Text · Converter
Markdown to HTML converter.
Type or paste Markdown and watch the rendered page and the HTML source update as you go. CommonMark 0.31.2 with optional GitHub-style tables, task lists and strikethrough. Output is sanitised: raw HTML is escaped and unsafe links are refused. Runs in your browser; nothing is sent anywhere.
Input
Result
Type Markdown to see the preview.
What this converts
The converter is markdown-it 15.0.2 (MIT licence, bundled with this site, no network call) in its commonmark preset, which implements the CommonMark 0.31.2 specification. With the GitHub option ticked it also enables pipe tables and ~~strikethrough~~ from GitHub Flavored Markdown, and a small rule that turns - [ ] and - [x] list items into disabled checkboxes. All specification pages and the library repository were read on 1 October 2026.
How the output is sanitised
- Raw HTML is never passed through. The library runs with
html: false, so<script>,<img onerror=...>and any other tag you type is escaped and shown as literal text. That is stricter than CommonMark, which allows raw HTML, and it is why noon*attribute can reach the output. - Unsafe link targets are refused. markdown-it rejects
javascript:,vbscript:,file:and mostdata:targets, so[x](javascript:alert(1))stays as plain text instead of becoming a link. Imagedata:URLs are only allowed for GIF, PNG, JPEG and WebP. - One caveat: this is protection for the HTML this page generates. If you paste it into another system, that system's own sanitiser and content policy still apply, and the converter does not check where your
https:links point.
Worked example
Press Load example. The input is a heading, a two-item task list, a two-column table with a centred second column, a line with ~~old~~ **new** and a link, and two deliberately unsafe pieces: a <script> tag and a javascript: link. The output is an <h1>, a <ul> of two checkbox items (one checked), a <table> whose second column carries style="text-align:center", a paragraph with <s>old</s> <strong>new</strong> and a working link, and the script tag and the bad link as escaped, harmless text. Untick the GitHub option and the same input shows the strict CommonMark result: the table and strikethrough become plain text and the checkboxes become literal [x].
Where converters differ
Markdown has one specification but many renderers. Differences you may see elsewhere: the original Markdown.pl and some CMS plugins treat a single newline differently (tick the line-break option to match GitHub comments); GitHub adds autolinks, footnotes, alerts and emoji shortcodes that are not part of this page; and renderers that allow raw HTML will output tags this page escapes. If your Markdown relies on raw HTML, this page is not the right tool: it would need a separate, trusted sanitiser that you control.
Sources: CommonMark 0.31.2 (spec.commonmark.org); GitHub Flavored Markdown spec (github.github.com/gfm); markdown-it (github.com/markdown-it/markdown-it), all as of 1 October 2026.
Frequently asked questions
Why did my HTML tags show up as text?
On purpose. Raw HTML is escaped so a pasted document cannot run script in the preview or in the HTML you copy. Use Markdown syntax for formatting instead.
Is my text uploaded?
No. Conversion runs in your browser with a bundled library, and nothing is stored or sent.
Do tables work in plain CommonMark?
No. Tables, strikethrough and task lists are GitHub Flavored Markdown extensions, which is why they sit behind a checkbox.
Is the downloaded file a full web page?
It is a minimal HTML document wrapping the converted fragment, with a UTF-8 charset and no styles. Copy HTML gives just the fragment.
Sanitised, not certified
The output is built to be safe to display, but this page does not guarantee the Markdown, its links or the destination system are safe. Nothing you type is stored or sent anywhere.