Skip to content

HTML Entity Encoder and Decoder

Paste text or HTML code and instantly see it with entities. It works the other way too: turn <p> or   back into the original characters.

Your text is never uploaded, everything is processed in your browser.

How to use the HTML entity encoder

  1. 1 Pick a direction. Encode turns characters into entities, Decode turns entities back into characters.
  2. 2 Type or paste your text. The result updates as you type, there is nothing to submit.
  3. 3 When encoding, choose whether to convert only <, >, &, " and ', or also accented letters and symbols, and which entity format to use.
  4. 4 Copy the result with the Copy button. Swap moves it to the input so you can check that it converts back.

What the tool can do

  • decodes all 2,000+ named HTML5 entities as well as numeric entities, exactly the way a browser does
  • correctly handles emoji too, for example &#128512; becomes 😀
  • warns you when the text already contains entities or has been encoded twice, and offers a one-click fix
  • encodes to named, decimal or hexadecimal entities
  • leaves line breaks, tabs and the rest of the text untouched
  • runs entirely in your browser, nothing is sent to a server

What are HTML entities?

An HTML entity is a way of writing a character using ordinary letters and digits. It starts with & and ends with a semicolon: &lt; stands for < and &copy; for ©. You mostly need entities for characters that have a special meaning in HTML. If you typed <b> straight into a page, the browser would treat it as a tag and show the following text in bold. Written as &lt;b&gt;, it displays exactly as <b>.

Parts of an entity
& start of the entity
copy character name or number
; end of the entity
= ©

What is the difference between HTML entities and Unicode?

Unicode is the worldwide character table in which every character has its own number, for example © is number 169 (U+00A9). An HTML entity is just a way of writing that character in HTML code. The numeric entity &#169; contains the Unicode number directly, the named entity &copy; is a readable shortcut for it. On a UTF-8 page you can also type the character directly, the result is the same.

Which characters must be escaped in HTML

On a UTF-8 page, only five characters need to be replaced with entities. Everything else, including accented letters, can be written directly. The first of them, &, is called the ampersand. It started out as a ligature of the letters in the Latin word et, meaning "and".

Character Entity When to escape it
& &amp; Always. Otherwise the text after it may be read as an entity, for example &copy=2 in page text displays as ©=2.
< &lt; Always in text. The browser would treat it as the start of a tag.
> &gt; Not required, but usually escaped together with < to keep the code readable.
" &quot; Inside a double-quoted attribute value, for example title="...".
' &#39; Inside a single-quoted attribute value, for example title='...'.

These are exactly the five characters escaped by PHP's htmlspecialchars function and by auto-escaping in Blade, Twig and React.

Named, decimal and hex entities

The same character can be written in three ways. Browsers display them identically, only the notation differs.

  • A named entity like &copy; is easy to read, but only some characters have a name.
  • A decimal entity &#169; contains the character's Unicode code point and works for any character, including emoji.
  • A hex entity &#xA9; is the same number in hexadecimal, the notation Unicode normally uses, for example U+00A9.
Character Named Decimal Hex
© &copy; &#169; &#xA9;
→ &rarr; &#8594; &#x2192;
č &ccaron; &#269; &#x10D;
😀 no name &#128512; &#x1F600;

Entity names are case-sensitive: &Eacute; is uppercase É, &eacute; is lowercase é.

List of HTML entities and special characters

The most commonly used entities, grouped by category. Click an entity to copy it. You can search by name, description, the character itself or its number, for example 8226.

Character Named Decimal
ampersand
less-than sign
greater-than sign
double quotation mark
apostrophe
non-breaking space
soft hyphen
en space
em space
thin space
no name narrow non-breaking space
zero-width space

Characters without a name, such as ✔ or emoji, can only be written as numeric entities. The CSS column shows the value for the content property, see the section on CSS and JavaScript for details.

How to make bullet points in HTML?

For a bulleted list, use the <ul> and <li> tags. The browser adds the bullets itself and you can change their shape in CSS, for example list-style-type: square for squares or list-style-type: "✓ " for check marks. Use the &bull; entity only when you need a bullet inside a line of text, for example in a footer: Contact &bull; Privacy policy.

How to type an arrow in HTML, CSS and on the keyboard

The most common arrows and triangles, with every way to write them. Type the code from the Word column into a document and press Alt+X right after it, and Word turns it into the character.

