Skip to content
Allin

HTML Entity Encoder / Decoder

Convert text to HTML entities and back, escaping <, >, &, quotes and optionally all non-ASCII characters.

Open HTML Entity Encoder / Decoder and you get an answer straight away, with no account to create. You will find it under Encoding & decoding, with Base64 Encoder / Decoder and URL encoder / decoder for the neighbouring cases.

How to use it

  1. Open the tool — no signup or install needed.
  2. Enter your input or adjust the available options.
  3. Get your result instantly, then copy or download it.

Frequently asked questions

What does HTML Entity Encoder / Decoder do?

Convert text to HTML entities and back, escaping <, >, &, quotes and optionally all non-ASCII characters.

When would I actually use this?

Reading a payload someone sent you, embedding a small file in a config, and finding out why a query string breaks once it reaches the server.

What is the most common mistake?

Treating Base64 as a form of protection. It is an encoding, not encryption — anyone can decode it instantly, and a token pasted into a public issue is a leaked token.

How is HTML Entity Encoder / Decoder different from Base64 Encoder / Decoder?

They sit next to each other but answer different questions: Base64 Encoder / Decoder is the one to open when you need it to encode and decode Base64 online — free. Pick whichever matches what you're starting from — both are free.

Is there a tool for the next step?

URL encoder / decoder is the closest one after this: Encode and decode URLs and query parameters.

What else is worth having open alongside it?

UUID Validator / Decoder and JWT decoder — they come up in the same task often enough to be worth a second tab.

Where do the figures come from?

The encodings follow their RFCs, so a round trip is lossless. URL encoding has two variants — one that encodes a space as %20 and one as a plus sign — and the tool says which it applies.

Further reading

All guides
GuideBuilding a URL With Parameters That Survives a Copy-PasteThree encodings, one visible difference: %20 or +. The builder's form mode matches URLSearchParams byte for byte on seventeen values — but give it a base URL with a fragment and every parameter lands inside the hash, where no server sees it.GuideStripping HTML Safely: What a Tag Remover Can and Cannot DoRemoving tags and sanitising HTML are two different jobs. One real fragment run through a naive regex and through a formatting-aware stripper, with script and style contents, block breaks, comments, CDATA and entity order all shown as output.GuideURL Encoding Explained: Percent-Encoding and Where It BitesPercent-encoding is decided per URL component, which is the whole source of the confusion. A slash is legal in a path and must be escaped in a query value; a space is %20 in a path and may be + in a form body. Here are the exact RFC 3986 sets, the three JavaScript functions that disagree, and the traps.ExplainerWhat Is Base64 Encoding?Base64 turns binary data into safe text. Here's what it does, why it exists, why it isn't encryption, and the size cost it adds.ExplainerWhat Is a JWT (JSON Web Token)?A JWT is a compact, signed token used to carry identity between services. Here's its three parts, how it's used for auth, and its security limits.ExplainerWhat Is Inside a JWT — and What It Does Not ProtectA JWT is signed, not encrypted. Anyone holding the token can decode the payload and read every claim in it. Here is a real token, decoded without any key, plus the three attacks the signature is supposed to stop and the one problem it cannot solve.