← All tools

HTML Entity Encoder & Decoder

Encode HTML-sensitive text or decode one layer of character references locally, without rendering the result as markup.

Your text stays in this browser. Input limit: 1 MiB; output limit: 8 MiB. 0 characters.

Not a sanitizer: the result is not safe for JavaScript, CSS, URLs, event handlers, or unquoted attributes.

Enter text, then choose encode or decode.

How to use this tool

Encode untrusted text for an HTML text or quoted-attribute context, or decode one layer to inspect copied source. Review the destination context before using the result.

When not to use it

This is not a sanitizer and does not make text safe for JavaScript, CSS, URLs, event handlers, or unquoted attributes.

Read the guide →