ASG ToolsPowered by ASG Groups
Developer Utilities

HTML Entity Encoder / Decoder

The problem: Pasting raw HTML into a CMS, template or code comment causes rendering bugs — < and > must be escaped, but doing it manually is tedious and error-prone.

ASG Privacy VerifiedVerified

100% In-Browser Execution. Zero server uploads. Your data never leaves this tab — disconnect your internet and the tool keeps working.

HTML Entity Encoder / Decoder: the complete guide

An HTML entity encoder and decoder converts special characters like <, >, &, double quotes and hundreds of international symbols to their safe HTML entity equivalents — and back again. HTML entities prevent browsers from interpreting text content as markup: a literal < is the start of a tag in HTML, but &lt; is safely rendered as a less-than sign. This matters any time you display user input in a web page, embed code snippets in HTML, write documentation, or populate a CMS that processes HTML. The decoder runs the same conversion in reverse, turning &lt;div&gt; back into <div> for inspection or testing. Both directions happen live as you type, with no server involved.

Named entities, decimal references and hex references

HTML defines three ways to represent a character as an entity. Named entities use a memorable name: &amp; for &, &lt; for <, &copy; for ©, &euro; for €, &mdash; for —. Decimal numeric references use the Unicode code point in base 10: &#38; for &, &#60; for <, &#169; for ©. Hexadecimal references use a 0x-prefixed hex code: &#x26;, &#x3C;, &#xA9;. All three representations are valid HTML and decode to the same character. Named entities are preferred for readability in code, but many Unicode characters (emoji, CJK characters, mathematical symbols) have no named entity and must be referenced numerically. The decoder handles all three forms.

When and why to encode HTML

Any text that originates outside the developer's control must be HTML-encoded before being rendered in a page. This includes user-submitted form fields, API data from external services, database content and URL parameters. Failure to encode is the root cause of Cross-Site Scripting (XSS) attacks: if a user submits <script>alert('xss')</script> as their name and the page renders it as raw HTML, the script executes in every visitor's browser. Encoding the input to &lt;script&gt;alert(&#39;xss&#39;)&lt;/script&gt; defangs the payload completely — the browser displays the text literally. Modern frameworks like React and Vue auto-encode by default, but raw innerHTML assignments, template literals in older codebases, and certain CMS contexts still require explicit encoding.

Step by step: how to use HTML Entities

  1. 1

    Select Encode mode to convert text with special characters to HTML entities.

  2. 2

    Or select Decode mode to convert HTML entities back to readable text.

  3. 3

    Paste or type your content in the input area — output appears live on the right.

  4. 4

    Use the Load example button to see a realistic sample of code-containing HTML.

  5. 5

    Click Swap to use the output as the new input (reverses the operation).

  6. 6

    Copy the output with the Copy button or select all text for manual copying.

Security & privacy

Encoding and decoding runs entirely in your browser tab with vanilla JavaScript string operations — no server, no network, no external libraries. User-submitted strings that may contain sensitive content (names, messages, identifiers) are processed only in local memory and never transmitted anywhere. This is the only acceptable design for a security-critical tool: a server-side encoder could log the very payloads you are trying to sanitize.

Frequently asked questions