100% local — your data never leaves your browser

HTML Escape — Text That Renders as Text

Escape text for HTML. The five structural characters become named entities and everything above ASCII a numeric reference that works on any page.

Instant Private Zero cookies

Text input

HTML Entities output

What this tool does

Five characters change the meaning of HTML, so they get a name:

CharacterOutput
&&
<&lt;
>&gt;
"&quot;
'&#39;

Everything above printable ASCII becomes a decimal numeric reference: é gives &#233;, € gives &#8364;.

Numeric rather than named

é comes out as &#233;, not &eacute;, and that is deliberate.

A named entity has to be defined by the document type. HTML defines a couple of thousand of them; XML defines exactly five. Paste &eacute; into an XML file, an Atom feed or an XHTML document served as XML, and the parser reports an undefined entity. &#233; is understood by all of them.

Invisible characters become visible

A non-breaking space becomes &#160;. That is often the whole point of running the tool: a U+00A0 pasted out of Word looks exactly like a space in your editor and behaves nothing like one, and encoding is how you find it.

Tab and newline stay literal. They are legal in HTML text, and turning them into references would make the source harder to read for no gain.

The apostrophe

' becomes &#39; rather than &apos;. &apos; is defined in XML and in HTML5, but not in HTML 4 — a document in that mode renders the seven characters instead of the quote. The numeric form has no such gap.

One reference per character, not per unit

An emoji comes out as &#128512;, a single reference. Characters outside the Basic Multilingual Plane are stored as two units internally, and a naive escaper emits two broken references for them. This one iterates code points.

Private by design

Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.

Frequently asked questions

Why is é encoded as &#233; and not &eacute;?
Because a numeric reference works in every document. Named entities beyond the core five are defined by the HTML doctype — XML predefines only `amp`, `lt`, `gt`, `quot` and `apos`, so `&eacute;` in an XML file is an undefined-entity error. `&#233;` has no such condition attached.
Do I have to escape every non-ASCII character?
No. A UTF-8 document declaring its charset renders `é` directly, and that is usually the better source. Escaping matters when the text has to survive a channel that is ASCII-only or that you do not control — an old templating system, a mail gateway, a database field of unknown encoding.
Is this enough to make user input safe in HTML?
For text content and for a quoted attribute value, yes — those five characters are exactly what changes the meaning of the markup. It is **not** enough inside `<script>` or `<style>`, in an unquoted attribute, or in a URL attribute where `javascript:` is the risk. Escaping is contextual, and this tool covers one context.

Related converters