Free online HTML entities converter. Encode special characters to HTML entities or decode entities back to readable text. Supports named entities (&), numeric decimal (&), and hex (&) formats. Essential for web developers sanitizing user content and preventing XSS. 100% browser-based.
100% browser-based — your data never leaves your device
Encode or decode HTML entities (& < > ") instantly.
Toggle between Encode (text to entities) and Decode (entities to text) mode.
Type or paste the text or HTML entities you want to convert.
Click Copy to grab the encoded or decoded output for your HTML or application.
Drop a file here or click to browse
Ctrl+Enter to encode
Count words, characters, sentences, and paragraphs in your text instantly.
Character CounterCount characters, words, sentences, and paragraphs in your text with real-time character analysis.
Slug GeneratorGenerate URL-friendly slugs from any text. Supports multiple separator styles.
Lorem Ipsum GeneratorGenerate placeholder text for your design and development projects.
URL Encode/DecodeEncode or decode URLs and query strings with proper percent-encoding.
URL Query ParserParse URL query parameters into a readable key-value table.
Diff CheckerFind differences between two texts with line-by-line highlighting.
Case ConverterConvert text between uppercase, lowercase, title case, sentence case, and more.
Base64 Encode/DecodeEncode or decode Base64 text instantly in your browser.
Regex TesterTest regular expressions with real-time matching, syntax highlighting, and cheat sheet.
Markdown PreviewWrite and preview markdown with live HTML rendering.
Markdown EditorWrite and preview markdown with live HTML rendering and syntax highlighting.
Reserved characters like ampersands, angle brackets, and quotes cannot simply sit inside HTML without being escaped, or the browser will interpret them as markup. This converter performs that escaping and reverses it on demand:
Encoding and decoding happen locally in your browser. Your content never reaches a server.
The most important use is security: escaping special characters in user-generated content before it is rendered is how you prevent cross-site scripting attacks. When a comment form, a profile field, or an admin panel accepts input and displays it back, converting angle brackets and quotes to their entity forms stops that input from being executed as HTML. The tool makes the transformation concrete, so you can see a dangerous string like a script tag become inert text.
The same escaping is needed any time you want HTML tags to display as visible text rather than render. Documentation that teaches HTML, code samples shown inside a page, and articles that print tags in a paragraph all rely on entities so the browser shows the angle brackets instead of acting on them. Instead of hand-writing < and > for every tag, you paste the block in, encode it, and copy the result.
Scraping and content extraction use the decode direction. Pulled pages and feeds are full of named and numeric entities, and decoding them produces clean, readable text for analysis, reprinting, or storage. Supporting both named entities like & and numeric references like & means whatever a parser threw at you comes back as the character it represents.
The content you escape is often the very thing that would be dangerous if it executed: user comments, form submissions, and pasted snippets that may contain malicious markup or private information. Sending that content to an online converter for inspection creates an odd situation where the data you are trying to neutralize is copied into a third party's logs.
Because conversion happens entirely in your browser, your user-generated content and HTML snippets never leave your device. You can escape a suspicious payload or a private block of markup without that material being stored or reviewed anywhere else.
Toggle between Encode (text to entities) and Decode (entities to text) mode.
Type or paste the text or HTML entities you want to convert.
Click Copy to grab the encoded or decoded output for your HTML or application.
Practical examples to help you get the most out of HTML Entities Converter:
Input: 'John & Jane said <hello>' Encoded: 'John & Jane said <hello>'
Input: 'The cost is £10 & €12' Decoded: 'The cost is £10 & €12'
If your content already contains &, encoding again will produce &amp;. Check if the text is already encoded before processing.
HTML entities are for HTML documents only. For JSON APIs, use JSON escape sequences (\u003C instead of <).
HTML entities are special codes that represent reserved characters in HTML. For example, & represents &, < represents <, and > represents >.
Encode HTML entities when displaying user-generated content to prevent XSS attacks, or when you need to show HTML tags as visible text rather than rendered markup.
Named entities use readable names like & (for &). Numeric entities use decimal or hex references like & or &. Both produce the same character.
No. All encoding and decoding happens locally in your browser.
Encode special characters to HTML entities or decode entities back to characters.
Uses standard HTML named entities where available for readability.
Also supports numeric character references ({) for full Unicode.
See results update as you type with instant copy support.
HTML Entities Converter is useful in a variety of scenarios across different workflows:
Escaping special characters in user-generated content for XSS prevention
Converting text for display in HTML emails and web pages
Decoding HTML entities from scraped content for clean text extraction
Always encode HTML entities in user-generated content before rendering to prevent XSS attacks. This converts < and > to < and >.
Named entities like & are easier to read in source code. Numeric entities like & are more universally supported across different parsers.
Explore more tools in the Content Workspace workspace:
Prompt Formatter
Format and structure AI prompts with markdown preview and template variables.
AI Response Comparator
Compare AI model outputs side by side for quality evaluation.
JSON Explainer
Get a plain-English explanation of any JSON structure, including fields, types, and nesting.
JSON Schema to Prompt
Convert JSON schemas into structured AI prompts for structured output generation.
Keyword Density Analyzer
Analyze keyword frequency and density in any text for SEO optimization.
Word Counter
Count words, characters, sentences, and paragraphs in your text instantly.