Character HTML Windows Word
← &larr; Alt+27 2190
→ &rarr; Alt+26 2192
↑ &uarr; Alt+24 2191
↓ &darr; Alt+25 2193
↔ &harr; Alt+29 2194
▲ &#9650; Alt+30 25B2
▼ &#9660; Alt+31 25BC
⇒ &rArr; 21D2

Type Alt codes while holding the left Alt key, using the numeric keypad, the number keys above the letters do not work. Word also automatically turns --> into →, <-- into ← and ==> into ⇒. The triangles ▲ and ▼ have no named entity, so write them as numeric entities.

How to type ©, ® and ™

The copyright, registered trademark and trademark symbols most often go in a website footer. Here is how to type them in HTML and in everyday apps:

Character HTML Windows Mac Word
© HTML: &copy; Windows: Alt+0169 Mac: Option+G Word: (c)
® HTML: &reg; Windows: Alt+0174 Mac: Option+R Word: (r)
™ HTML: &trade; Windows: Alt+0153 Mac: Option+2 Word: (tm)

The Mac shortcuts are for the US keyboard layout. With a different layout, open the Character Viewer with Ctrl+Cmd+Space and search for the symbol. In Word, (c), (r) and (tm) turn into the symbol automatically. In a website footer, just write something like &copy; 2026 Company Name.

How to type a symbol that is not on your keyboard

If you need a symbol in ordinary text rather than in HTML code, you do not need an entity. On Windows 10 and 11, press Win+period to open the emoji and symbol panel, on a Mac press Ctrl+Cmd+Space. You can also copy the symbol from the list above. On Windows, the built-in Character Map app is another option.

Non-breaking space &nbsp;

A non-breaking space looks like a regular space, but the browser will never break a line at it. In English it keeps together things that look wrong when split across two lines:

10&nbsp;km
a number and its unit, for example 25 °C, 5 kg or 100 MB
Mr.&nbsp;Smith
titles and names, for example Mr. Smith or Dr. Jones
October&nbsp;2
dates, so the month and day stay together
page&nbsp;12
page, chapter and figure numbers
9:30&nbsp;a.m.
times, and product or version names such as Windows 11

For long words in narrow columns, try &shy;, the soft hyphen: the browser splits the word there and adds a hyphen only when the word does not fit on the line.

How to insert a non-breaking space in Word, Excel or on a Mac

Word on Windows
Ctrl+Shift+Space
Excel, PowerPoint and other Windows apps
Alt+0160 on the numeric keypad
Mac
Option+Space in most apps
Google Docs
Insert, then Special characters, and search for "no-break space"
Anywhere
copy it from the HTML entities list above by clicking the character

Why does &nbsp; show up in my email or message?

If you received an email, text message or chat message containing “&nbsp;”, it is not an abbreviation or a hidden link. The sender or the app copied the text from a web page and did not convert the non-breaking space entity back into a character. There should simply be a regular space in its place. In the same way, you may see &amp; instead of & or &quot; instead of quotation marks. If you want clean text, paste it into the tool above and choose Decode.

How to add multiple spaces in HTML

Browsers collapse several spaces, tabs and line breaks in a row into a single space. That is why the page does not show how many spaces you typed in the code. Depending on what you need, you have these options:

John&nbsp;&nbsp;Smith
one or two non-breaking spaces between words that will not collapse
a&emsp;b
a wider space, &ensp; is as wide as the letter n and &emsp; as wide as the letter m
p { text-indent: 2em; }
indent the first line of a paragraph instead of a row of &nbsp; entities
.icon { margin-right: 0.5rem; }
space between elements, for example between an icon and text
.code { white-space: pre-wrap; }
keeps spaces and line breaks exactly as they are in the text

Indenting or aligning text with a row of &nbsp; entities is not worth it: the layout falls apart on a different screen width. Page layout is what CSS is for.

How to add a line break and line spacing in HTML

The browser displays a line break in your code as an ordinary space, and the same goes for the &#10; entity. New lines and larger gaps are made differently:

First line<br>Second line
a new line within one paragraph, for example in an address
<p>Paragraph</p>
a new paragraph, the browser adds space before and after it
p { line-height: 1.6; }
line height, that is the spacing between lines in a paragraph
p { margin-bottom: 1.5em; }
spacing between paragraphs
.address { white-space: pre-line; }
keeps the line breaks from the text, for example from a form

The &#10; entity creates a new line only where line breaks are preserved: inside <textarea> and <pre> tags, or in the title attribute, where it produces a two-line tooltip. If you are looking for the Enter key symbol, it is ↵ (&crarr;) or ⏎ (&#9166;).

Do I need entities for accented letters?

