Output encoding
HTML escaping: encode for the destination context
HTML character references can represent syntax-sensitive characters such as ampersands and angle brackets. Encoding is useful only when it matches the exact output context. It does not remove malicious meaning, validate a URL, or sanitize markup.
Encode data at the HTML output boundary
For HTML text, encode at least &, <, and > before inserting untrusted data. This tool also encodes both quote characters, so its default output can be used as text or as a value inside a properly quoted HTML attribute. Keep the surrounding quotes; an unquoted attribute follows different parsing rules.
Do not encode a whole template or trusted markup. Modern frameworks normally escape interpolated text already; manually encoding before the framework can produce visible & sequences after a second layer.
Change encoders when the context changes
HTML encoding is not the right defense inside JavaScript, CSS, an event-handler attribute, or a URL. Use the framework or API designed for that context. A URL-valued attribute also needs an allowed scheme and destination check: encoding javascript:alert(1) does not make that URL safe.
When you intentionally allow user-authored HTML, use a maintained HTML sanitizer with an explicit allowlist. Showing decoded text in a text area is safe here because the result is assigned as text and never inserted into the page as executable markup.
Decode one layer and inspect what appears
The decoder follows the browser's HTML parser for named, decimal, and hexadecimal character references. Unknown references remain literal. It decodes exactly once: &lt; becomes <, not <. Repeated decoding can unexpectedly reveal syntax and is a common source of filter bypasses.
The optional non-ASCII mode converts each Unicode code point to a decimal character reference. It preserves supplementary characters such as emoji as one code point, but usually makes text harder to read and is not required for UTF-8 HTML. Use it only when a receiving system explicitly requires ASCII-only source.
Keep the result local and bounded
Input and output stay in this browser and are not stored or added to the URL. The tool accepts up to 1 MiB of UTF-8 input and stops before an output exceeds 8 MiB. Editing, swapping, or clearing invalidates the previous result.
Encoding or decoding success proves only that the transformation completed. Review the final template, attribute quotes, URL policy, framework behavior, and browser rendering before shipping.
<p title="Tom & Jerry"><strong>Hello</strong></p>Data provenance