</>

HTML Entity Encoder & Decoder

Encode five special characters or decode HTML entities one layer

Regex & String
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026
Options
Input

Paste HTML or entity-encoded text and convert it with auto-detection first; scenario guidance and fixes are available in Advanced mode.

Conversion result
Encoded output
—
PreviewBasic formatting only; scripts, links, images and styles removed
Page reading mode

The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.

About this tool

Encode replaces &, <, >, double quotes and single quotes with HTML entities. Decode resolves named HTML entities and decimal or hexadecimal character references once; it does not repeatedly decode nested content. Auto mode chooses decode when entity decoding changes the input, so choose a specific mode when the intended context matters. Advanced mode shows both forms plus an isolated preview of basic text, lists and tables. The preview removes links, images, styles, scripts and all element attributes; it is deliberately different from the source. This is text conversion, not a sanitizer for production HTML, JavaScript, CSS or URLs. Processing is local, and input drafts are not saved.

Scenario Recipes

01

Inspect one entity layer

Goal: Avoid unintentionally decoding data twice.

  1. Select Decode.
  2. Paste &amp;lt; &copy; &#x1F600; and convert.
  3. Compare the raw output with the isolated basic-formatting preview.

Result: The output is &lt; © 😀. A second decode would change the first item.

Failure Clinic (Common Pitfalls)

A decoded string is still untrusted markup

Cause: Entity decoding restores characters; it does not validate their destination context.

Fix: Keep the output as text, or apply the appropriate sanitizer before rendering it elsewhere.

Production Snippets

Worked example

text

input:  &amp;lt; &copy; &#x1F600;
output: &lt; © 😀

Frequently Asked Questions

Which characters are encoded?

The encoder replaces & with &amp;, < with &lt;, > with &gt;, double quotes with &quot;, and single quotes with &#39;.

Which entities can be decoded?

Named HTML entities and decimal/hexadecimal references are supported. For example, &copy; &#65; &#x1F600; becomes © A 😀. Invalid references follow the HTML entity decoder’s replacement rules.

Does decoding repeat until no entities remain?

No. &amp;lt; becomes &lt; after one conversion. Decode again only when the data source explicitly contains another encoding layer.

Is the preview the full decoded page?

No. It is a sandboxed basic-formatting view with active resources and attributes removed. Copy uses the actual converted text, not the restricted preview.

Can entity encoding prevent every injection issue?

No. HTML text, HTML attributes, URLs, JavaScript and JSON have different escaping rules. Use the output only in an appropriate context and use a dedicated sanitizer when accepting untrusted HTML markup.

Keep browsing