HTML Entity Encoder / Decoder

Encode special characters to HTML entities or decode entities back to text. Prevent XSS and display issues. Free, browser-based. 100% free and private.

How to use

  1. Choose Mode — Select Encode to convert special characters to entities, or Decode to reverse
  2. Enter Text — Paste HTML or entity-encoded text into the input area
  3. Convert & Copy — Click to process, then copy the result

What Are HTML Entities?

HTML entities are special character sequences that represent reserved characters in HTML. When the browser encounters these sequences, it renders the corresponding character instead of interpreting it as HTML markup. For example, &lt; renders as the less-than symbol (<) without starting an HTML tag.

The HTML specification defines hundreds of named entities for special characters, mathematical symbols, Greek letters, and more. The most critical ones are the five characters that have special meaning in HTML: ampersand (&), less-than (<), greater-than (>), double quote ("), and single quote (').

Why Encode HTML Entities?

Encoding HTML entities serves two critical purposes:

  • Security (XSS prevention): If user input containing <script> is inserted into HTML without encoding, it executes as JavaScript. Encoding converts it to harmless text that displays literally.
  • Correct rendering: Characters like < and & have special meaning in HTML. Without encoding, they may be misinterpreted as tags or entity references, causing rendering errors.

Types of HTML Entities

  • Named entities: Human-readable names like &amp;, &lt;, &copy;
  • Decimal entities: Numeric codes like &#38; (ampersand), &#169; (copyright)
  • Hexadecimal entities: Hex codes like &#x26; (ampersand), &#xA9; (copyright)

All three forms are valid HTML. Named entities are most readable; numeric entities can represent any Unicode character.

Common Entities Reference

Ampersand: &amp; | Less-than: &lt; | Greater-than: &gt; | Double quote: &quot; | Single quote: &#39; | Non-breaking space: &nbsp; | Copyright: &copy; | Em dash: &mdash;

XSS Prevention

Cross-site scripting (XSS) is one of the most common web security vulnerabilities. It occurs when an attacker injects malicious scripts into a web page viewed by other users. The primary defense is to encode all user-generated content before inserting it into HTML. This tool helps developers understand and verify entity encoding.

Privacy

All encoding and decoding happens in your browser. No data is sent to any server. Safely encode content containing sensitive information.

Encode data for URLs with our URL Encoder/Decoder. Encode binary data with our Base64 Encoder. Minify your HTML with our HTML Minifier.

Frequently asked questions

What are HTML entities?

HTML entities are special codes that represent characters with reserved meaning in HTML. For example, < is written as &lt; to prevent the browser from interpreting it as a tag.

Which characters need encoding?

The five characters that must be encoded in HTML content are: & (ampersand), < (less than), > (greater than), " (double quote), and ' (single quote/apostrophe).

Why encode HTML entities?

Encoding prevents XSS (cross-site scripting) attacks and ensures special characters display correctly. Without encoding, a < character would be interpreted as the start of an HTML tag.

Does decoding handle named and numeric entities?

Yes. The decoder handles named entities (like &amp;), decimal entities (like &#38;), and hexadecimal entities (like &#x26;).

Related free tools

  • XML Formatter & Minifier — Beautify or minify any XML — SOAP, RSS, SVG, sitemap. Browser-based parser.
  • XML to JSON Converter — Parse any well-formed XML into a clean JSON tree with attributes and arrays.
  • JSON to XML Converter — Convert JSON to well-formed XML — supports attributes, custom root, declaration.
  • CSV Viewer — Open CSV or TSV files in your browser — sort, search, paginate, export filtered view.
  • JSON to CSV Converter — Convert JSON data to CSV format. Export to spreadsheets easily.
  • CSV to JSON Converter — Convert CSV data to JSON format. Useful for API development.
  • JSON Formatter — Format, beautify, or minify JSON with customizable indentation.
  • JSON Validator — Validate JSON syntax and find errors with line and column numbers.
  • HTML Minifier — Compress HTML by removing comments, whitespace, and line breaks.
  • CSS Minifier — Minify CSS by stripping comments, whitespace, and unnecessary characters.
  • JavaScript Minifier — Compress JavaScript by removing comments, whitespace, and empty lines.
  • Base64 Encoder/Decoder — Encode text to Base64 or decode Base64 back to text. UTF-8 support.

Browse all free tools · Guides and tutorials · PDF tools · Developer tools · Text tools · SEO tools