HTML Entity Encode and Decode
Escape text so it displays literally on a web page, or turn &, é and € back into the characters they stand for.
HTML entities examples
| Text | Encoded |
|---|---|
| <script>alert(1)</script> | <script>alert(1)</script> Essential: Shown as text instead of being run |
| Tom & "Jerry" | Tom & "Jerry" Essential: & and quotes are escaped, letters are not |
| café £5 © | café £5 © Essential: Non-ASCII is left alone, which is fine on a UTF-8 page |
| café £5 © | café £5 © Named: Readable in the source |
| café £5 © | café £5 © Numeric: Understood by XML as well |
Encoding guides
How each one works, with worked examples.
Everything happens in your browser. What you type or paste is never uploaded, stored or added to the share link, so it is safe to use with tokens, keys and customer data.
Why HTML needs escaping
In HTML, < starts a tag and & starts an entity. To show either as an ordinary character it must be written as an entity: < and &. Inside an attribute value the quote that delimits the value needs the same treatment, " or '.
Escaping is also the main defence against cross-site scripting (XSS). If text that came from a user is put into a page without being escaped, a script tag in that text will run. Escaping the five characters & < > " and ' makes any text inert as HTML content or as a quoted attribute value. It is not enough on its own inside a script block, a style block or an unquoted attribute, which have their own rules.
Essential, named or numeric
On a page served as UTF-8, which is nearly all of them, only the five special characters need escaping, and that is what Essential does. Accented letters, currency signs and emoji can be left exactly as they are.
Named also converts non-ASCII characters to names where one exists (é, €, ©) and to numbers where it does not. Numeric uses the hexadecimal code point for every one (é). Both are for systems that are not safe for UTF-8, such as some email templates and old databases. Numeric entities are also valid in XML, which knows only five named entities.
Decoding
Decoding understands every entity name in the HTML5 standard (there are over 2,000), decimal entities such as € and hexadecimal ones such as €. Like a browser, it also accepts the older names without their closing semicolon (©, &,  ), since a lot of real-world HTML leaves it off.
One to watch for: decodes to a non-breaking space, which looks identical to a normal space but is a different character, and will not match a normal space in a search or a comparison.
Frequently asked questions
- Which characters must be escaped in HTML?
- & and < always. > is escaped by convention. Inside an attribute value, also the quote character around it: " as " or ' as ' (or ').
- What is the difference between ' and '?
- Both are an apostrophe. ' is valid in HTML5 and XML but was not in HTML 4, so older code uses the numeric ', which works everywhere.
- Why do I see &amp; on my page?
- The text was escaped twice, so the & of & became & again. Decode it once here to check, and remove one of the two escaping steps in your code.
- Do I need to encode accented letters and emoji?
- Not if the page is UTF-8, which is the default for HTML5. Use the Named or Numeric style only when the text passes through something that cannot handle UTF-8.
More bits and bobs
- JWT DecoderDecode a JSON Web Token to read its header, claims and expiry in plain English, and check an HMAC signature, without the token leaving your browser.
- Cron Expression BuilderBuild or decode a crontab schedule field by field, read it in plain English and see the next five runs in any time zone.
- Regex TesterTest a JavaScript regular expression on your own text with live highlighting, groups, replace, a plain-English explanation and code for six languages.
- UK Salary CalculatorTake-home pay after income tax, National Insurance, pension and student loans, with Scottish rates, tax codes, bonuses and overtime.