HTML Entity Encoder/Decoder

Escape &, <, >, " and ' into safe HTML entities, or turn entities back into characters, with instant two-way results in your browser.

Everything is processed locally in your browser. Your text never leaves your device.

—

How It Works

Escape mode walks your text through five replacements in a fixed order: the ampersand is handled first (& → &amp;), then <, >, the double quote (&quot;) and the single quote (&#39;). Doing & first is what keeps the result correct — if you escaped < before &, the ampersands introduced by earlier replacements would be escaped a second time. Unescape mode goes the other way by handing your text to the browser's own HTML parser through a detached <textarea> element, so every named and numeric entity the parser knows comes back as a plain character.

Showing code snippets safely
A tutorial that wants to display <div> as visible text has to write &lt;div&gt; in its source, otherwise the browser consumes it as markup and the snippet disappears. Paste your snippet into Escape mode and you get the entity soup to embed — and a rendered page that shows the tags literally.
Escaping stops HTML injection
When a site drops user input straight into the page, a comment containing <script> becomes live code — that is cross-site scripting. Escaping every special character on output turns such payloads into inert text like &lt;script&gt;, which is why output escaping is the default defense for rendered user content.
Decoding reverses named and numeric entities
&amp;, &#65; and &#x41; all decode back to their character, including HTML5 named entities without trailing semicolons. The parser resolves everything while the textarea stays detached from the document, so no scripts execute during decoding.

Frequently Asked Questions

Is escaping the same as sanitizing?

No, and the difference matters for security. Escaping turns every special character into inert text, so no markup or script can survive — it is the right tool when you want to display arbitrary content as-is. Sanitizing keeps a safe subset of real HTML (paragraphs, links, bold) and removes the rest, which requires an allowlist parser and is far easier to get wrong. Use escaping by default; only reach for a vetted sanitizer when you truly need user-supplied formatting.

Which characters need escaping in HTML?

The five this encoder handles cover the dangerous set: & starts every entity, < opens tags, > closes them, and the quotes " and ' can break out of attribute values. Angle brackets are only fatal in text position, but quotes kill you in attributes, so escaping all five everywhere is the cheap, context-free rule that never fails.

Why does & show as &amp; after a second escape?

Because escaping is literal: the & inside &amp; is itself escaped into &amp;amp;, so a browser now shows the text '&amp;' instead of '&'. Escaping is one-way per pass — if you are not sure whether content is already escaped, Unescape until it stabilizes, then escape exactly once when rendering.

Does the decoder handle numeric entities like &#233;?

Yes. Unescape uses the browser's own HTML parser via a detached textarea element, which resolves the full standard set: named entities (&lt;, &nbsp;, &euro;), decimal references (&#233;) and hexadecimal ones (&#x00E9;), including modern HTML5 named entities with or without the trailing semicolon.

Is anything uploaded to a server?

No. Escaping and decoding are a few lines of vanilla JavaScript running in your browser, and the decoder uses a detached DOM node that is never attached to the page. Your text never leaves your device, with no account, no tracking and no network request involved.