Skip to content
SPCXTools

HTML Encode / Decode

Convert text to safe HTML entities — or turn entities back into readable characters.

Runs locally — files never leave your device

Loading tool…

How to use HTML Encode / Decode

  1. 1Choose Encode to escape text for HTML, or Decode to turn entities back into characters.
  2. 2Paste your text or HTML into the Input box.
  3. 3When encoding, optionally convert non-ASCII characters (accents, symbols, emoji) to numeric entities.
  4. 4Copy or download the result. Switching direction moves the result to the input.

Escape and unescape HTML

Whenever you show code samples on a web page, insert user content into HTML, write text into XML or JSON templates, or read data that arrived full of & and ', you need to convert between characters and HTML entities. This tool does both: it escapes text so it displays safely in HTML, and it decodes any named or numeric entity back to the original character.

Features

  • Encode the five HTML special characters: & < > " '.
  • Optional numeric entities for every non-ASCII character, in decimal or hexadecimal.
  • Decode all named entities plus decimal and hex numeric entities.
  • Two-way switching that keeps your text.
  • Safe: input is never rendered as HTML.
  • Private: everything runs in your browser.

Common HTML entities

Character Named entity Numeric
& &amp; &#38;
< &lt; &#60;
> &gt; &#62;
" &quot; &#34;
' &apos; &#39;
non-breaking space &nbsp; &#160;
© &copy; &#169;
€ &euro; &#8364;
… &hellip; &#8230;
— &mdash; &#8212;

Related tools

Encode text for web addresses with URL Encode / Decode, encode binary data with Base64, turn Markdown into HTML with Markdown to HTML, or tidy XML with the XML Formatter.

Frequently asked questions

Which characters must be escaped in HTML?
& must always be written as &amp; and < as &lt;. Inside attribute values, quotes must be escaped too: " as &quot; and ' as &#39;. > is escaped as &gt; for consistency. The encoder escapes all five.
Why escape text at all?
Unescaped < and & can break your page layout, and when text comes from users it can allow cross-site scripting (XSS) attacks. Escaping makes the browser display the characters instead of interpreting them as HTML.
Do I need to encode accented letters and emoji?
Not if your page is served as UTF-8, which almost every modern site is. Encoding them as numeric entities such as &#233; is only useful for systems that can't handle Unicode, like some legacy email or CMS tools.
Which entities can be decoded?
All of them — every named entity defined in HTML (such as &nbsp;, &copy;, &euro;, &hellip;), decimal entities (&#8364;) and hexadecimal entities (&#x20AC;).
Is decoding untrusted HTML safe here?
Yes. Decoding uses a plain text field, so tags in the input are treated as text and no scripts or images are loaded. The output is shown as text, never rendered as HTML.