Encoding · HTML

HTML entity encoder & decoder.

Escape text as HTML character references, decode &, © and &copy the way a browser does, and search every named entity below. Runs in your browser; nothing is sent anywhere.

Advertisement

Input

Result

Enter text and press Convert.

Worked example

Input: <a href="x?a=1&b=2">Café & Crème © 2026</a>

Decoding I'm &notit; I tell you, &copy 2026, &notin; &#128; as text content gives I'm ¬it; I tell you, © 2026, ∉ €. The first &notit; is not a known name, so the longest known prefix &not (a legacy form with no semicolon) is decoded and it; is left; &copy decodes without its semicolon; &#128; is remapped from the C1 control U+0080 to the euro sign, as the standard requires.

How the rules work

Encoding. The five characters that can end or start markup are &, <, >, " and '. They are always encoded, so the output is safe in element text and in quoted attribute values. The apostrophe is written &#39; rather than &apos; because &apos; is not in HTML 4. In "every non-ASCII character" mode, the named style picks one name per character when several exist (for example &nbsp; rather than &NonBreakingSpace;): names that also work without a semicolon first, then the shortest, then lower case first. Characters with no single-character name, such as most emoji, fall back to decimal numbers.

Decoding named references. The decoder takes the longest run of characters after & that is a key in the WHATWG table. That table has 2,231 keys: 2,125 end in a semicolon and 106 legacy keys (such as &amp, &copy, &nbsp, &lt) are also accepted without one. Inside an attribute value, a legacy match with no semicolon followed by = or a letter or digit is left alone, so ?a=1&copy=2 in a URL is not turned into a copyright sign. Pick "Attribute value" to apply that rule.

Decoding numbers. &#N; is decimal and &#xH; is hex; the semicolon is optional. Zero, values above U+10FFFF and surrogates become U+FFFD. Values 0x80 to 0x9F are mapped through the Windows-1252 table in the standard (so &#150; is an en dash), except the five that table leaves undefined.

Not covered. This is the character-reference step of the HTML parser, not a sanitizer. Escaping text for a JavaScript string, a CSS value, a URL or an XML document needs a different rule; entities such as &nbsp; are not valid in XML without a declaration.

Sources, as of 2026-10-01: entities.json and Named character references (WHATWG HTML Living Standard); Tokenization: named and numeric character reference states; Unicode Blocks.txt (the reference categories below are this tool's own grouping by Unicode block).

Named entity reference

All 2,125 named references from the WHATWG table. Search by name, by the character itself, or by code point (for example eacute, €, 20AC or U+20AC). A tick in the "No ;" column means the name also works without a trailing semicolon. 93 names expand to two code points.

Loading table…

Frequently asked questions

Which characters must I always escape?

In element text, & and < are required, and > is conventional. In a quoted attribute value, escape & and the quote character you used. Escaping all five, as the minimal mode does, is safe everywhere in text and attributes.

Do I need to escape non-ASCII characters?

Not if the page is served as UTF-8 (declare <meta charset="utf-8">). The non-ASCII mode is for ASCII-only channels, such as old email templates or systems that mangle encodings.

Why does &copy decode without a semicolon but &hearts does not?

Only 106 names are legacy forms from early HTML and are accepted without the semicolon. Everything else needs it. Always write the semicolon.

Does this make user input safe to put in a page?

It escapes text for HTML element content and quoted attributes only. It does not sanitize markup, and it is not enough inside script, style or unquoted attributes, or in URLs.

Conversion only

This tool converts text and mirrors the HTML standard's character reference rules. It is not a security sanitizer, and it does not check that your markup is valid.

Advertisement
Advertisement
Listening…