100% local — your data never leaves your browser

XML Escape — Text That Stays Inside the Tag

Replace the five XML markup characters with their entities, so your text survives inside an element or an attribute and the document still parses.

Instant Private Zero cookies

Text input

XML Escaped output

What this tool does

XML has exactly five characters that a parser cannot read literally inside content, and this tool replaces each of them with its predefined entity:

CharacterBecomes
&&
<&lt;
>&gt;
"&quot;
'&apos;

Everything else passes through untouched — accents, emoji, tabs and newlines are all legal XML content and are left exactly as you typed them.

When you need it

Whenever text you did not write ends up inside markup: a product name containing &, a code snippet containing <, an attribute value containing a quote. This is markup escaping, not string-literal escaping — if you are building a Java or C# source file rather than an XML document, the rules are different and the matching tool is the one for that language.

What it does not do

It escapes; it does not validate. If your text is already a fragment of XML, escaping it turns the tags into visible text rather than markup — which is usually what you want for embedding a snippet, and never what you want for merging documents.

Private by design

Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.

Frequently asked questions

Which characters does it replace?
Exactly five: & becomes &amp;, < becomes &lt;, > becomes &gt;, " becomes &quot; and ' becomes &apos;. Nothing else is touched, because nothing else can break XML parsing.
Does the ampersand get double-escaped?
The tool escapes what you give it, character by character. If your input already contains &amp;, the ampersand in it is escaped again and you get &amp;amp;. Paste raw text, not text that has already been escaped once.
Is this the same as HTML escaping?
Close, but not identical. HTML predefines many more named entities and treats &apos; as an XML-only name that older HTML parsers do not know. For HTML attributes and text nodes these five are still the ones that matter.

Related converters