HTML encoder
Paste text to escape it for safe HTML, or paste entity-riddled HTML to decode it back — named and numeric entities both ways, instantly.
Output appears here as you type…Entities in both directions
Encode takes plain text and escapes the five characters HTML reserves — & < > " ' — so the text can sit safely inside markup or attribute values. Optionally it also converts every character outside printable ASCII to a numeric entity, emoji included.
Decode goes the other way: named entities (& © and the rest of the HTML spec's list), decimal entities (é), and hex entities (é) all come back as the characters they stand for. Anything that isn't a valid entity is left untouched. The swap button feeds the output back in and flips the direction — useful for checking a round trip.
When you need which direction
- Showing code on a page — encode a snippet before pasting it into a blog post or docs page, or the browser will try to render it instead of displaying it.
- Cleaning scraped or exported text — HTML exports, RSS feeds, and API responses often arrive full of & and ’; decode to get readable text back.
- Double encoding — if you see &lt; in output, something encoded twice. Decode twice to inspect, then fix the pipeline so each layer encodes exactly once.
- In templating frameworks, prefer the built-in auto-escaping over hand-encoding — use this tool for one-off snippets, debugging, and understanding what your pipeline did to the text.
Frequently asked questions
What does HTML encoding do?
It replaces characters that have special meaning in HTML with entities: & becomes &, < becomes <, > becomes >, and quotes become " and '. The browser then displays the characters instead of interpreting them as markup.
Which characters must always be escaped in HTML?
At minimum & and < in text content, and additionally " or ' inside attribute values (matching the quote style of the attribute). Escaping > is not strictly required but is conventional and harmless.
What's the difference between named, decimal, and hex entities?
They're three spellings of the same thing. ©, ©, and © all decode to the © character. Named entities are readable but only exist for a fixed list of characters; numeric entities (decimal &#NNN; or hex &#xHH;) can express any Unicode code point. The decoder here handles all three.
When should I encode non-ASCII characters as numeric entities?
Mainly when the file or channel carrying your HTML isn't reliably UTF-8 — legacy email templates, old CMS fields, or systems that mangle encodings. On a modern UTF-8 page it's unnecessary; literal é is fine and smaller than é.
Does escaping HTML prevent XSS?
Escaping untrusted text before inserting it into HTML is the core defense against cross-site scripting, yes — but context matters. Text going into a URL, a JavaScript string, or a CSS value needs that context's own escaping, not HTML entities. Encode for the context you're inserting into.
Is my text uploaded anywhere?
No. Encoding and decoding both run entirely in your browser. Decoding uses an inert parsed document, so pasted HTML is never executed — scripts can't run and nothing is fetched.
Related free tools
See all free tools →Built something? Put it online in seconds
host0 is the cloud for small software: bring any coding agent, build the tool only you need — like this one — and say "deploy to host0". Live at a shareable URL, no servers to run.