. Readable, but only a fixed list of names exists.
  • Decimal — &#169;. Works for any Unicode code point.
  • Hexadecimal — &#xA9;. Same, written in hex, which matches how code points are usually documented.

Extended mode escapes every non-ASCII character as a numeric reference. That is occasionally required by systems that cannot carry UTF-8, but for a modern page serving charset=utf-8 it is unnecessary and makes the source harder to read.

For escaping text destined for a URL rather than HTML, use the URL encoder. To tidy the markup itself, use the HTML beautifier.

Related guides

More tools

70 tools, none of which want your file

Everything this tool does happens in the page you are looking at. No account, no upload, no watermark.