HTML Entities: Encode & Decode
Escape text so it displays as text in HTML, or turn &-style entities back into readable characters.
Common entities reference
| Char | Named | Numeric | What it is | Copy |
|---|
Nothing matches that filter.
Free forever, no sign-up and no limits, and this tool installs on its own so you can keep it on your home screen.
Encode text so a browser displays it instead of interpreting it (& to &amp;, < to &lt;) or decode entity soup back into readable characters. Choose how much gets encoded: just the five structural characters, only accented and special characters, or everything, as named entities or numeric codes. Decoding is handled by the browser's own parser so every named and numeric entity works, and a searchable reference table keeps the entities everyone forgets one tap away.
How to use it
- Pick direction and scopeEncode to make text safe for HTML, choosing minimal, non-ASCII only, or everything, as named or numeric entities. Decode to make escaped text readable again.
- Paste the textCode samples, scraped content, CMS exports, the result updates as you type.
- Copy or chainCopy the result, feed it back as input for multi-layer messes, or grab a single entity from the reference table.
Text that talks about markup
HTML has a bootstrapping problem: the characters that define its structure sometimes need to appear as ordinary text. A tutorial showing a <div> must stop the browser building one. Entities are the escape hatch, write the character as a name or number, and the parser renders it without acting on it. Every code example on every documentation page passes through this transformation, which is why encode mode exists.
The archaeology of decode mode
Decode traffic comes from data that has been through too many systems. Feeds escape their content; databases store the escaped form; another layer escapes it again on the way out. The result reads like &#8217;, an apostrophe wearing three coats. Because this tool decodes with the browser's own parser, it understands the full entity vocabulary, named, decimal, hex, and repeated passes peel one layer each, so even multi-encoded text unwinds cleanly. When text looks like that, resist fixing it downstream: find which system double-escapes, and use this to verify the layers while you hunt.
The entities everyone looks up
Below the tool sits a reference table of the entities people actually search for: arrows, the two dashes, curly quotes, currency signs, the comparison operators. Each row shows the character, its named form, its numeric form and a copy button, and the filter box narrows it as you type. It exists because the usual alternative is a search engine round trip for a single →, and because seeing the named and numeric forms side by side is the fastest way to learn the vocabulary.
Questions people ask
Which characters need encoding in HTML?
Five do the structural work: & < > " and '. The angle brackets open tags, the ampersand opens entities, and the quotes end attribute values. Encode those five and any text can sit safely in a page; this tool encodes exactly them, leaving everything else readable.
Why does &amp; appear on web pages sometimes?
Double encoding: text was encoded twice, so the ampersand of & got encoded again. It usually happens when two systems each 'helpfully' escape. The fix is decoding one layer, paste it here in decode mode and each pass unwraps one level.
What is the difference between ' and '?
The same apostrophe, numerically and by name. The numeric form works everywhere; ' was technically absent from old HTML4, which is why careful encoders (this one included) emit ' instead. Decoding accepts both, and every other named or numbered entity, because the browser's own parser does that work.
When do I meet entities in the wild?
Displaying code snippets on a page, content pulled from feeds and APIs that arrives pre-escaped, CMS database exports, and email templates. Decode direction gets the most traffic: turning &eacute; soup from a feed back into é.
Does this protect against XSS?
Encoding output correctly is one real part of XSS defence, untrusted text rendered into HTML must be escaped exactly like this. But security escaping belongs in your framework's templating, which does it automatically and contextually. Use this tool to understand and repair text, not as a security layer.
What do the three encoding scopes do?
Minimal encodes only the five structural characters, the right choice for embedding text in HTML. Non-ASCII only leaves those five alone and encodes accented and special characters (é, €, arrows), useful when a system mangles anything beyond plain ASCII but the markup must survive. Everything does both, producing output that is safe in HTML and survives any ASCII-only pipeline.
Named or numeric entities, which should I pick?
They decode identically, so it is about who reads them before the browser does. Named entities (&mdash;, &euro;) are readable by humans in source code. Numeric ones (&#8212;, &#8364;) work for every character that exists, including the thousands with no name, and are safer for very old or non-HTML consumers. The tool uses names where a common one exists and falls back to numbers, or gives you all-numeric output on request.
Do I still need entities in modern HTML?
For the structural characters, always. For everything else it is now optional: pages are served as UTF-8, so a euro sign or an arrow can sit in the source as itself. Entities stay useful when a file has to survive something that mangles anything outside plain ASCII.