◆ Online Dev Kit

HTML Entity Encode / Decode

Escape and unescape HTML special characters.

About this tool

HTML entity encoding converts characters like <, >, & and quotes into their safe entity equivalents so they display as text instead of being parsed as markup. This is essential for preventing broken layouts and XSS when showing user content. Everything runs locally.

Common use cases

How it works

HTML entity encoding replaces special characters with named or numeric entity references. The five core entities are: & → &, < → <, > → >, " → ", and ' → '. Named entities use mnemonic names (© for ©), numeric entities use decimal (©) or hex (©). Decoding reverses this process, replacing entity references with their corresponding Unicode characters. This ensures special characters display correctly in HTML without being interpreted as markup.

FAQ

Why escape HTML?

To display characters like < and > as text and to prevent user input from injecting markup or scripts (XSS).

Which characters get encoded?

The five key ones: &, <, >, double quote and single quote. Decoding handles all named and numeric entities.

Do I need to encode all special characters?

No. Only <, >, &, ", and ' are strictly required for HTML safety. Other characters like ©, é, or emoji can be used directly in UTF-8 HTML, but entities are useful for characters hard to type or for compatibility.

What is the difference between   and a regular space?

  (non-breaking space) prevents line wrapping at that position and is not collapsed by HTML whitespace rules. Regular spaces are collapsed and allow line breaks. Use   to keep words together or add intentional spacing.