Outils gratuits

Encodage / Décodage d'entités HTML

Échappez le texte en entités HTML sûres ou décodez les entités nommées et numériques en texte brut.

What the HTML entity encoder and decoder is for

Whenever you want characters like a less-than sign, a greater-than sign, an ampersand, or a quotation mark to appear as literal text on a page instead of being interpreted as markup, you need HTML entities. This tool escapes plain text into safe entities and decodes named or numeric entities back into the characters they stand for, all inside your browser. It is the helper you reach for when pasting a code snippet into a blog or documentation, sanitising user-supplied text before it lands in a template, working out why a page renders as bold rather than showing the tag, or making sense of a scraped string peppered with ' and &.

How HTML entity encoding works

An entity is a short code that stands in for a character the browser would otherwise treat specially. Entities come in two shapes. Named entities use a mnemonic between an ampersand and a semicolon, such as the sequence for a non-breaking space or for the ampersand itself. Numeric entities reference a character directly by its Unicode code point, either in decimal, like the pattern © for the copyright sign, or in hexadecimal with an x prefix, like © for the same character. The encoding direction here focuses on the five characters that genuinely matter for safety inside HTML: the ampersand, the two angle brackets, and the double and single quotation marks. Escaping the ampersand first is essential, because it is the character that begins every entity — get the order wrong and you would double-escape everything else.

Decoding is deliberately broad. The tool resolves the full range of named and numeric entities the browser itself knows, because it decodes by handing the string to the browser's own HTML parser and reading back the plain-text result. That means an obscure named entity, a decimal reference, and a hexadecimal reference that all point at the same character will each decode correctly to that one character, without you needing a lookup table.

Concrete examples and use cases

  • Displaying source code on a page: the angle brackets in a tag must be escaped so they show as characters instead of creating a real element.
  • Preventing cross-site scripting: escaping user input before inserting it into HTML stops a stray script tag or event handler from ever executing.
  • Cleaning up exported or scraped content where quotes and ampersands arrived already entity-encoded and need to become readable punctuation again.
  • Handling copy that mixes languages or symbols, where numeric references are the most portable way to guarantee a character survives a pipeline.

Tips and gotchas

The most common mistake is escaping in the wrong order or escaping twice. Because the ampersand introduces every entity, encoding text that already contains entities will escape those ampersands again, so a value that was already safe becomes visibly broken with doubled codes like <. Escaping is also context-sensitive: entity escaping is the correct defence when text goes into HTML, but it is not a substitute for the right encoding in other contexts, each of which has its own rules — a JavaScript string, a URL, and an SQL statement all need their own escaping, not HTML entities. When decoding, remember that a real HTML parser will also normalise or drop some constructs, so decoding is best reserved for genuine entity strings rather than for trying to repair arbitrary broken markup.

Everything stays on your device

This encoder and decoder run one hundred percent locally in your browser; nothing you paste is uploaded, transmitted, or logged anywhere. That is worth emphasising precisely because entity encoding is a security control — the text you are sanitising is very often the untrusted or sensitive content you would least want to send through a random online service just to clean it. Keeping the work on your own machine removes that risk entirely and lets the tool run offline. If you build pages or APIs that must escape their output safely, our developer documentation covers where server-side escaping belongs in a request pipeline, and this browser tool is a handy companion for spot-checking values by hand.

Les gens ont trouvé cette page en recherchant

Vraies phrases de recherche auxquelles cette page répond — les liens ouvrent la page qui les couvre en profondeur.