🇬🇧EN

HTML Encoder / Decoder

Escape or unescape HTML entities — in your browser, nothing uploaded.

✨ What do you want to try next?

You've finished this tool — here are a few you might find useful.

Explore 100+ free toolsPDF, Image, Text, Convert, Calculate and more — all free.View all tools →

About the HTML Encoder / Decoder

This escapes the characters that have special meaning in HTML — <, >, &, ", ' — into their entity equivalents so they display as literal text instead of being interpreted as markup, and decodes entities back the other way. Developers and writers use it to show code samples on a web page without the browser rendering them, to safely drop user-supplied text into HTML, to fix double-encoded content, or to read what an entity-laden string actually says.

How it works

  • Encode replaces the five markup-sensitive characters with their standard entities: & → &amp;, < → &lt;, > → &gt;, " → &quot;, ' → &#39;. Doing & first prevents double-escaping the others.
  • Decode uses the browser's own HTML parser to resolve entities, so it understands not just those five but named entities like &copy; and &nbsp; and numeric ones like &#8212;, turning them back into the real characters.

Both run live as you type.

Assumptions and behaviour

  • Encoding targets the five special characters that matter for HTML safety and display; ordinary letters, digits, punctuation and non-ASCII text are left as-is (they don't need escaping in a UTF-8 page).
  • Decoding is browser-powered, so it handles the full range of named and numeric HTML entities, not just the five the encoder produces.
  • Escaping both quote types (" and ') makes the output safe to place inside HTML attribute values as well as body text.

Limitations

  • Encoding doesn't convert non-ASCII to numeric entities. Accented letters and emoji are left as literal characters, which is correct for a UTF-8 page but not what you'd want if you specifically need an ASCII-only, fully-entity-encoded output.
  • It's HTML escaping, not sanitisation. Escaping makes text safe to display; it does not clean or validate a block of HTML you intend to render as markup.
  • Decoding interprets any entity it recognises, so partial or malformed entities may resolve in ways the browser deems reasonable rather than erroring.

Privacy

Encoding and decoding run entirely in your browser. Your text is never uploaded or stored.

Frequently asked questions

Is this HTML encoder free?

Yes — free, no sign-up, no limits, runs in your browser.

Which characters does it escape?

The five that matter for HTML: & becomes &amp;, < becomes &lt;, > becomes &gt;, " becomes &quot;, and ' becomes &#39;.

Can it decode named entities like &copy; and &nbsp;?

Yes. Decoding uses the browser's HTML parser, so it resolves named and numeric entities, not just the five the encoder outputs.

Why weren't my accented characters turned into entities?

Encoding only escapes the five markup-sensitive characters. Accents and emoji are valid as-is in a UTF-8 page, so they're left literal.

Is this the same as sanitising HTML?

No. It escapes characters so text displays safely; it doesn't clean or validate HTML you plan to render as markup.

Can I safely put the output in an attribute?

Yes. Because both quote characters are escaped, the encoded text is safe inside HTML attribute values as well as body text.

Is my text uploaded?

No. Everything runs locally in your browser; nothing is sent or stored.

Lakshay Kumar

Written by Lakshay Kumar(TechLakshay)

A QA Automation Engineer by trade, Lakshay's real passion is untangling complex problems into simple, working solutions — which is exactly why FreeMyTask exists. On Instagram, he channels that same instinct into helping 26,000+ content creators with SEO education, motivation, and hands-on query solving.

Last updated: August 22, 2026
🎁