100% private. Your text is processed entirely in your browser — nothing is uploaded, stored, or sent anywhere.
Developer / Code
Encode or decode HTML entities
Encoding turns the five unsafe characters (& < > " ') into entities so text displays safely in a page. Decoding reverses it.
Result
When NOT to use HTML Encoder & Decoder
- Encoding is for displaying text safely — it is not a substitute for proper output escaping in your application code, and it must never be applied twice (double-encoded text shows the entity literally).
- It only handles the core entities; it does not convert accented or symbol characters to named entities like é.
Questions people ask
Is my input sent to a server?
No. This tool runs entirely in your browser using JavaScript. Nothing you paste is uploaded, stored, or sent anywhere.
Which characters get encoded?
The five characters that are unsafe in HTML content and attributes: & < > " and '. They become & < > " and '.
When should I encode text as HTML entities?
Whenever you display user-provided or untrusted text inside a web page — encoding stops the browser from interpreting it as markup, which prevents broken layouts and XSS.
Related tools
Share this tool
Found it useful? Share it with someone who needs it — the tool is free and runs entirely in the browser.