FREE TOOL

HTML Encoder and Decoder: Encode and Decode HTML Entities

An HTML encoder converts characters that have special meaning in HTML, such as <, >, & and quotes, into entity codes like &lt; and &amp; so a browser shows them as text instead of reading them as code. The WritoryBuzz HTML encoder and decoder encodes and decodes in named, decimal and hex formats and includes attribute-safe and JS-string safe modes.

Paste text, choose Encode or Decode, pick a mode and click Run. A decoder reverses the process, turning entities back into readable characters.

Encode or decode HTML above
Quick start
1Paste your text
2Choose an encode mode
3Pick a format
4Click Run

Encode / Decode HTML

Input
Output

Entity Reference (common entities)

CharacterNamedDecimalHex
Copied to clipboard
Key Takeaway:: Minimal mode
encodes the five reserved characters: & < > " and '. Full mode also converts every non-ASCII character to a numeric entity. Encoding helps prevent XSS only when it matches the context where the data is placed. It is not a complete security solution. Double encoding (such as &amp;amp;) is a common bug. Smart Decode helps you fix it.

What Is HTML Encoding?

HTML uses certain characters as syntax. The less-than sign opens a tag, the ampersand starts an entity and quotes wrap attribute values. If you want to show those characters literally, such as a code sample or a user comment containing a tag, you replace them with entities. A browser then displays the character and does not treat it as markup.

An entity has three common forms, and all three display the same character:

CharacterNamedDecimalHex
& (ampersand)&amp;&#38;&#x26;
< (less-than)&lt;&#60;&#x3C;
> (greater-than)&gt;&#62;&#x3E;
" (double quote)&quot;&#34;&#x22;
' (single quote)&#39;&#39;&#x27;
(c) copyright&copy;&#169;&#xA9;
(R) registered&reg;&#174;&#xAE;
(TM) trademark&trade;&#8482;&#x2122;
Euro sign&euro;&#8364;&#x20AC;
Pound sign&pound;&#163;&#xA3;
Non-breaking space&nbsp;&#160;&#xA0;
Citable definition

HTML entity encoding replaces characters that have special meaning in HTML with entity references, such as &lt; for the less-than sign, so that browsers display them as text rather than interpreting them as markup.

How to Use the HTML Encoder and Decoder

  1. 1
    STEP 1 Paste your text into the Input box, or click a sample: Basic HTML, XSS test string, Non-ASCII text or Double-encoded.
  2. 2
    STEP 2 Choose an encode mode: Minimal (5 chars), Full (all non-ASCII), Attribute-safe or JS-string safe. Or choose Decode HTML, or Smart Decode for mixed or double-encoded text.
  3. 3
    STEP 3 Pick a format for the entities: Named, Decimal or Hex.
  4. 4
    STEP 4 Click Run. The result appears in the Output box.
  5. 5
    STEP 5 Copy the output with the Copy button.
Encode or decode HTML above

Choosing the Right Encoding Mode

ModeWhat it doesUse it when
Minimal (5 chars)Encodes & < > " and ' onlyShowing text inside HTML element content
Full (all non-ASCII)Also converts every non-ASCII character to a numeric entityYou need compatibility with older systems or an unknown character encoding
Attribute-safeAdds the extra encoding needed inside attribute valuesPutting text inside value="..." or title="..."
JS-string safeEscapes characters so text can sit in a JavaScript string literalYou must place text in a script string. Prefer safer patterns, see the XSS section.
Decode HTMLTurns named, decimal and hex entities back into charactersReading stored or scraped HTML
Smart DecodeHandles mixed and double-encoded inputYou see &amp;amp; or &amp;lt; in your text

Named vs decimal vs hex

Named entities are the easiest to read, but only common characters have names. Numeric entities, decimal or hex, work for any Unicode code point, so they are the safer default for full encoding. For the plain reserved characters, all three formats are equivalent in a browser.

HTML Encoding and XSS: What It Does and Does Not Do

Cross-site scripting (XSS) happens when a site puts untrusted input into a page in a way that the browser runs as code. If a comment contains <script>alert(1)</script> and you print it into the page as raw HTML, every visitor's browser may execute it. Encoding the input so that < and > become &lt; and &gt; makes the browser show the text and not run it.

