Skip to content
Bai
EspañolEnglishEuskara Get started →

Tools

HTML entity encode

Encode text as HTML entities

Convert <, >, &, quotes and special characters into safe HTML entities.

Private by design

Turns accents, ñ, emoji and so on into numeric entities, e.g. ñ → &#241;.

Encoding always escapes & < > " and '. Decoding recognises every HTML5 named entity plus decimal (&#241;) and hexadecimal (&#xF1;) numeric entities.

About this tool

Whenever you want to show a code snippet on a web page, put text inside an attribute, or publish HTML in a CMS that would otherwise render it, the characters < > & and quotes have to be escaped as entities. That way the browser displays them literally instead of treating them as tags. It is also useful for email templates, XML feeds and technical documentation.

Type or paste your text into “Text to encode” and the entity-escaped result appears straight away: & becomes &amp;, < becomes &lt;, > becomes &gt;, " becomes &quot; and ' becomes &#39;. Turn on “Also convert non-ASCII characters” to change accented letters, symbols and emoji into numeric entities such as &#233;, handy when you don’t control the character encoding of the target document.

The conversion runs in your browser and your text isn’t sent anywhere. Escaping stops text being interpreted as HTML, but it is no substitute for the validation and output escaping your application should do on the server to prevent XSS. Named entities such as &eacute; are not generated: numeric ones are used because they work in both HTML and XML.

Frequently asked questions

Which characters must be escaped in HTML?

At minimum & and <, and it is wise to escape > as well. Inside attributes you also need to escape the quote that wraps the value (" or '). This tool always escapes all five.

Is &eacute; better than &#233;?

Both display é. Numeric entities work in HTML and XML alike, whereas named ones rely on the reader knowing that name. If your page is served as UTF-8 you don’t need to escape é at all.

When should I turn on the non-ASCII option?

When the text is going somewhere that might not be UTF-8, such as an old email system, a legacy application or a file in another encoding. With numeric entities the output is pure ASCII and displays correctly regardless.

Does escaping entities protect my site from XSS?

It helps when you output text in the body or inside a quoted attribute, but it isn’t enough in every context, such as inline JavaScript or URLs. Real protection has to live in your application.

Related tools