What are HTML entities and when do you need them?
Some characters have a special meaning in HTML. < starts a tag, & starts an entity, and quotes delimit attribute values. If you want to show them as text, for example a code example or a user comment containing <script>, they must be written as entities: < for <, & for &, and so on. Otherwise the browser interprets them as markup, which can break the page or, with untrusted input, open the door to injection.
This tool, built on the he library, has two modes. The first escapes only the five special characters (& < > " '), which is exactly what you need to insert any text safely into HTML content or attribute values. Everything else, including accents and emoji, stays as it is, which is fine for any page served as UTF-8.
The second mode also encodes every non-ASCII character: accented letters, ñ, €, symbols and emoji. You choose how: named entities where one exists (é, €), decimal numeric entities (é) or hexadecimal ones (é). The result is pure ASCII, useful for systems that mangle encodings, old email templates or code where you want to see exactly which character is used.
Encoding runs in your browser and the text is not uploaded. You get one free try per tool: one file or one pasted text. After that you can still re-process the same text with different options, but new input needs ToolStudio Pro, which gives unlimited use of every tool, several files at once downloaded together in a ZIP, and no ads. You can cancel anytime.
How to encode HTML entities
- Paste your text or drop a file.
- Choose the mode: escape only the 5 special characters, or encode all non-ASCII characters too.
- For non-ASCII characters, choose named, decimal or hexadecimal entities.
- Encode, then copy or download the result.
When to encode HTML entities
- Showing code examples with tags on a web page or blog post.
- Inserting text into an HTML attribute that contains quotes.
- Preparing content for systems that only accept ASCII.
- Writing accents and symbols in old email templates.
- Escaping text by hand when a template engine does not do it for you.
Common HTML entities
- & → &
- < → < and > → >
- " → " and ' → ' (or ')
- é → é = é = é
- ñ → ñ = ñ = ñ
- € → € = € = €
- non-breaking space → =  
Named, decimal or hex?
They all produce the same character. Named entities are the easiest to read but only exist for some characters (about 2,000 in HTML5). Numeric entities work for any Unicode character: decimal uses the code point in base 10, hex in base 16. Emoji, for example, have no named entity, so they are always written as numeric ones.
Frequently Asked Questions
Which characters must be escaped in HTML?
The five special ones: & < > " and '. Escaping them is enough to insert any text safely in content and quoted attributes.
Do I need to encode accents and emoji?
Not if your page is served as UTF-8, which is the norm. Encode them only for systems that mishandle encodings or require ASCII.
What is the difference between é and é?
None in the result: both are é. The first is the code point in decimal, the second in hexadecimal.
Is my text uploaded?
No. Encoding happens in your browser.
Is it free?
One file or one pasted text is free, and you can re-encode it with other options. New input needs ToolStudio Pro: unlimited use, several files at once in a ZIP and no ads.