That is real protection, but only for the context you encoded for. Security guidance, such as the OWASP Cross Site Scripting Prevention Cheat Sheet, stresses context-aware output encoding. The right encoding depends on where the data lands:

Where the data goesWhat is neededCommon mistake
HTML element contentHTML entity encoding of < > & and quotesNot encoding at all, or decoding before display
HTML attribute valueAttribute encoding, and always quote the attributeUnquoted attributes allow a space to start a new attribute
Inside a script block or inline event handlerJavaScript-specific escaping, or better, avoid putting data hereUsing HTML entities, which do not protect script contexts
URLURL (percent) encoding, and validate the schemeAllowing javascript: links
CSSCSS escaping, or avoid untrusted inputDropping user text into style attributes

In practice, do not rely on a manual web tool or a hand-written replace to protect an application. Use your framework's automatic output escaping, such as the default escaping in React, Django or Jinja2 templates, encode at the point of output and add defence in depth such as a Content Security Policy. This tool is for learning, debugging and one-off conversions. Treat the XSS test string sample as a way to see how encoding changes a payload, not as a security test of your site.

Encoding vs Escaping vs URL Encoding

  • HTML encoding makes text safe for display inside HTML.
  • URL encoding (percent encoding) makes text safe inside a URL, such as turning a space into %20. It is a different job.
  • Base64 is a way to represent binary data as text. It is not encryption and does not make anything safe.
  • Escaping is the general term for adding a backslash or code so a special character is treated literally. HTML entity encoding is one form.

Why You See &amp;amp; in Your Text

If you see &amp;amp; or &amp;lt; on a page, the text was encoded twice. It happens when data is encoded when saved and again when displayed, or when a CMS and a template both escape it. Use Smart Decode once to see the original, then fix the layer that encodes the second time. Decoding repeatedly in code to hide the problem can expose you to injection, so fix the source.

Who Uses an HTML Encoder and Decoder

Developers

Displaying user content or code samples safely.

Bloggers and technical writers

Showing HTML tags in a post without the tags rendering.

Email and newsletter builders

Dealing with special characters in templates.

SEO professionals

Cleaning titles and descriptions where an ampersand or quote appears as an entity. If you are writing meta tags, the Meta Tag Generator handles this for you.

Security learners

Studying how encoding changes an XSS payload.

Common Mistakes

  • Encoding twice. It produces &amp;lt; and similar garbage.
  • Encoding for the wrong context. HTML entities do not make data safe inside a script block.
  • Using a blocklist of bad words such as removing the word "script" instead of encoding output.
  • Leaving attributes unquoted. Encoding cannot save an unquoted attribute value.
  • Using &nbsp; for layout spacing. Use CSS for spacing. Non-breaking spaces are for keeping words together.
  • Decoding untrusted input and then inserting it as HTML. This undoes the protection.

Honest Limits of This Tool

  • It converts text. It does not scan your website for XSS or tell you whether your application is secure.
  • Encoding for one context does not protect another context.
  • Numeric entities are universally supported. Some named entities depend on the HTML version and the browser.
  • It handles the text you paste. Character encoding problems in your files, such as a wrong charset declaration, need fixing at the source. Make sure pages declare UTF-8.

Working with data formats too? Check and tidy payloads with the JSON Formatter, or compare two encoded versions with Text Compare.

Frequently Asked Questions

What is HTML entity encoding?

HTML entity encoding replaces characters that have special meaning in HTML, such as < and &, with codes like &lt; and &amp;. Browsers then show them as text and not as markup.

What are the five characters HTML encoding handles in minimal mode?

Ampersand, less-than, greater-than, double quote and single quote. These are the characters that can break out of text or attribute contexts.

Does HTML encoding prevent XSS?

It helps when it matches the context where the data is placed, such as HTML text or a quoted attribute. It does not protect script, URL or CSS contexts and is not a complete security solution on its own.

What is the difference between named, decimal and hex entities?

All three represent the same character. Named entities like &amp; are easiest to read. Decimal and hex numeric entities work for any Unicode character, including those without a name.

Why does my text show &amp;amp; or &amp;lt;?

It has been encoded twice. Decode it once with Smart Decode to see the original, then find which layer of your system is encoding again.

When should I use full encoding?

Use it when you need compatibility with older systems or an unknown character encoding, because it converts every non-ASCII character into a numeric entity. For modern UTF-8 pages, minimal encoding is usually enough.

What is the difference between HTML encoding and URL encoding?

HTML encoding makes text safe to display in a web page. URL encoding, also called percent encoding, makes text safe inside a web address. They use different formats.

How do I decode HTML entities?

Choose Decode HTML, paste the text and click Run. Named, decimal and hex entities all convert back to characters. Use Smart Decode for mixed or double-encoded input.

Is the HTML encoder and decoder free?

Yes. It is a free WritoryBuzz tool with no signup. Encode or decode your HTML now, and check the context before you trust the output in production.

Ready to try the HTML Encoder / Decoder?

Free to use. Open the tool and get your result in seconds.

Encode or decode HTML above
For contributors
Got something worth sharing? Write for us.

Original, well researched guides are always welcome here.

  1. 1Read the guidelines
  2. 2Send us your pitch
  3. 3Our editors review it