How to use
- Paste or type text into the input box.
- Select Encode to escape HTML special characters, or Decode to turn HTML entities back into characters.
- Use Copy output to copy the result.
What gets encoded
Encoding escapes exactly the five characters that have special meaning in HTML: & becomes &, < becomes <, > becomes >, " becomes " and ' becomes '. The result is safe to place in HTML text and in quoted attribute values.
Everything else — letters in any language, emoji, spaces and line breaks — is kept as is, because a UTF-8 page can contain these characters directly. Text that already contains entities is encoded again: < becomes &lt;.
What gets decoded
Decoding converts numeric references such as < and < for any Unicode character, and the named references & < > " and ' (plus their uppercase forms & < > "). A reference must end with a semicolon. Decoding is done once, so &lt; becomes <.
Other named entities such as or ©, numbers that are not valid Unicode characters, and references without a semicolon are kept exactly as written, and the tool tells you how many were left unchanged. Nothing is guessed.
Always plain text
The output is shown as plain text and is never rendered or run as HTML, so decoding <script> tags is safe. This tool escapes characters; it is not an HTML sanitizer and does not make untrusted HTML safe to render.
Input is limited to 5,000,000 characters, and encoded output to 20,000,000 characters.
FAQ
- Is my text uploaded?
- No. Encoding and decoding run entirely in your browser. Your text is not sent to a server, not stored, and not added to the page URL.
- Why is ' encoded as ' and not '?
- ' works in every version of HTML and XHTML, while ' is not defined in HTML 4. Both are decoded.
- Does encoding then decoding give back my original text?
- Yes. Decoding the encoded output always returns the original text. The reverse is not always identical: < decodes to <, which encodes as <.