HTML Entities Encode / Decode
Escape text for safe embedding in HTML — or turn entities like & back into characters.
When to escape HTML
Any time user-supplied text is placed inside an HTML page — comments, titles, code samples —
the characters & < > and quotes must become entities, or you risk broken markup
and cross-site scripting (XSS). Decoding reverses the process: named entities
(&amp; &lt; &nbsp; …) and numeric forms (&#169;,
&#x27;) are resolved via the browser's own parser, so the full entity table is supported.
FAQ
Does the non-ASCII option help with old systems?
Yes — encoding every character above U+007F as a numeric entity makes the output safe for pipelines that assume ASCII-only input.
Is my data uploaded?
No. Encoding and parsing run locally.
Encode / Decode — FAQ
Is Encode / Decode free to use?
Yes. It is completely free, with no signup, no installation and no usage limits.
Is my data uploaded to a server?
No. The tool runs entirely in your browser — the data you paste or upload never leaves your device.
Does it work on mobile devices?
Yes. It works in any modern desktop or mobile browser, with nothing to install.