URL Encoder
Escape spaces, symbols and non-ASCII characters for use in URLs.
Convert HTML special characters to entities and back again.
Certain characters have structural meaning in HTML. An angle bracket starts a tag, an ampersand starts an entity, and quotes delimit attribute values. To display those characters as text rather than have the browser act on them, they must be written as entities: less-than becomes <, ampersand becomes &, and so on. This tool converts in both directions.
Encoding is the safety-critical direction. Any text that comes from a user and ends up inside a page must be escaped, otherwise a submitted script tag runs as code. That class of bug is cross-site scripting, and escaping is the standard defence. Use encode mode to see exactly what a value should look like once escaped.
Decoding is the everyday direction. Content pulled from feeds, exports and databases often arrives with entities still in it, so a headline reads with & in the middle of it. Decode mode turns those back into the characters they represent, including numeric entities and the full set of named ones.
The html encoder & decoder is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:
Ampersand, less-than and greater-than in any text, plus double and single quotes when the text sits inside an attribute value. Encoding those five covers the structural cases that cause rendering problems and security holes.
It removes one important class of vulnerability, but security depends on context. Text placed inside a script block, a style block or a URL attribute needs its own escaping rules. Escaping is necessary, not sufficient.
Named entities such as © are readable but only exist for a defined list of characters. Numeric entities such as © work for any character by code point. The decoder understands both forms.
The source was probably double-encoded, so the ampersand of the entity was itself encoded. Run the decode a second time to resolve it.
Usually not. Modern pages served as UTF-8 display accented and non-Latin characters directly. The option to encode everything exists for legacy systems that cannot handle anything beyond ASCII.
No. Conversion happens in the page using the browser's own parser, so nothing you paste leaves your device.
If the html encoder & decoder is not quite what you need, these other free tools solve closely related problems.
Escape spaces, symbols and non-ASCII characters for use in URLs.
Encode any text, including emoji and accents, to a Base64 string.
Pretty-print and validate JSON, with the exact line and column of any error.
Tidy messy pasted text: extra spaces, empty lines, breaks and special characters.
Decode %20 and other percent escapes back into normal characters.