nicetool.dev logo

HTML Entity Encoder / Decoder

Escape text before inserting it into HTML to prevent broken markup and XSS.

Input
Result

Common entities

Click an entity to copy it.

What are HTML entities?

HTML entities are codes that represent reserved or special characters, such as &lt; for < and &amp; for &. Encoding user-provided text before rendering it as HTML keeps your markup valid and helps prevent cross-site scripting (XSS).

Features

  • • Encode only reserved characters or all non-ASCII characters
  • • Named, decimal and hexadecimal entity formats
  • • Decode every HTML5 named and numeric entity
  • • Quick reference of the most common entities

Local processing

Encoding and decoding happen in your browser. Your content is never sent to a server.

100% client-side.

How to use the HTML Entities

  1. 1

    Choose Encode to turn special characters into HTML entities, or Decode to turn entities such as &lt; or &#169; back into characters.

  2. 2

    For encoding, pick a mode: Basic escapes only & < > " and ', Named uses entities like &eacute;, Decimal and Hex turn every non-ASCII character into a numeric reference.

  3. 3

    Paste your text or HTML. The result updates instantly.

  4. 4

    Copy the output, or use "Use result as input" to chain operations. Click any entry in the reference table to copy a common entity.

Practical examples

Showing code on a web page

To display <div class="box"> as text in a blog post or documentation, encode it to &lt;div class=&quot;box&quot;&gt; so the browser does not treat it as markup.

Safe user content

Escaping user-provided text before inserting it into HTML prevents broken layouts and cross-site scripting (XSS). Basic mode covers the five characters that matter.

Fixing double-encoded text

Seeing &amp;amp; or &amp;quot; in a page or an RSS feed? Decode once or twice to find where the text was escaped too many times.

ASCII-only systems

Some email templates, legacy CMSs or XML feeds only accept ASCII. Decimal or Hex mode turns é, ñ or ữ into references like &#233; that survive any encoding.

Frequently asked questions

Which characters must be escaped in HTML?+

In text content, & and < must be escaped. Inside attribute values, also escape the quote character used around the value (" or '). Escaping > as well is a common, harmless habit.

Named or numeric entities?+

Both are rendered the same way. Named entities like &copy; are easier to read; numeric ones like &#169; work for every Unicode character, including those without a name.

Is HTML escaping enough to prevent XSS?+

It is the right defense for text placed between tags or inside quoted attributes. Text inside <script>, style, event handlers or URLs needs different, context-specific escaping, which modern frameworks handle for you.

Do I need entities for accented letters?+

Not if your page is served as UTF-8, which is the default today. Entities for letters like é are only needed for systems limited to ASCII.