Skip to content
Convertto

HTML Entity Encoder & Decoder

Convert characters to HTML entities and back — escape markup safely for display.

To encode HTML entities, paste text containing angle brackets, ampersands or quotes and they are replaced with safe entity references. This is the standard defence against cross-site scripting when displaying untrusted content inside a web page.

Runs in your browser
Privacy
Runs entirely in your browser — nothing is uploaded
Cost
Free, unlimited, no sign-up

Frequently asked questions

Which characters must be escaped in HTML?

At minimum < > & in text content, plus quotes inside attribute values. Failing to escape & silently breaks entities, and failing to escape < is how untrusted content becomes executable script.

How to use the html entity encoder & decoder

  1. 1Enter or paste your text or html.
  2. 2Choose the direction.
  3. 3Turn "Encode all non-ASCII" on or off as needed.
  4. 4The result appears immediately — copy or download it.

Embed this tool

Put the working html entity encoder & decoder on your own site. It runs in your visitors' browsers exactly as it does here — free, no account, nothing uploaded.

Share this tool

Last updated

More encoders & decoders