ToolBrigadeToolBrigade

HTML Entity Encoder / Decoder

Convert special characters to HTML entities and back — includes a reference table of common entities.

How to use this tool

  1. 1Click Encode or Decode to choose the direction.
  2. 2Paste your input into the left textarea.
  3. 3Click the Encode or Decode button to convert.
  4. 4Copy the result from the right output panel.

About HTML Entity Encoder / Decoder

This HTML entity converter encodes special characters to entities and decodes them back, with a quick reference of common entities.

CMS fields and XML digests break on bare &, <, and quotes. Encoding locally avoids paste errors in tickets.

Click Encode or Decode to choose the direction. Paste your input into the left textarea. Click the Encode or Decode button to convert. Copy the result from the right output panel. Processing stays in your browser.

Use it for email HTML and CMS snippets. Only encode what your context requires.

Named vs numeric entities differ. Decoding twice creates garbage. Do not encode entire documents blindly.

Close the tab when you finish so sensitive input is not left in page memory.

Code examples

JavaScript

// Encode
const encode = (str) =>
  str.replace(/[&<>"']/g, c => ({
    "&":"&amp;","<":"&lt;",">":"&gt;",
    '"':"&quot;","'":"&#39;"
  })[c]);

// Decode
const decode = (str) => {
  const el = document.createElement("textarea");
  el.innerHTML = str;
  return el.value;
};

Python

import html

encoded = html.escape('<script>alert("xss")</script>')
decoded = html.unescape(encoded)

Frequently asked questions

Different tools use different definitions and parsers, so small gaps are common. HTML Entity Encoder / Decoder applies browser-native parsers and encoders appropriate to the job with one consistent browser-side rule set. Hidden characters, stricter syntax, or a different tokenizer usually explain the mismatch. Reduce the input to a minimal sample, then add pieces back until the difference appears. Match the rule your destination actually enforces.

Treat the error as a signal that this environment is stricter or configured differently. Browser APIs reject malformed structures early instead of guessing. Convert to a boring intermediate when it helps—plain UTF-8 text, PNG, WAV, or an unlocked PDF—then retry. If the intermediate works, the original encoding was the problem. Keep that minimal sample for the next regression check.

Runtimes disagree even when feature names match. Locales, parser strictness, codec builds, and library versions differ between your browser and CI. Export the exact bytes from HTML Entity Encoder / Decoder, hash them, and compare in the pipeline. Align normalization steps so both systems see the same input. Use the browser result as a reference artifact, then make CI match it.

Desktop apps win on deep feature sets, batch farms, and specialized hardware paths. HTML Entity Encoder / Decoder wins on zero install, private local processing, and speed for the everyday job on this page. Choose desktop software for multi-hour editorial work or exotic edge formats. Choose this tool when you need a correct result quickly without uploading. Many people do a quick pass here first, then open the heavy suite only if an edge case demands it.

Prefer HTML Entity Encoder / Decoder whenever the input is personal, unpublished, customer-owned, or under NDA, because the core transform stays in your browser via browser-native parsers and encoders appropriate to the job. Cloud services can still help for formats your browser truly cannot decode, but you must trust their retention policy. Strip secrets before any upload. Privacy is usually the reason to stay local—not a longer marketing checklist.

Start from the best original input you still have. Change only what the destination requires. Prefer lossless intermediates when you must convert twice. Because the tool is local, iterate in small steps: tweak one setting, re-run, compare. Spot-check a short sample before batching anything important.

No account is required for normal use. The core html entity converter transform runs in your browser on your device using browser-native parsers and encoders appropriate to the job. You get on-screen output, a copy action, or a download without a mandatory ToolBrigade upload for that step. Keep your browser updated. A few lookup utilities may call public reference APIs for live fields only—they still do not need your private documents.

Lighter text, code, calculator, and many image jobs work on modern phones. Large video encodes and huge PDFs are happier on a plugged-in laptop with more RAM. Fully client-side flows can continue offline once scripts are cached; live lookups still need network. If a run seems stuck, try a smaller sample, free memory by closing tabs, and confirm the input is not truncated. Prove the path on a short fixture before blaming the algorithm.

Related Tools