HTML Entity Encoder & Decoder
Encode five special characters or decode HTML entities one layer
Paste HTML or entity-encoded text and convert it with auto-detection first; scenario guidance and fixes are available in Advanced mode.
—
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Encode replaces &, <, >, double quotes and single quotes with HTML entities. Decode resolves named HTML entities and decimal or hexadecimal character references once; it does not repeatedly decode nested content. Auto mode chooses decode when entity decoding changes the input, so choose a specific mode when the intended context matters. Advanced mode shows both forms plus an isolated preview of basic text, lists and tables. The preview removes links, images, styles, scripts and all element attributes; it is deliberately different from the source. This is text conversion, not a sanitizer for production HTML, JavaScript, CSS or URLs. Processing is local, and input drafts are not saved.
Scenario Recipes
Inspect one entity layer
Goal: Avoid unintentionally decoding data twice.
- Select Decode.
- Paste &lt; © 😀 and convert.
- Compare the raw output with the isolated basic-formatting preview.
Result: The output is < © 😀. A second decode would change the first item.
Failure Clinic (Common Pitfalls)
A decoded string is still untrusted markup
Cause: Entity decoding restores characters; it does not validate their destination context.
Fix: Keep the output as text, or apply the appropriate sanitizer before rendering it elsewhere.
Production Snippets
Worked example
text
input: &lt; © 😀
output: < © 😀Frequently Asked Questions
Which characters are encoded?
The encoder replaces & with &, < with <, > with >, double quotes with ", and single quotes with '.
Which entities can be decoded?
Named HTML entities and decimal/hexadecimal references are supported. For example, © A 😀 becomes © A 😀. Invalid references follow the HTML entity decoder’s replacement rules.
Does decoding repeat until no entities remain?
No. &lt; becomes < after one conversion. Decode again only when the data source explicitly contains another encoding layer.
Is the preview the full decoded page?
No. It is a sandboxed basic-formatting view with active resources and attributes removed. Copy uses the actual converted text, not the restricted preview.
Can entity encoding prevent every injection issue?
No. HTML text, HTML attributes, URLs, JavaScript and JSON have different escaping rules. Use the output only in an appropriate context and use a dedicated sanitizer when accepting untrusted HTML markup.
Keep browsing