Skip to content
Toolars
Explore
Report bug

Developer · Local utility

HTML Encoder / Decoder

Escape the five markup-breaking characters or decode named and numeric HTML entities back to text, locally, with one-click round trips.

Task path / input to outcome

Choose Encode or Decode

Runs locally · Nothing is uploaded

How HTML Encoder/Decoder works, privacy, and related tools

Task path / input to outcome

How to encode and decode HTML entities

  1. 01

    Choose Encode or Decode

    Pick a direction in the mode tabs. Encode turns markup into displayable text you can paste into documentation; Decode resolves character references back to real characters you can read. The two pane labels always show which direction is active.

  2. 02

    Paste the content

    Use the HTML or plain text field when encoding, or the HTML entities field when decoding. The result updates live as you type, and Load sample shows a small round-trip example with a tag and an emoji reference.

  3. 03

    Read the result

    Encoding escapes exactly the five characters that break markup — &, <, >, ", and ' become &amp;, &lt;, &gt;, &quot;, and &#39; — while decoding resolves named and numeric character references through the browser's own parser. Everything else in your text passes through untouched, so a fragment like &lt;strong&gt; comes back as a real tag when you decode.

  4. 04

    Round-trip with Swap

    Swap moves the output back into the input with the opposite mode selected, so you can encode a fragment, swap, and decode it again to confirm the text survives the round trip unchanged. The pane labels switch with the mode, so the current direction is always visible.

  5. 05

    Copy or download

    Copy result sends the output to the clipboard, and Download .txt saves it as toolars-html-entities.txt for handing to a colleague or attaching to a ticket. Clear empties both panes for the next fragment.

Tool facts

Processing
In your browser
Input leaves this device
Never
Retention
Nothing is stored
Price
Free

Your input stays in the browser.

HTML Encoder/Decoder uses its verified local execution path and does not create a hidden input or output history.

Local execution

Runs inside the current browser tab.

No hidden processing

Active tool data never becomes a Toolars document record.

No account required

Use the core workflow without creating a profile. Favorites sync to your account after you sign in.

Immediate reset

Clear the tab and the active working data is gone.

What HTML Encoder/Decoder actually does

A tutorial needs to show a snippet of markup without the browser swallowing the tags; a CMS export comes back sprinkled with &amp; and &#39; and someone has to read it; a template keeps breaking because an attribute value contains a raw quote. HTML Encoder/Decoder handles both directions locally, with a Swap button that makes round-trip checks a two-click job — and it is the quickest way to see what a stored export will look like once a browser parses it. Draft content and unpublished pages never leave the tab, and no account stands between you and the result.

Common questions

Which characters does Encode escape?
Exactly five: &, <, >, the double quote, and the single quote, which become &amp;, &lt;, &gt;, &quot;, and &#39;. Everything else stays as typed, so ordinary text remains readable in the encoded output and only the characters that would break markup or attributes change.
What kinds of entities can Decode resolve?
Decode recognizes named references such as &amp;, decimal references such as &#38;, and hexadecimal references such as &#x26; through the browser HTML parser. Unknown references remain literal. Some named references without a final semicolon can still decode under browser rules, so a missing semicolon is not a reliable way to keep the text unchanged.
Is encoding the same as sanitizing HTML?
No. Encoding escapes five characters so markup displays as text; it is a presentation step, not a security filter, meant for tutorials, documentation, and code samples. Do not treat encoded output as a substitute for a real sanitization policy when you actually intend to render user content.
Why does the apostrophe become &#39; and not &apos;?
The encoder uses the numeric reference &#39;, which every HTML parser accepts in both HTML and XHTML contexts. It decodes back to a plain apostrophe through any standards-compliant parser, including the browser's own.
What happens if I decode text that has no entities?
It comes back unchanged. Decoding only rewrites character references it recognizes, so plain text passes through as-is and you can safely run unknown content through Decode to check whether it contains entities at all.
Is my markup uploaded anywhere?
No. Both directions run entirely inside the current browser tab, the input is never sent or retained, and no account is required.

Continue in Developer

Related tasks, not a dead end.

Move into another focused workspace without returning to the full index.

Code to Image Converter

Export syntax-highlighted code as PNG or SVG for six languages with light and dark themes, line numbers, a window title, and 1x or 2x scale.

Create

URL Slug Generator

Turn titles into clean URL slugs with hyphens or underscores — accents stripped, ampersands expanded, non-Latin scripts preserved — live as you type.

Create

React Native Shadow Generator

Compare legacy shadow properties and boxShadow for React Native, tune iOS and Android output side by side, and copy the StyleSheet code.

Create

Base64 Encoder/Decoder

Encode Unicode text to Base64 or decode it back with live validation, URL-safe and UTF-8 options, and a swap button for round trips.

Convert