%url-decoder.net

HTML Encode / Decode

Escape special characters to HTML entities, or decode entities back to plain text. Free and fully in your browser.

0 chars · 0 bytes
0 chars · 0 bytes

Everything runs locally in your browser. Nothing you type or upload is ever sent to a server.

What are HTML entities?

An HTML entity is a piece of text that stands in for a character: it starts with an ampersand and ends with a semicolon, like < for the less-than sign or é for é. Entities exist because some characters are instructions in HTML: a browser that meets a raw angle bracket starts reading a tag. Writing the entity instead tells the browser to display the character rather than obey it.

Escaping matters most for security. If user input is placed into a page without encoding, an attacker can submit markup that the browser will execute, the class of attack known as cross-site scripting. Encoding the five critical characters below turns injected markup into harmless visible text.

The five characters that must be escaped

CharacterNameEntityWhy
&Ampersand&Starts every entity, so it must always be escaped first
<Less-than&lt;Opens a tag; unescaped, it turns data into markup
>Greater-than&gt;Closes a tag
"Double quote&quot;Ends a double-quoted attribute value
'Single quote&#39;Ends a single-quoted attribute value

Frequently asked questions

What does HTML encoding do?
It replaces characters that have special meaning in HTML with entities, so they display as literal text instead of being interpreted as markup. The five that always matter are the ampersand, the two angle brackets, and both quote characters; this tool converts them to &amp;, &lt;, &gt;, &quot;, and &#39;.
When do I need to escape HTML?
Whenever text that is not meant to be markup ends up inside a page: user-generated content, code samples, text placed into attributes, or HTML snippets shown as examples. Escaping user content before rendering is the standard defense against cross-site scripting (XSS), because injected tags and scripts become harmless visible text.
What is the difference between &#39; and &apos;?
Both represent the single quote. &apos; is guaranteed in XML and modern HTML5 but was missing from HTML 4, so very old parsers may not understand it. The numeric form &#39; works everywhere, which is why this tool emits it when encoding.
Named or numeric entities: which should I use?
They decode to the same characters. Named entities like &eacute; are easier for people to read; numeric ones like &#233; (decimal) or &#xE9; (hex) work for every Unicode character including those without a name. When this tool encodes non-ASCII text it uses numeric entities because they are universally valid.
Does this tool decode every named entity?
Yes. Instead of shipping a fixed entity list, it asks your browser's own HTML parser to resolve each named entity, so everything in the WHATWG standard is supported, from &amp; to &hellip; to obscure math symbols. Unknown names are left unchanged, matching real browser behavior.
Is my text sent to a server?
No. Encoding and decoding run entirely in your browser with JavaScript. You can load the page, disconnect from the internet, and keep working.