100% local — your data never leaves your browser

XML Unescape — Read an Escaped Snippet

Decode the five XML entities and numeric character references back to text, in a single pass, so you read what the document actually carried.

Instant Private Zero cookies

XML Escaped input

Text output

What this tool does

It decodes the five entities XML predefines — &, <, >, " and ' — along with numeric character references in both forms: decimal A and hexadecimal A, including characters above U+FFFF, so 😀 comes back as its emoji.

Entity names are case-sensitive, as XML requires: & decodes, & does not. A reference also needs its semicolon — &amp without one is ordinary text and is left as such.

One pass, deliberately

Decoding runs exactly once. &amp;lt; gives &lt;, not <, because &amp;lt; is the escaped form of the literal text &lt; and that text is the correct answer.

Running the decode a second time is how escaped markup turns back into live markup — the step behind a whole class of injection bugs. If you genuinely have a doubly encoded value, paste the result back in and decode again, as a decision you make rather than one the tool makes for you.

What it does not do

HTML named entities are out of scope. &nbsp;, &copy; and the several thousand others belong to HTML, not XML, and come back untouched.

Invalid numeric references are preserved verbatim rather than replaced. A surrogate code point (&#xD800;) or a value beyond U+10FFFF (&#99999999;) cannot map to a character, and returning the reference unchanged keeps the input recoverable instead of quietly losing it. The same applies to every character XML 1.0 cannot represent at all — NUL, most control characters, the non-characters U+FFFE and U+FFFF: &#0; and &#xFFFF; come back as written. Decoding them would hand you a document no XML parser will accept.

Private by design

Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.

Frequently asked questions

Why is `&nbsp;` left alone?
Because it is not an XML entity. XML predefines exactly five — `&amp;`, `&lt;`, `&gt;`, `&quot;` and `&apos;` — and everything else is HTML. Use the HTML entities tool for those.
Why does `&amp;lt;` give `&lt;` rather than `<`?
Because decoding runs once, on purpose. `&amp;lt;` is the escaped form of the text `&lt;`, so one pass is the correct answer; decoding twice is how escaped markup gets turned back into live markup.
What happens to an invalid numeric reference?
It comes back exactly as written. A surrogate code point such as `&#xD800;` or an out-of-range value such as `&#99999999;` has no character to decode to, so the reference is preserved rather than replaced by a placeholder.

Related converters