HTML Entity Encoder / Decoder
Encode and decode HTML entities instantly. Convert special characters to HTML entities and back. Supports named, decimal, and hex entities. Free online tool.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Worked Examples
Encoding a code snippet for display
You want to show <div class=“box”> as visible text on a web page.
Paste it into the input and select Encode. The output will be:
<div class="box">
This safely renders as the literal HTML tag text in any browser.
Decoding received HTML content
You received a string from an API: Tom & Jerry — Season 1.
Paste it in and select Decode. The output will be:
Tom & Jerry — Season 1
Encoding non-ASCII characters
Paste Café © 2024 and select Encode.
Non-ASCII characters are converted to numeric entities:
Café © 2024
Encoding an attribute value
Input <a title="Tom's café"> gives <a title="Tom's café"> and the status “Encoded — 6 characters converted.” The apostrophe becomes ', so the result is safe inside both single-quoted and double-quoted attributes.
Emoji and other characters outside the BMP
Ship it 🚀 encodes to Ship it 🚀: one reference with the code point U+1F680. Some encoders loop over UTF-16 code units and write �� instead. Those two numbers are surrogates, which the HTML parser replaces with U+FFFD, so the rocket turns into two replacement characters.
What Encode Changes
- The five characters with meaning in markup:
&→&,<→<,>→>,”→",’→'. - Every character above U+007F, as a decimal reference. Accented letters, CJK text and emoji all become numbers, which makes the output pure ASCII. That helps when a template or e-mail system is not UTF-8 clean, but the file gets larger:
中(3 bytes in UTF-8) becomes中(8 bytes). In a UTF-8 page you only need the first five. - Nothing else. Line breaks, tabs and spaces are kept. The encoder never writes named entities such as
©; the tables on this page list names for reading, not output.
How Decode Works
Decode hands the input to the browser’s own HTML parser (it sets the innerHTML of a <textarea> and reads the text back). Tags in the input are not created or run; only character references are replaced. The result therefore follows the HTML character reference rules:
- Every name in the HTML named character list is recognized (2,231 entries, counting the legacy forms without a semicolon), plus decimal (
©) and hex (©) forms. - Some legacy names work without the semicolon:
© 2024decodes to© 2024. The status count only includes references that end in;, so it can be lower than the number actually decoded. €toŸare mapped as Windows-1252, as the spec requires:€becomes €.�and surrogate numbers become U+FFFD.
Limits
- Encoding is for HTML text and quoted attribute values. Inside
<script>, inline event handlers, CSS or URLs, other escaping rules apply. Use String Escape for JavaScript and JSON strings and URL Encode for query parameters. - Decoding twice is not undone:
&lt;decodes to<, not<. For double-encoded text, put the output back into Input while Decode is selected. - The conversion status messages are in English on every language version of this page.
Common HTML Entities
| Character | Entity Name | Decimal | Description |
|---|---|---|---|
& | & | & | Ampersand |
< | < | < | Less-than sign |
> | > | > | Greater-than sign |
” | " | " | Double quotation mark |
’ | ' | ' | Apostrophe |
|   | Non-breaking space | |
© | © | © | Copyright sign |
™ | ™ | ™ | Trademark |
— | — | — | Em dash |
€ | € | € | Euro sign |
FAQ
What are HTML entities?
HTML entities, or character references, are codes that stand for one character. For example, < is written as < so the browser does not read it as the start of a tag, and © can be written as © or ©.
When should I encode HTML entities?
Encode when you put user-generated text or a code snippet into HTML text or a quoted attribute value. Escaping <, >, &, and quotes there prevents broken markup and HTML injection (XSS). The result is for HTML only: JavaScript strings, event handlers, CSS and URLs need their own escaping rules.
What is the difference between named, decimal, and hex entities?
Named entities use a label from the HTML list (&). Decimal entities use the character's Unicode code point in base 10 (&). Hex entities use base 16 (&). All three mean the same character and Decode reads all three. Encode writes names only for &, <, > and double quotes, and decimal references for everything else.
Is my data sent to any server?
No. The conversion runs in your browser tab, and the text is not sent to a server or saved in browser storage. The page's analytics records a usage event with the tool name and the direction you switch to, not the text.
Why does Tom's become Tom's and not Tom's?
The encoder always writes the decimal reference ' for an apostrophe. ' is also in the HTML named character list and decodes to the same character, so both are correct. Either form stops an apostrophe in English text from ending a single-quoted attribute value.