No, as long as your page uses UTF-8, which is the standard today. Just make sure the head contains <meta charset="utf-8"> and write letters like é, ü, ñ or ø directly, whether in names or loanwords like café. Numeric forms like &#233; date back to the era of ISO-8859-1 and Windows-1252, when accented letters could easily turn into garbled characters on another computer. Today they are only useful in rare cases, for example for a system that cannot handle UTF-8, or when you want plain ASCII in your source code. That is what the Also encode accents and symbols option is for.

Accented letters show up as garbled characters

When you see strange characters instead of “Dvořák café”, it is almost always an encoding mismatch. What exactly you see tells you where the problem is:

What you see What happened How to fix it
Dvořák café The text is in UTF-8, but the browser reads it as the Western European encoding Windows-1252 or ISO-8859-1. How to fix it: Add <meta charset="utf-8"> to the page head and check that the server does not send a different encoding in the Content-Type header.
Dvořák café The text is in UTF-8, but it is read as Windows-1250, the Central European Windows encoding used by older Czech, Polish or Hungarian software. How to fix it: Same as above: <meta charset="utf-8"> and a correct Content-Type header from the server.
Dvo��k caf� The file is saved in an older encoding such as Windows-1250, but the page claims to be UTF-8. Accented letters therefore turn into the � character. How to fix it: Save the file again as UTF-8. In VS Code you will find this option in the status bar, in Notepad in the Save As dialog.
Dvo?ák café The letters were lost when the text was saved, for example to a database using the latin1 encoding, which cannot store them. The question marks are stored permanently. How to fix it: Switch the database, the tables and the connection to utf8mb4 and save the text again. The original letters cannot be recovered from the question marks.

If you see code like &#233; or &eacute; instead of a letter, it is not an encoding problem but double-encoded entities. You will find the fix in the section on common mistakes.

HTML entities and security (XSS)

Escaping <, >, &, " and ' is the basic defense against XSS, an attack where someone injects their own script into your page. When the input <script> is output as &lt;script&gt;, the browser just displays it and does not run it. But it has its limits:

  • Entities only protect page text and attributes whose value is in quotes. An unquoted attribute such as title=value can be broken out of with a simple space.
  • They do not protect inside JavaScript, CSS or link URLs. A link to javascript:alert(1) contains nothing that would be encoded, yet it still runs code. Validate URLs from user input separately.
  • In event handler attributes like onclick, the browser decodes entities before running the code, so they offer no protection there.
  • Encode at output time, when writing to HTML, not when saving to the database. Otherwise you can easily end up encoding the text twice.
  • The safest approach is to let a template engine that escapes automatically handle it, such as Blade, Twig, React or Vue.

HTML entities in CSS and JavaScript

Entities only work in HTML. In CSS and JavaScript strings the same character is written differently, and &rarr; would show up literally. Here is the arrow → in each language:

HTML
<span>&rarr;</span>  or  <span>&#8594;</span>
CSS
.next::after { content: "\2192"; }
JavaScript
element.textContent = "\u2192";
JavaScript (emoji)
element.textContent = "\u{1F600}";

You will find the CSS value for every entity in the list above. If the code in CSS is followed by another letter from a to f or a digit, separate them with a space, otherwise they will be read as part of the code.

Do HTML entities work in React and Markdown?

In React, entities work in JSX text, so <p>&copy; 2026</p> displays ©. They do not work inside a string in curly braces, though: {'&copy;'} is output literally. There, type the character directly or use its JavaScript escape, for example {'\u00A9'}.

Entities work in Markdown, because Markdown passes HTML through: &copy; displays as ©. Inside a code block, however, they are shown literally, which is handy when you want to show the entity itself. The same applies on GitHub and in other Markdown editors.

HTML entities in PHP, JavaScript and Python

Most languages have built-in ways to encode entities, so you do not need to write your own. Here is how it looks in the most popular ones:

PHP

$text = 'Tom & Jerry <3';

echo htmlspecialchars($text, ENT_QUOTES | ENT_HTML5, 'UTF-8');
// Tom &amp; Jerry &lt;3

echo html_entity_decode('&lt;p&gt;&copy; 2026&lt;/p&gt;', ENT_QUOTES | ENT_HTML5, 'UTF-8');
// <p>© 2026</p>

htmlspecialchars encodes only the five special characters, while htmlentities also encodes accented letters. With the ENT_HTML5 flag the apostrophe becomes &apos;, without it &#039;.

