HTML encoder and decoder for text and entities

Convert special characters into HTML entities or decode character references back into readable text. The default escapes text for HTML while keeping accented letters, symbols, and emoji readable. Paste your text and copy the result, or open Options for other uses.

Loading the tool…

What is HTML entity encoding?

HTML uses characters such as < and & as part of its syntax. To display them as ordinary text, you can replace them with character references, often called HTML entities. For example, &lt; displays a less-than sign and &amp; displays an ampersand.

There are three common forms: a named reference such as &copy;, a decimal reference such as &#169;, and a hexadecimal reference such as &#xA9;. All three represent the copyright symbol, ©. Names are case-sensitive; include the final semicolon when writing references.

Encoding is useful when you want to show an HTML example on a page, insert literal text into a template, or represent a symbol with an explicit character reference. Decoding helps you read entity-encoded text from an export, source file, or copied snippet. It converts references to characters; it does not remove HTML tags or render a page.

For example, encoding this text:

<strong>Hello & welcome</strong>

produces HTML source that displays the tags literally:

&lt;strong&gt;Hello &amp; welcome&lt;/strong&gt;

Encoding already encoded text can double its entities: &amp; becomes &amp;amp;. Decode first only when you know the source is already entity-encoded.

For normal page output, use your template engine’s automatic escaping. HTML text escaping is not a general HTML sanitizer, JavaScript string escaper, or URL encoder; attribute values need appropriate quoting and context-specific validation.

Common HTML entities and reserved characters

Use these tables as a quick reference, not as a complete list. < and & have special roles in HTML text; quotes matter when they delimit attributes. The currency signs, mathematical symbols, and spacing characters below are useful references, not all reserved syntax. Decimal and hexadecimal references represent the same Unicode character; for example, &#169; and &#xA9; both mean ©. The x marks a hexadecimal value.

The HTML5 tab covers modern HTML. HTML4 shows commonly used legacy names and the different treatment of apostrophes. XML lists its five predefined names and explains when numeric references are needed. Changing a reference tab does not change the converter’s settings.

HTML5 character references

Quotes can remain literal in ordinary HTML text; escape the matching quote when inserting text into a quoted attribute.

The WHATWG named character reference list defines the names supported by modern HTML.

CharacterEntity nameDecimal referenceHex referenceDescription
&&amp;&#38;&#x26;Ampersand; begins a character reference.
<&lt;&#60;&#x3C;Less-than sign; begins markup.
>&gt;&#62;&#x3E;Greater-than sign; usually literal in text, but may be escaped.
"&quot;&#34;&#x22;Double quote; escape it inside a double-quoted attribute.
'&apos;&#39;&#x27;Apostrophe; escape it inside a single-quoted attribute.
Non-breaking space&nbsp;&#160;&#xA0;Keeps adjacent words on the same line.
©&copy;&#169;&#xA9;Copyright symbol.
®&reg;&#174;&#xAE;Registered trademark symbol.
™&trade;&#8482;&#x2122;Trademark symbol.
€&euro;&#8364;&#x20AC;Euro currency sign.
£&pound;&#163;&#xA3;Pound currency sign.
¥&yen;&#165;&#xA5;Yen or yuan currency sign.
×&times;&#215;&#xD7;Multiplication sign.
÷&divide;&#247;&#xF7;Division sign.
≤&le;&#8804;&#x2264;Less-than or equal-to sign.
≥&ge;&#8805;&#x2265;Greater-than or equal-to sign.
→&rarr;&#8594;&#x2192;Right arrow.
✓&check;&#10003;&#x2713;Check mark; this name is not in HTML4.

HTML4 character references

The W3C HTML 4.01 entity reference documents the older named set. HTML4 does not define &apos;; use &#39; for an apostrophe when that compatibility matters. These shared names also work in HTML5.

CharacterEntity nameDecimal referenceHex referenceDescription
&&amp;&#38;&#x26;Ampersand; escape it when displaying a literal ampersand.
<&lt;&#60;&#x3C;Less-than sign; escape it when displaying literal text.
>&gt;&#62;&#x3E;Greater-than sign.
"&quot;&#34;&#x22;Double quotation mark.
'No HTML4 name&#39;&#x27;Apostrophe; use the numeric reference.
Non-breaking space&nbsp;&#160;&#xA0;Space that prevents a line break.
©&copy;&#169;&#xA9;Copyright symbol.
®&reg;&#174;&#xAE;Registered trademark symbol.
™&trade;&#8482;&#x2122;Trademark symbol.
€&euro;&#8364;&#x20AC;Euro currency sign.
£&pound;&#163;&#xA3;Pound currency sign.
¥&yen;&#165;&#xA5;Yen or yuan currency sign.
×&times;&#215;&#xD7;Multiplication sign.
÷&divide;&#247;&#xF7;Division sign.
≤&le;&#8804;&#x2264;Less-than or equal-to sign.
≥&ge;&#8805;&#x2265;Greater-than or equal-to sign.
→&rarr;&#8594;&#x2192;Right arrow.

