HTML Entity Encoder
Escape text into HTML entities so markup characters survive, in your browser.
Runs entirely in your browser. Nothing is uploaded, logged or stored.
Five characters cannot appear literally in HTML without changing what the markup means: the ampersand, the two angle brackets and the two kinds of quote. Escaping them is what turns a piece of text into a piece of text that a browser will display rather than obey.
How it works
Minimal escapes only those five characters. It is the right choice almost always: if your page is UTF-8 and your files are UTF-8, an accented letter needs no escaping at all, and escaping it makes the source harder to read for no gain.
Named entities replace every character that HTML 4.01 has a name for — 252 of them, é as é, © as ©. Use it when the output has to pass through something that mangles anything above ASCII, such as an old mail system or a database column with the wrong collation.
Numeric references give the same guarantee by code point rather than by name, so they work for every character rather than for the 252 with names. They are written in hexadecimal with the closing semicolon, which every parser accepts.
Examples
| Case | Input | Result |
|---|---|---|
| A tag that must be shown, not run | <script>alert(1)</script> | <script>alert(1)</script> |
| An ampersand inside a value | Tom & Jerry | Tom & Jerry |
| An accented letter, named | café | café |
Frequently asked questions
Is escaping here enough to make user input safe?
For text between tags, and for an attribute value in quotes, yes: the quotes are escaped too. Elsewhere, no: a value going into a URL, a style block or a script block needs its own escaping, and HTML entities are the wrong tool for all three. Escape at the point of output, in the context of that output, in your code — not by pasting through a web page.
Why is the apostrophe escaped as ' and not '?
' is not in HTML 4.01. It was added in XHTML and later in HTML5, and old browsers show it literally. The numeric form has always worked everywhere.
Which named entities are supported?
The 252 of HTML 4.01. HTML5 defines around two thousand more, mostly mathematical, and they are not included here. Anything without a name in that set is left as it is in named mode, or escaped by code point in numeric mode.
Do I need to escape the accents on a modern site?
No. If the page declares UTF-8 and the file is saved as UTF-8, é is simply é. Named entities are for getting text through systems that are not UTF-8 clean.
Good to know
- Everything happens in your browser. What you paste is not uploaded, not logged and not stored.