All tools run in your browser — your files never leave your device.
All tools154

Developer & Security

HTML Entity Encoder

Encode and decode HTML entities, named or numeric.

What it does. HTML entities represent characters that would otherwise be parsed as markup. Only five characters strictly need escaping in HTML, and escaping only those keeps text readable — escaping every accented letter and emoji makes the source unreadable for no benefit.
Runs in your browserNothing uploadsNo signupWorks offline

How to use HTML Entity Encoder

  1. Paste text or entities in.
  2. Choose encode or decode, and named or numeric.
  3. Copy the result.

Escape what needs escaping, not everything

Many encoders convert every non-ASCII character to an entity, turning readable text into a wall of numeric codes. On a modern UTF-8 page that achieves nothing — the browser renders an accented letter perfectly well as itself.

The characters that genuinely need escaping are the ones the parser would otherwise treat as markup.

The minimal mode here escapes only those. It produces output a human can still read and diff, which matters when the escaped text ends up in a template that someone has to maintain.

Escaping is context-dependent

Escaping is context-dependent
ContextWhat is dangerousEscaping needed
HTML textLess-than and ampersandHTML entities
Attribute valueQuotes as wellEntities including the quote
Inside a URLReserved charactersPercent-encoding, not entities
Inside JavaScriptQuotes, backslashes, a closing script tagJS escaping, not entities
Inside CSSBackslashes and quotesCSS escaping

This table is the important part. HTML entity encoding is the right defence in HTML text and attributes and the wrong one everywhere else — entity-escaping a string that lands inside a script block does not make it safe, and can break it.

Named against numeric

Named entities are readable; numeric ones are universal. Named entities beyond the original handful depend on the parser knowing them, which is reliable in HTML5 and much less so in XML.

XML defines only five named entities — anything else must be numeric or explicitly declared.

That is the practical rule: named for HTML, numeric for XML and for anything that might be processed by a stricter parser than a browser. Using a non-breaking space entity by name in XML is a common and confusing failure.

Frequently asked questions

Which characters need HTML escaping?

Strictly five: ampersand, less-than, greater-than and both quote characters. Ampersand and less-than always; the quotes matter inside attribute values. Escaping accented letters and emoji is unnecessary on a UTF-8 page.

What is the difference between named and numeric entities?

Named entities are readable; numeric ones are universal. HTML5 knows thousands of names, but XML defines only five — so use numeric form for XML.

Does HTML escaping prevent XSS?

In HTML text and attribute values, correct escaping is the right defence. It is not sufficient inside script blocks, URLs or CSS, which need their own escaping — the context determines what is dangerous.

Why did a named entity break my XML?

Because XML defines only five named entities. Anything else must use the numeric form or be declared, which is why a non-breaking space by name fails.

Should I escape every non-ASCII character?

No. On a UTF-8 page the browser renders them correctly as themselves, and encoding them makes the source unreadable and harder to diff for no benefit.