HTML Encode / Decode

HTML Encode / Decode

Encode text to HTML entities or decode entities back to text.

What the HTML Encoder Does

A handful of characters carry a special meaning in HTML, so they have to be written as entities whenever you want them shown as literal text rather than treated as markup. This HTML decoder and encoder converts plain text into safe HTML entities, and back again, so code snippets, user input and special characters do not break the page.

No uploads and no waiting: whether you HTML encode online or HTML decode online, it converts as you type, in your browser.

How to Use the HTML Encoder / Decoder

Everything runs in your browser; nothing is uploaded or stored.

What Is HTML Encoding?

When You Would Use This

Worked Example

Input:

<div class=”title”>Hello & welcome</div>

Output:

&lt;div class=&quot;title&quot;&gt;Hello &amp; welcome&lt;/div&gt;

Every <, >, ” and & is replaced by its entity, and Decode puts them back exactly as they started — the round trip is lossless. Accented and symbol characters are converted too, as numeric entities: ñ becomes &#241; and © becomes &#169;.

HTML Encoding in Code

JavaScript

function htmlEncode(str) {
  const el = document.createElement("div");
  el.innerText = str;
  return el.innerHTML;
}
htmlEncode('<div>Hello & "World"</div>');

PHP

htmlspecialchars('<div>Hello & "World"</div>', ENT_QUOTES);

Python

import html
html.escape('<div>Hello & "World"</div>')

Do’s and Don’ts

Do

Don’t

Common Mistakes

Good to Know

Frequently Asked Questions

Which characters does HTML encoding actually convert?

The core set is <, >, &, ” and ‘, because each has a special meaning in HTML markup. This tool also converts non-ASCII characters to numeric entities, so ñ becomes &#241; and © becomes &#169;.

Are HTML encoding and URL encoding the same?

No. HTML encoding escapes characters that have a special meaning inside HTML markup; URL encoding (percent-encoding) escapes characters that are unsafe inside a URL. The formats differ and the two are not interchangeable.

Does HTML encoding protect against every security issue?

No. It closes one big category — content being misread as executable markup — but it is not a full sanitizer. If your application has to accept some real HTML from users, use a dedicated sanitization library as well.

What is the difference between named and numeric entities?

Named entities such as &amp; and &copy; are readable shortcuts for common characters. Numeric entities such as &#38; and &#169; refer to a character by its Unicode code point, so they work for almost any character, named or not.

Can I recover the exact original text by decoding?

Yes. Encoding and decoding are fully reversible here — a round trip through Encode and then Decode returns the original text character for character.