Category: Developer tools

HTML Encoder Decoder

System ideaMissing a tool?

Encode the five reserved characters, decode named and numeric entities

Escape &, <, >, " and ' into HTML entities, or decode named, decimal and hexadecimal entities back to text. Copy the result; everything runs in your browser.

Result
The result will appear here.

Everything on this page is processed in your browser. Nothing is uploaded.

What this tool does

This HTML encoder and decoder handles two directions. Encoding escapes the five reserved characters &, <, >, " and ' into their HTML entities, so a code sample or a piece of user input is displayed as text instead of being parsed as markup. Decoding turns supported entities back into ordinary characters: the named forms amp, lt, gt, quot, apos, #39 and nbsp, plus decimal and hexadecimal numeric entities such as &#39; and &#x27;. The result can be copied in one action and everything runs in the browser. The boundaries matter. There is no complete named-entity catalogue, only the names listed above plus numeric forms. Encoding does not transform ordinary non-ASCII characters, so accented letters, CJK text and emoji pass through unchanged. There is no HTML sanitization, parsing, minification or rendering preview, and escaping on its own is not a complete XSS defence. There is no URL percent-encoding, Unicode normalization, file upload or batch conversion. Your text and the transformed output stay in the browser and are never uploaded to LocalTools.

How to use it

  1. Paste the text or the already-escaped HTML fragment you want to convert.
  2. Choose encode to escape &, <, >, " and ', or decode to restore supported named and numeric entities.
  3. Read the output and copy it; nothing leaves your browser at any point.

Privacy

This tool runs entirely in your browser. Your input is never uploaded, stored or shared — closing the tab removes it.

Frequently asked questions

Which characters are encoded?
Exactly five: ampersand, less-than, greater-than, double quote and apostrophe. Those are the characters that change how markup is parsed, so escaping them is what keeps text as text.
What is the difference between encode and decode here?
Encode replaces those five characters with entities such as &lt; and &amp;. Decode goes the other way, turning supported entities back into the original characters.
Does it support numeric HTML entities?
On decode, yes: decimal forms like &#39; and hexadecimal forms like &#x27; are both handled, alongside amp, lt, gt, quot, apos and nbsp. Encoding always produces the five escapes, never numeric output.
What about named entities like &copy; or accented letters?
The decode set is limited to the names listed above plus numeric entities, so a full catalogue such as &copy; or &euro; is out of scope. Encoding leaves ordinary non-ASCII characters, including accents and emoji, untouched.
Is this the same as URL encoding, or a security sanitizer?
Neither. HTML entities and URL percent-encoding are different schemes for different places, and this tool does not do URL encoding. It also does not sanitize, parse, minify or render HTML, so it is not an XSS filter on its own.