HTML Escape and Unescape — HTML Entity Encoder & Decoder

Escape text so it displays safely in HTML, convert text to HTML entities, or decode HTML entities back to plain text. Runs in your browser — the input is never uploaded.

What HTML escaping does

Five characters have a structural meaning in HTML. If they appear in text you want to display — a code sample, a user’s comment, a product name like Tom & Jerry — the browser may read them as markup. HTML escaping (also called HTML encoding) replaces each with an entity so it renders literally:

CharacterEntityWhy
&&Starts every entity; must always be escaped first.
<&lt;Would open a tag.
>&gt;Closes a tag; escaped for symmetry and old parsers.
"&quot;Ends a double-quoted attribute value.
'&#39;Ends a single-quoted attribute value (&apos; is HTML5 and XML only).

So <strong>Hello</strong> becomes &lt;strong&gt;Hello&lt;/strong&gt; and shows up on the page as the tag text rather than bold type.

Text to HTML entities (encode)

Choose Escape / Encode. Special chars only gives the five-character HTML escape above, which is all a UTF-8 page needs. Choose + non-ASCII to also turn accented letters, curly quotes, dashes, symbols and emoji into entities — useful for ASCII-only email templates, legacy CMS fields or source files. Every character encodes letters and digits too, as numeric entities.

The entity format decides how those characters are written: Named uses the mnemonic where one exists (&eacute;, &copy;, &mdash;, &euro;) and falls back to a numeric entity; Decimal gives &#233;; Hex gives &#xE9;. Characters outside the Basic Multilingual Plane, such as emoji, are encoded by their full code point (&#x1F600;), not as two surrogate halves.

HTML entities to text (decode)

Choose Unescape / Decode, or leave Auto-detect on and paste text that contains entities. The HTML decoder handles all 2,000+ HTML5 named entities (&nbsp;, &hellip;, &rarr;…), decimal entities (&#8364; → €) and hex entities (&#x20AC; → €). Tags in the input are left as text: decoding &lt;p&gt; gives you <p>, it does not render it.

Named vs numeric entities

CharacterNamedDecimalHex
non-breaking space&nbsp;&#160;&#xA0;
©&copy;&#169;&#xA9;
é&eacute;&#233;&#xE9;
—&mdash;&#8212;&#x2014;
“ ”&ldquo; &rdquo;&#8220; &#8221;&#x201C; &#x201D;
€&euro;&#8364;&#x20AC;
™&trade;&#8482;&#x2122;
→&rarr;&#8594;&#x2192;

XML only knows five named entities (&amp; &lt; &gt; &quot; &apos;), so choose Decimal or Hex when the output goes into XML, RSS or SVG.

Escaping HTML in code

JavaScript

const escapeHtml = s => s.replace(/&/g, "&amp;").replace(/</g, "&lt;")
  .replace(/>/g, "&gt;").replace(/"/g, "&quot;").replace(/'/g, "&#39;");

// decode every entity with the browser's own parser
const t = document.createElement("textarea");
t.innerHTML = "Caf&eacute; &amp; cr&#232;me"; t.value;   // "Café & crème"

Python

import html
html.escape('<a href="x">Tom & Jerry\'s</a>')   # quote=True escapes " and ' too
html.unescape("Caf&eacute; &#8364;5")              # 'Café €5'

PHP

htmlspecialchars($s, ENT_QUOTES | ENT_HTML5, 'UTF-8');   // escape
html_entity_decode($s, ENT_QUOTES | ENT_HTML5, 'UTF-8'); // decode
htmlentities($s, ENT_QUOTES | ENT_HTML5, 'UTF-8');       // encode non-ASCII too

Common questions

How do I convert HTML entities to text?

Paste the text and choose Decode (Auto-detect does this when it sees entities). Every named entity such as &lt;, &copy; or &nbsp;, and every numeric entity such as &#39; or &#x20AC;, is turned back into its character. If the result still contains entities, the text was encoded twice and a Decode again button appears.

Which characters must be escaped in HTML?

In text content, & and < must be escaped as &amp; and &lt;. Inside an attribute value, also escape the quote that delimits it: &quot; for double quotes and &#39; for single quotes. Escaping > as &gt; is not required but is common and harmless, so this tool escapes all five.

What is the difference between named and numeric HTML entities?

A named entity uses a mnemonic, like &eacute; for é. A numeric entity uses the Unicode code point, in decimal (&#233;) or hex (&#xE9;). Every character has a numeric form, but only about 2,000 have names. Numeric entities work everywhere, including XML, which only defines five named entities.

Do I need to encode accented letters and emoji?

Not if the page is served as UTF-8, which almost every modern page is. Encode non-ASCII characters only when the destination is not UTF-8 safe, such as an old email template, a legacy CMS field, or source code that must stay ASCII.

Is escaping HTML enough to prevent XSS?

Escaping protects HTML text and quoted attribute values. It does not make a value safe inside a script block, a style block, an unquoted attribute, or a URL such as a javascript: link. Use your template engine’s context-aware escaping and a Content Security Policy as well.

Is my text uploaded?

No. Encoding and decoding run in your browser. Nothing is sent to a server.