Tools
HTML entity encode
Encode text as HTML entities
Convert <, >, &, quotes and special characters into safe HTML entities.
Turns accents, ñ, emoji and so on into numeric entities, e.g. ñ → ñ.
About this tool
Whenever you want to show a code snippet on a web page, put text inside an attribute, or publish HTML in a CMS that would otherwise render it, the characters < > & and quotes have to be escaped as entities. That way the browser displays them literally instead of treating them as tags. It is also useful for email templates, XML feeds and technical documentation.
Type or paste your text into “Text to encode” and the entity-escaped result appears straight away: & becomes &, < becomes <, > becomes >, " becomes " and ' becomes '. Turn on “Also convert non-ASCII characters” to change accented letters, symbols and emoji into numeric entities such as é, handy when you don’t control the character encoding of the target document.
The conversion runs in your browser and your text isn’t sent anywhere. Escaping stops text being interpreted as HTML, but it is no substitute for the validation and output escaping your application should do on the server to prevent XSS. Named entities such as é are not generated: numeric ones are used because they work in both HTML and XML.
Frequently asked questions
Which characters must be escaped in HTML?
At minimum & and <, and it is wise to escape > as well. Inside attributes you also need to escape the quote that wraps the value (" or '). This tool always escapes all five.
Is é better than é?
Both display é. Numeric entities work in HTML and XML alike, whereas named ones rely on the reader knowing that name. If your page is served as UTF-8 you don’t need to escape é at all.
When should I turn on the non-ASCII option?
When the text is going somewhere that might not be UTF-8, such as an old email system, a legacy application or a file in another encoding. With numeric entities the output is pure ASCII and displays correctly regardless.
Does escaping entities protect my site from XSS?
It helps when you output text in the body or inside a quoted attribute, but it isn’t enough in every context, such as inline JavaScript or URLs. Real protection has to live in your application.