Developer tool / 10

HTML Encoder and Decoder

Escape HTML-sensitive characters or decode named and numeric entities.

HTML Encoder and Decoder: TOEA escapes ampersands, angle brackets, quotes, and apostrophes, and decodes common named plus numeric Unicode entities. Runs 100% locally in your browser with zero server file uploads.

Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
HTML entity codecLocal processing

Runs entirely in your browser

Where encoding is not enough

Encoding makes text display as text in element content and in quoted attribute values. It does nothing for a URL: javascript:alert(1) contains no special characters, so it passes through unchanged and still runs when placed in an href. Check that links start with https: or /. Inside <script>, <style>, and on… event attributes different escaping rules apply, and a query-string value needs percent-encoding with the URL encoder before it goes into an attribute.

What the decoder recognises

Every numeric entity is decoded, but only six named ones: &amp;, &lt;, &gt;, &quot;, &apos;, and &nbsp;. Others, such as &eacute;, &copy;, or &mdash;, are left as written. HTML defines more than two thousand names, so replace unfamiliar ones with their numeric form, such as &#233; for é.

Text like &amp;lt; means it was encoded twice. Decode once, check, and decode again if entities remain.

How to use it

  1. Choose Encode or Decode.
  2. Paste text or entities.
  3. Transform and copy the result.

Privacy & limitations

Processing is local. Entity encoding is context-sensitive and is not a complete substitute for secure templating.

Related tools

Frequently asked questions

Does encoding make arbitrary HTML safe?

It safely represents common text characters, but application security still depends on the exact HTML, attribute, URL, or script context.

Are hexadecimal entities supported?

Yes. Decimal and hexadecimal numeric entities are decoded.

Free tool · runs in your browser · no account required