Which PHP function to use

htmlspecialchars()
encodes the five special characters, which is enough for safe output to HTML
htmlentities()
encodes everything that has a named entity, including accented letters, not needed on a UTF-8 page
htmlspecialchars_decode()
decodes only those five special characters back
html_entity_decode()
decodes all entities, both named and numeric

Since PHP 8.1, both encoding functions also encode the apostrophe by default and replace invalid UTF-8 characters with �. In older versions, pass the ENT_QUOTES | ENT_SUBSTITUTE flags yourself.

Common HTML entity mistakes

&amp; or &quot; shows up on the page

The text was encoded twice, for example once when saving and again when displaying. & became &amp; and then &amp;amp;. The tool detects this and offers a Decode again button. To fix it for good, encode in one place only, at output time.

Missing semicolon

Browsers recognize some legacy entities even without the semicolon. That is why ?id=1&copy=2 displays on the page as ?id=1©=2. Always write & in text and in links as &amp;.

The &apos; entity in older browsers

&apos; is defined in HTML5 and XML, but it did not exist in HTML 4, and Internet Explorer 8, for example, did not display it. The &#39; form, which this tool uses, is the safer choice.

Entities in URLs

Do not replace spaces and accented letters in a URL with entities, use percent-encoding instead, for example %20. That is what the URL encoder is for. However, when you put a link with several parameters into an href attribute, write the & between them as &amp;.

Entities in JSON and JavaScript

Entities are not converted in JSON or in JavaScript strings. If an API returns &quot; instead of quotation marks, the text was HTML-encoded too early. Decode it and encode only when writing it to the page.

The invisible non-breaking space

Text copied from Word or a web page can contain the U+00A0 character. It looks like a space, but search and form validation do not treat it as one. Encode the text with the Also encode accents and symbols option and every such space will show up as &nbsp;.

FAQ

What is an HTML entity?

An HTML entity is a way of writing a character that starts with & and ends with a semicolon, for example &lt; for < or &copy; for ©. It is used for characters that have a special meaning in HTML and for characters that are hard to type on a keyboard.

How do I write < or > in HTML?

Write < as &lt; and > as &gt;. The browser then displays them as text instead of treating them as the start or end of a tag.

What does &nbsp; mean in HTML?

&nbsp; is a non-breaking space. It looks like a regular space, but the line will not break at it. Use it, for example, between a number and its unit (10&nbsp;km) or in names with a title (Mr.&nbsp;Smith).

What is the difference between named and numeric entities?

A named entity uses a name, for example &euro;. A numeric entity contains the character's Unicode code point, either in decimal &#8364; or in hex &#x20AC;. Browsers display all three the same way, but every character has a numeric entity, while only some have a name.

How do I write an arrow, check mark or star in HTML?

The right arrow is &rarr;, the check mark &check; and the black star &starf;. The heavy check mark ✔ has no name, so you write it as &#10004;. You will find more in the HTML entities list on this page, where you can copy them with one click.

Do I have to encode accented letters in HTML?

No, as long as the page uses UTF-8 and has <meta charset="utf-8"> in the head. You can then type letters like é, ü, ñ or ø directly. Entities for accented letters are only useful for systems that do not support UTF-8.

Why does the tool write the apostrophe as &#39; and not &apos;?

The &apos; entity did not exist in HTML 4, so older browsers such as Internet Explorer 8 did not display it. &#39; works everywhere. By default PHP uses the same numeric reference, written as &#039;.

How do I use an HTML entity in the CSS content property?

Entities do not work in CSS. Write the character as a backslash followed by its hex code, for example the arrow as content: "\2192";. You will find the CSS value for every entity in the list on this page.

Does encoding HTML entities prevent XSS?

Yes, when you insert text into the page content or into a quoted attribute. It does not protect inside JavaScript, CSS or link URLs, though. The best approach is to let a template engine that escapes automatically handle it.

Why do I see &amp; or &quot; on my page?

The text was encoded twice. Paste it into the tool, choose Decode, and if entities remain in the result, click Decode again. Then find the place in your code where the text gets encoded the extra time.

What does &#39;, &#8226; or &#160; mean?

These are numeric entities. The number is the character's position in Unicode: &#39; is the apostrophe ', &#8226; the bullet • and &#160; a non-breaking space. You can look up other numbers in the HTML entities list on this page, just type the number into the search. To convert a whole text with entities, use the decoder.

How do I add multiple spaces in HTML?

Browsers collapse multiple spaces in a row into one. To add extra space between words, use non-breaking spaces, for example word&nbsp;&nbsp;word. For paragraph indents and spacing between page elements, use CSS instead, for example text-indent or margin.

Are my texts sent to a server?

No. Encoding and decoding happen entirely in your browser, your text never leaves it.