XML character references

XML defines only five predefined entity names. They work without a DTD or custom entity declaration. References are case-sensitive and require a semicolon.

CharacterEntity nameDecimal referenceHex referenceDescription
&&amp;&#38;&#x26;Escape a literal ampersand in text or attributes.
<&lt;&#60;&#x3C;Escape a literal less-than sign in text or attributes.
>&gt;&#62;&#x3E;Optional in ordinary text, except to avoid a literal ]]> sequence.
"&quot;&#34;&#x22;Escape inside a double-quoted attribute.
'&apos;&#39;&#x27;Escape inside a single-quoted attribute.

Names such as &nbsp; and &copy; are not predefined in XML. Use &#160; for a non-breaking space or &#169; for ©, or declare the names in a DTD. Numeric references must still identify characters allowed by XML.

Choose Text with quotes to escape these five characters. This tool does not validate XML or remove forbidden characters, and Decode mode uses HTML5 rules rather than parsing XML.

HTML encoding and decoding in code

For repeatable conversions in an application, use a standard library or a maintained entity library. These examples encode the same short text and decode it again. They demonstrate string conversion, not rendering untrusted HTML. Libraries differ in their handling of quotes, Unicode, and incomplete references, so equivalent output need not use identical entity spellings.

JavaScript and TypeScript

The entities library works in Node.js and browser bundles. Install it with npm install entities. This example uses escapeText, the same function as this tool’s default HTML text (recommended) option. Use escapeUTF8 for Text with quotes, or encodeNonAsciiHTML for Extended entities.

import { escapeText, decodeHTML } from "entities";

const text = "<p>Tea & coffee</p>";
const encoded = escapeText(text);
const decoded = decodeHTML(encoded);

console.log(encoded); // &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
console.log(decoded); // <p>Tea & coffee</p>

When putting plain text on a web page, assigning it to textContent avoids interpreting it as markup. encodeURIComponent performs URL encoding, which is a different operation.

Python

Python’s built-in html module includes both operations. html.escape escapes quotes by default while leaving ordinary Unicode text unchanged; html.unescape recognizes HTML5 named and numeric references.

import html

text = "<p>Tea & coffee</p>"
encoded = html.escape(text, quote=True)
decoded = html.unescape(encoded)

print(encoded)  # &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
print(decoded)  # <p>Tea & coffee</p>

PHP

Use htmlspecialchars for special characters and html_entity_decode to decode references. Explicit flags select HTML5, escape both quote types, and replace invalid UTF-8 sequences during encoding. Ordinary Unicode letters remain unchanged.

<?php
$text = '<p>Tea & coffee</p>';
$flags = ENT_QUOTES | ENT_SUBSTITUTE | ENT_HTML5;
$encoded = htmlspecialchars($text, $flags, 'UTF-8');
$decoded = html_entity_decode($encoded, $flags, 'UTF-8');

// Run in the CLI to inspect both strings as text.
echo $encoded, PHP_EOL; // &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
echo $decoded, PHP_EOL; // <p>Tea & coffee</p>

C# and .NET

System.Net.WebUtility provides HTML conversion without an additional package. HtmlEncode and HtmlDecode are convenient for strings; do not assume every HTML5 named reference is recognized by every platform’s decoder.

using System;
using System.Net;

string text = "<p>Tea & coffee</p>";
string encoded = WebUtility.HtmlEncode(text);
string decoded = WebUtility.HtmlDecode(encoded);

Console.WriteLine(encoded); // &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
Console.WriteLine(decoded); // <p>Tea & coffee</p>

Go

Go’s standard html package escapes the five special characters and decodes a broader set of references. For an actual HTML template, prefer html/template, which applies escaping according to the surrounding context.

package main

import (
    "fmt"
    "html"
)

func main() {
    text := "<p>Tea & coffee</p>"
    encoded := html.EscapeString(text)
    decoded := html.UnescapeString(encoded)

    fmt.Println(encoded) // &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
    fmt.Println(decoded) // <p>Tea & coffee</p>
}

Rust

Add the html-escape crate with cargo add html-escape. Its encode_text function escapes &, <, and > for ordinary HTML text. It leaves quotes alone; use the crate’s appropriate attribute encoder for a quoted attribute value. decode_html_entities decodes terminated named and numeric references, with stricter behavior than a browser for malformed input.

use html_escape::{decode_html_entities, encode_text};

fn main() {
    let text = "<p>Tea & coffee</p>";
    let encoded = encode_text(text);
    let decoded = decode_html_entities(encoded.as_ref());

    println!("{}", encoded); // &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
    println!("{}", decoded); // <p>Tea & coffee</p>
}

Java

Add Apache Commons Text (org.apache.commons:commons-text) to your Maven or Gradle project. Its StringEscapeUtils provides escapeHtml4 and unescapeHtml4. These use HTML4 names, not the full HTML5 set; apostrophes are not escaped by escapeHtml4.

