Encode special characters to HTML entities or decode entities back to text. Prevent XSS and display issues. Free, browser-based. 100% free and private.
HTML entities are special character sequences that represent reserved characters in HTML. When the browser encounters these sequences, it renders the corresponding character instead of interpreting it as HTML markup. For example, < renders as the less-than symbol (<) without starting an HTML tag.
The HTML specification defines hundreds of named entities for special characters, mathematical symbols, Greek letters, and more. The most critical ones are the five characters that have special meaning in HTML: ampersand (&), less-than (<), greater-than (>), double quote ("), and single quote (').
Encoding HTML entities serves two critical purposes:
<script> is inserted into HTML without encoding, it executes as JavaScript. Encoding converts it to harmless text that displays literally.&, <, ©& (ampersand), © (copyright)& (ampersand), © (copyright)All three forms are valid HTML. Named entities are most readable; numeric entities can represent any Unicode character.
Ampersand: & | Less-than: < | Greater-than: > | Double quote: " | Single quote: ' | Non-breaking space: | Copyright: © | Em dash: —
Cross-site scripting (XSS) is one of the most common web security vulnerabilities. It occurs when an attacker injects malicious scripts into a web page viewed by other users. The primary defense is to encode all user-generated content before inserting it into HTML. This tool helps developers understand and verify entity encoding.
All encoding and decoding happens in your browser. No data is sent to any server. Safely encode content containing sensitive information.
Encode data for URLs with our URL Encoder/Decoder. Encode binary data with our Base64 Encoder. Minify your HTML with our HTML Minifier.
HTML entities are special codes that represent characters with reserved meaning in HTML. For example, < is written as < to prevent the browser from interpreting it as a tag.
The five characters that must be encoded in HTML content are: & (ampersand), < (less than), > (greater than), " (double quote), and ' (single quote/apostrophe).
Encoding prevents XSS (cross-site scripting) attacks and ensures special characters display correctly. Without encoding, a < character would be interpreted as the start of an HTML tag.
Yes. The decoder handles named entities (like &), decimal entities (like &), and hexadecimal entities (like &).
Browse all free tools · Guides and tutorials · PDF tools · Developer tools · Text tools · SEO tools