HTML Entity Encoder / Decoder
Escape and unescape HTML special characters and entities. Everything runs in your browser — nothing is sent anywhere or stored.
How to use the HTML entity tool
- Choose Encode to escape raw text into safe HTML, or Decode to turn entities back into characters.
- When encoding, tick Encode all non-ASCII to numeric entities if you also want accented letters, symbols and emoji converted to
&#NNN;. - Paste your text, click the button, and copy the result.
Core escapes: & becomes &, < becomes <, > becomes >,
" becomes " and ' becomes '. The ampersand is always encoded first.
More PAYATE tools
Frequently asked questions
What are HTML entities?
HTML entities are special codes that represent characters which would otherwise be interpreted as HTML markup or cannot be typed directly. A named entity looks like & (for &) and a numeric entity looks like < or < (for <). Encoding replaces the raw character with its entity so the browser displays it as text instead of treating it as code.
When should I escape HTML?
Escape HTML whenever you insert untrusted or user-supplied text into a page, an attribute or a template. It prevents cross-site scripting (XSS) by stopping the browser from running injected <script> tags, and it lets you display code samples literally so tags show up as text rather than being rendered.
What is the difference between named and numeric entities?
A named entity uses a readable label such as &, < or ©. A numeric entity uses the character's code point in decimal (©) or hexadecimal (©). Numeric entities work for any character even when no name exists, while named entities are easier to read. Both decode to the same character.
Does it handle emoji and Unicode?
Yes. Decoding resolves numeric entities for any code point, including astral characters and emoji such as 😀. When encoding, the optional numeric entities for non-ASCII setting converts every character above code 127 to &#NNN; using its full code point, so emoji round-trip correctly.
Is my data stored or sent anywhere?
No. Encoding and decoding run entirely in your browser with plain JavaScript — nothing is uploaded to a server and nothing is stored. It is safe for text you would not want to transmit.
Which characters must I escape in HTML?
At minimum escape the five that affect markup: & (to &), < (to <), > (to >), and inside attribute values the quotes " (to ") and ' (to '). The ampersand must always be escaped first so existing entities are not double-encoded.