import org.apache.commons.text.StringEscapeUtils;

public class HtmlEntitiesExample {
    public static void main(String[] args) {
        String text = "<p>Tea & coffee</p>";
        String encoded = StringEscapeUtils.escapeHtml4(text);
        String decoded = StringEscapeUtils.unescapeHtml4(encoded);

        System.out.println(encoded); // &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
        System.out.println(decoded); // <p>Tea & coffee</p>
    }
}

Swift

Add SwiftSoup through Swift Package Manager and include its product in your target. Use Entities.escape for HTML text and Parser.unescapeEntities to decode references without stripping tags or rendering HTML. The false argument selects text rather than attribute context for decoding. Text escaping leaves quotes unchanged, so it is not a quoted-attribute encoder.

import SwiftSoup

let text = "<p>Tea & coffee</p>"
let encoded = Entities.escape(text)

do {
    let decoded = try Parser.unescapeEntities(encoded, false)
    print(encoded) // &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
    print(decoded) // <p>Tea & coffee</p>
} catch {
    print("Could not decode HTML entities: \(error)")
}

Delphi / Object Pascal

Delphi’s TNetEncoding.HTML, from System.NetEncoding, provides Encode and Decode. It escapes &, <, >, and double quotes. Its documented decoder recognizes numeric references and the names amp, lt, gt, and quot; do not expect full HTML5 named-entity support or apostrophe escaping. This example uses Delphi’s runtime library, which is not shared by every Object Pascal compiler.

program HtmlEntitiesExample;

{$APPTYPE CONSOLE}

uses
  System.NetEncoding;

var
  Text, Encoded, Decoded: string;
begin
  Text := '<p>Tea & coffee</p>';
  Encoded := TNetEncoding.HTML.Encode(Text);
  Decoded := TNetEncoding.HTML.Decode(Encoded);

  Writeln(Encoded); // &lt;p&gt;Tea &amp; coffee&lt;/p&gt;
  Writeln(Decoded); // <p>Tea & coffee</p>
end.

How to use this tool

  1. Choose a conversion. Select Encode HTML entities to turn characters such as < and & into entity text. Select Decode HTML entities to turn references such as &lt; and &#169; back into readable characters.
  2. Choose an encoding style if needed. In Encode mode, open Options to change the style. Keep HTML text (recommended) for ordinary text on a web page. Choose Text with quotes for quoted attribute values, or Extended entities when you need more characters converted. Options are hidden in Decode mode.
  3. Type or paste your text into Input. Output updates immediately as you type or change a setting. For example, encoding Tea & coffee produces Tea &amp; coffee; decoding that result restores the original text.
  4. Copy or reuse the result. Select Copy result beside Output. Inverse moves the result into Input without changing the conversion mode. To undo an encoding, switch to Decode after using Inverse. Clear beside Input empties both fields.

Choosing an encoding style

Modern HTML supports Unicode: accented letters, symbols, and emoji can stay readable in a UTF-8 page. HTML5 does not require converting them into entities. These options change how much is escaped, not which browser version you support. The HTML syntax reference describes the rules for text and attributes.

  • HTML text (recommended) is the default for text between tags, such as a paragraph. It escapes &, <, and > and writes non-breaking spaces as &nbsp;. Quotes and other Unicode characters stay unchanged. For example, café & tea © becomes café &amp; tea ©.
  • Text with quotes escapes &, <, >, and both quote types, using names that also work in XML. Choose it for text inside a quoted attribute such as title="...", or for XML text. Accented letters, emoji, and non-breaking spaces stay unchanged. It does not validate XML or make URLs and JavaScript safe.
  • Extended entities also converts non-ASCII characters into named or numeric references. For example, café © becomes caf&eacute; &copy;. Choose it when another system or your preferred source format calls for entity-based text; ordinary modern web pages do not need it.

The default also escapes > and non-breaking spaces for consistent output, although HTML does not always require this. For attribute values, use Text with quotes and keep the surrounding quotes in your markup. Decode recognizes HTML5 named and numeric references regardless of the encoding option you last used.

If the result is unexpected

Encoding text that already contains entities can encode it again: &amp; becomes &amp;amp;. Check whether your source needs decoding first. Decoding displays markup as text; it does not remove tags. If copying is unavailable, select the output and copy it with your keyboard or context menu.

Your tool data stays in your browser

This tool processes your data on your device. The text, files, or passwords you enter and the results it creates are not sent to our servers or any other server.

Page and asset requests still occur. Production pages also load Google Tag Manager and AdSense advertising; tool code does not send inputs or results to analytics or ads. See our privacy policy.

To inspect requests while using the tool, open your browser's developer tools and select Network. Try it with sample data.

Read How to check website network requests in Chrome, Firefox, Edge, and Safari.

Learn more and references

Premium is coming soon

An optional premium subscription to remove ads is planned. Subscriptions are not available yet.

You can keep using our free tools without an account.