Free HTML Encoder and Decoder
This free tool encodes text into HTML entities, turning characters such as less-than, greater-than, ampersand and quotes into safe codes, or decodes named and numeric entities back into readable characters. You can also encode every non-ASCII letter as a numeric entity. It suits anyone who needs to show code on a web page or clean up text full of codes such as & and ’.

HTML Encoder and Decoder
Generators and Converters
About this tool
In HTML, a few characters have a special meaning: the less-than sign starts a tag, the ampersand starts an entity, and quotes close attribute values. To show them as text, they are written as entities such as <, & and ". Forgetting this is the reason code samples vanish from a page or break its layout.
Encoding here replaces those five characters by default. Switching on the non-ASCII option also writes accented letters, symbols and emoji as numeric entities, which is useful for old systems and email templates that do not handle UTF-8 well. Decoding reverses the process and understands named entities like ©, decimal ones like ’ and hexadecimal ones like ’.
Encoding is not the same as sanitising. It makes text safe to display, but it does not clean untrusted HTML for storage. Output escaping belongs in your code, at the point where text is written into a page. Nothing you paste here is stored.
Frequently asked questions
Which characters does the encoder change?
By default five: ampersand, less-than, greater-than, double quote and single quote. These are the characters that can break markup or attributes. Turn on the non-ASCII option to also convert accented letters, symbols and emoji into numeric entities.
When should I encode text as HTML entities?
Whenever you show code, a tag or user-typed text inside a web page and want it displayed rather than run. It is also used for email templates and old systems that mishandle special characters. Modern pages served as UTF-8 do not need accented letters encoded.
Can it decode numeric and hexadecimal entities?
Yes. Named entities, decimal entities and hexadecimal entities are all understood, so the three different spellings of the copyright sign decode to the same character. Unknown names are left as they are, so nothing is lost.
Does encoding protect against cross-site scripting?
It is one part of the defence, when it is done at the moment text is written into a page and for the right context. Pasting text here once does not secure a site. Use your framework or language escaping function on every output.
