This html entity encoder writes five characters as entities and decodes a documented set back to characters. Encode replaces ampersand, less-than, greater-than, double quote, and apostrophe. The apostrophe becomes ', not a named apostrophe entity. Ampersand is replaced first so the replacements are not encoded again.
Decode accepts & < > " and numeric character references in decimal or hexadecimal, including '. A named entity outside that list, such as nbsp or copy, is an error. The status names the entity and clears the result. This page does not claim to implement the full HTML named-entity list.
Decoding never assigns the string to innerHTML. The result is the value of a textarea. A decoded less-than, the word script, and a greater-than are characters in that value. They do not become a script element, and they do not run. Encode output is also a textarea value, so the entities you see are text you can copy into source, not markup the browser has already parsed.
Decode is one pass. A double-encoded sequence becomes a single-encoded sequence. Run Decode again if you wanted the next step. An ampersand that is not followed by a complete entity is left as text, and the status says sequences without a semicolon were left unchanged. A numeric reference outside Unicode, or a surrogate code point, is an error. The limit is 200,000 characters.
Empty input is an error. Characters outside the five encode targets, including letters and emoji, stay as themselves when you encode. That is intentional. The page is not a general transliterator.
Encoding a & b < c > "d" 'e' produces entities for each of those five characters. Decoding <script>alert(1)</script> produces the characters less-than, script, greater-than, and the rest, visible in the result box and absent from the document as an element. Decoding A or A produces A. Decoding stops because nbsp is not in the supported named set.
<script>
JSON string escaping is a different job. The JSON Escape / Unescape tool writes backslash escapes for a JSON string. It is linked here only as a contrast. Do not send HTML entities through it and expect HTML rules, and do not send JSON escapes through this page and expect JSON rules.
Numeric references can name a control character, including U+0000, when the code point is in range and is not a surrogate. The page will decode it into the textarea. It will not strip it. If you needed a filter for control characters, this is not that filter.
The hint under the buttons repeats the supported set so you do not have to scroll to this section while you are trying a string. If an entity you expected is missing, the honest result is an error, not a best-effort substitution from a larger table this page did not ship.
Copy copies the result box. If the box was cleared by an error, there is nothing to copy. Clear empties both boxes. Nothing is written to local storage or sent to a server.
Encodes ampersand, less-than, greater-than, double quote, and apostrophe. Apostrophe is written as '. Decode accepts & < > " ' and numeric references such as A and A. Other named entities are an error. The result stays plain text. Limit: 200,000 characters.
No. Named decoding is amp, lt, gt, and quot. Numeric references, including numeric 39 for an apostrophe, are also decoded. The named entity nbsp is an error.
No. The result is placed in a textarea as text. The page does not assign it to innerHTML.
JSON Escape writes JSON string escapes such as a backslash followed by n. This page writes HTML entities.
One pass. A double-encoded less-than becomes a single less-than entity. Run Decode again if you want the second step.