HTML Entity Encoder / Decoder

Encode or decode a documented HTML entity set as plain text. The result is never inserted into the page as HTML.

Last updated: October 5, 2026

Tool

This tool will load here.

What this tool does

This html entity encoder writes five characters as entities and decodes a documented set back to characters. Encode replaces ampersand, less-than, greater-than, double quote, and apostrophe. The apostrophe becomes ', not a named apostrophe entity. Ampersand is replaced first so the replacements are not encoded again.

Decode accepts & < > " and numeric character references in decimal or hexadecimal, including '. A named entity outside that list, such as nbsp or copy, is an error. The status names the entity and clears the result. This page does not claim to implement the full HTML named-entity list.

Decoding never assigns the string to innerHTML. The result is the value of a textarea. A decoded less-than, the word script, and a greater-than are characters in that value. They do not become a script element, and they do not run. Encode output is also a textarea value, so the entities you see are text you can copy into source, not markup the browser has already parsed.

Decode is one pass. A double-encoded sequence becomes a single-encoded sequence. Run Decode again if you wanted the next step. An ampersand that is not followed by a complete entity is left as text, and the status says sequences without a semicolon were left unchanged. A numeric reference outside Unicode, or a surrogate code point, is an error. The limit is 200,000 characters.

How to use

  1. Paste the text.
  2. Choose Encode or Decode.
  3. Read the result as text. Copy and Clear work on the boxes, not on the page around them.

Empty input is an error. Characters outside the five encode targets, including letters and emoji, stay as themselves when you encode. That is intentional. The page is not a general transliterator.

Example

Encoding a & b < c > "d" 'e' produces entities for each of those five characters. Decoding &lt;script&gt;alert(1)&lt;/script&gt; produces the characters less-than, script, greater-than, and the rest, visible in the result box and absent from the document as an element. Decoding &#65; or &#x41; produces A. Decoding &nbsp; stops because nbsp is not in the supported named set.

&lt;script&gt;

JSON string escaping is a different job. The JSON Escape / Unescape tool writes backslash escapes for a JSON string. It is linked here only as a contrast. Do not send HTML entities through it and expect HTML rules, and do not send JSON escapes through this page and expect JSON rules.

Limits

  • Named set: amp, lt, gt, quot, plus numeric references and '.
  • No innerHTML decode. Output stays text.
  • One pass. Unknown named entities are errors.
  • 200,000 characters. The text stays in this browser.

Numeric references can name a control character, including U+0000, when the code point is in range and is not a surrogate. The page will decode it into the textarea. It will not strip it. If you needed a filter for control characters, this is not that filter.

The hint under the buttons repeats the supported set so you do not have to scroll to this section while you are trying a string. If an entity you expected is missing, the honest result is an error, not a best-effort substitution from a larger table this page did not ship.

Copy copies the result box. If the box was cleared by an error, there is nothing to copy. Clear empties both boxes. Nothing is written to local storage or sent to a server.

On this page

Related Articles

Related guides

Related solutions

Need another tool ?

Open the free tools — no signup.

FAQs

newsletter signup

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
Innovative Solutions For Modern Needs
Copyright © 2026 Yallasolve. all rights reserved.