// Escape HTML
<a href="x">Tom & Jerry</a><a href="x">Tom & Jerry</a>Start typing to search, or pick a tool.
Escape unsafe HTML characters into entities and decode entities back to characters. Useful for safely embedding user content in HTML.
Text
Escaped
When you insert text into an HTML document, characters like <, >, and & have special meaning to the browser. If your text contains these characters and you don't escape them, the browser may interpret your text as HTML markup — causing broken layouts or, worse, cross-site scripting (XSS) attacks. Escaping replaces these characters with HTML entities: < becomes <, > becomes >, & becomes &, " becomes ", and ' becomes '.
Unescaping reverses the process: < becomes < again. This is useful when you receive pre-escaped data from an API, database, or email and need to render it as actual HTML. Always unescape before rendering, then re-escape if the data needs to go back into a text context.
HTML escaping prevents characters from being interpreted as markup, but it is not a complete XSS defense. Escaping only handles the five characters above. If you're rendering user-provided HTML (not just text), you need a full sanitizer like DOMPurify that strips <script> tags, event handlers (onclick), and dangerous attributes (href="javascript:").
Use this tool to escape user input before inserting it into a template. Use DOMPurify to sanitize user input that contains actual HTML markup. They serve different purposes and should be used together.
HTML defines both named entities (<, >, &) and numeric entities (<, >, &). Named entities are more readable; numeric entities work for any Unicode character. This tool uses named entities for the five standard characters and numeric entities for everything else.
The five characters that must be escaped in HTML are: < (less than), > (greater than), & (ampersand), " (double quote — in attributes), and ' (single quote — in attributes). All other characters are safe to include unescaped in HTML text content.
Database output. If your application stores user-generated text in a database and later renders it inside an HTML template, escape at render time — not at insert time. Storing pre-escaped data makes it harder to reuse the same content in non-HTML contexts like plain-text emails or API responses.
Email templates. Many email clients support HTML content. User-provided strings inserted into email HTML must be escaped to prevent rendering bugs and potential phishing vulnerabilities. Use the unescape mode to clean up data that arrives already escaped from a legacy system or third-party API.
Log files and debugging. When copying HTML snippets into log files or terminal output, escaping prevents the browser from interpreting stray angle brackets as markup. This makes it easier to read and search log content without rendering artifacts.
The five characters above are the only ones that must be escaped in HTML text content, but any Unicode character can be represented as a numeric entity using &# followed by its code point and a semicolon — for example, © for the copyright symbol or 😀 for a grinning face emoji. Numeric entities are useful when you need to represent characters that aren't available in the document's character encoding.
This tool focuses on the five mandatory characters because they are the ones that cause real problems in practice. If you need to encode an entire document with HTML entities for legacy compatibility, consider a dedicated HTML entity encoder that covers the full Unicode range.
Most modern templating engines — React, Vue, Svelte, Jinja2, Handlebars — auto-escape interpolated values by default. This is a strong safety default, but it can cause double-escaping if you manually escape input before passing it to the template. If you see < rendered as literal text instead of <, the value was likely escaped twice. This tool helps you undo one layer of escaping to diagnose and fix the issue.
Conversely, when you need to render raw HTML inside a template, you must explicitly mark the content as trusted — set:html in Astro, v-html in Vue, dangerouslySetInnerHTML in React. Only use raw HTML output for content you control or have sanitized with a library like DOMPurify.
// Escape HTML
<a href="x">Tom & Jerry</a><a href="x">Tom & Jerry</a>// Unescape entities
<a href="x">Tom & Jerry</a><a href="x">Tom & Jerry</a>No. Escaping makes text safe to put inside an HTML document, but it does not protect against every XSS vector. Use a sanitizer like DOMPurify when rendering untrusted HTML.
<, >, &, ", and ' are escaped to their named or numeric entity equivalents.
No. Encoding and decoding happen in your browser.