HTML Encoder / Decoder
Convert special characters to HTML entities (<, &, etc.) and back.
π How to Use
Type or paste text containing HTML special characters.
Click πΌ HTML Encode to convert <, >, & to entities, or π½ HTML Decode to revert them.
Click π Copy to save the encoded/decoded HTML to your clipboard.
About the HTML Encoder / Decoder
HTML reserves a few characters for its own syntax — <, >, &, and the quote characters — so any that appear in your content must be written as character entity references rather than literally. The HTML Encoder does that translation in both directions: encoding replaces reserved characters with entities so the browser renders them as visible text, and decoding reverses entities back to the original characters. It is the standard primitive for safely embedding user-provided strings in an HTML document.
How it works
Entities come in two families. Named entities use a readable name wrapped in & and ;: < renders <, > renders >, & renders &, " renders ", and ' renders '. Numeric entities reference the Unicode code point directly — decimal < or hexadecimal < — and can express any code point. Both families decode to the same character.
Encoding matters because the parser is greedy: seeing <script> it tries to build an element, and seeing a bare & it starts looking for an entity name. Escaping those bytes forces the browser to treat them as text. That is also why encoding is the first line of defense against XSS (Cross-Site Scripting): if attacker-controlled input is reflected into HTML with <, >, and " escaped, a payload like <script>alert(1)</script> renders as inert text rather than executing. Decoding reverses the process by scanning for &name; / &#NN; / &#xHH; patterns and substituting the matching character, so the round-trip is lossless.
Common use cases
- Safely displaying user comments or form input in an HTML page
- Showing a code snippet with HTML tags without it being parsed
- Preparing sample markup for a tutorial or docs page
- Hardening a template against reflected and stored XSS
- Decoding scraped text that arrives full of entities
Worked example
Take a snippet with a script tag and an ampersand:
<script>alert("a & b")</script>
After encoding it becomes entities that the browser will render as text instead of executing:
<script>alert("a & b")</script>
Decoding that output returns the original snippet exactly, because every entity maps back to one character.
Frequently asked questions
Which characters should be encoded?
In body content the four essential characters are < (less-than), > (greater-than), & (ampersand), and " (double quote). In attribute values you should also escape the quote character that wraps the value (" or '). Encoding these prevents the browser from treating user text as live HTML markup.
What is the difference between named and numeric entities?
A named entity uses a readable name such as < or &. A numeric entity references the Unicode code point directly, either in decimal (<) or in hexadecimal (<). They resolve to the same character; named entities are easier to read while numeric entities can represent any code point that has no name.
Does HTML encoding prevent XSS?
Yes, for content reflected into HTML text or attributes. Escaping <, >, and " stops the browser from parsing attacker-supplied <script> tags as real elements, so the payload renders as inert text instead of executing. This is context-dependent output encoding, which is the primary defense against reflected and stored XSS.
Why does my encoded text look the same after decoding?
Because decoding is the exact inverse of encoding. The decoder walks the string, finds entities such as < or <, and replaces each with the character it stands for, returning the original text. Encoding then escaping that text again yields the same entities, so round-tripping is lossless.
Is my text uploaded anywhere?
No. Encoding and decoding run entirely in your browser through string replacement. Nothing is sent to a server, so the tool is safe for templates, source code, and sensitive content.
HTML μΈμ½λ/λμ½λλ?
HTMLμ μΌλΆ λ¬Έμλ₯Ό μ체 λ¬Έλ²μ©μΌλ‘ μμ½ν΄ λ‘λλ€ — <, >, &, λ°μ΄ν λ¬Έμκ° κ·Έκ²μ
λλ€. κ·Έλμ μ½ν
μΈ μμ μ΄λ° λ¬Έμκ° λμ€λ©΄ κΈμ κ·Έλλ‘κ° μλλΌ λ¬Έμ μν°ν° μ°Έμ‘°(character entity reference)λ‘ μ¨μΌ ν©λλ€. HTML μΈμ½λλ μ΄ λ³νμ μλ°©ν₯μΌλ‘ μνν©λλ€. μΈμ½λ©μ μμ½ λ¬Έμλ₯Ό μν°ν°λ‘ λ°κΎΈμ΄ λΈλΌμ°μ κ° μ΄λ₯Ό 보μ΄λ ν
μ€νΈλ‘ λ λλ§νκ² λ§λ€κ³ , λμ½λ©μ μν°ν°λ₯Ό μλ λ¬Έμλ‘ λλ립λλ€. μ¬μ©μκ° μ 곡ν λ¬Έμμ΄μ HTML λ¬Έμμ μμ νκ² λΌμ λ£μ λ μ°λ νμ€ ν리미ν°λΈμ
λλ€.
μλ λ°©μ
μν°ν°μλ λ κ°μ§ κ³μ΄μ΄ μμ΅λλ€. μ΄λ¦ μν°ν°(named entity)λ &μ ;λ‘ κ°μΌ μ½κΈ° μ¬μ΄ μ΄λ¦μ μλλ€. <λ <, >λ >, &λ &, "λ ", 'λ 'λ‘ λ λλ§λ©λλ€. μ«μ μν°ν°(numeric entity)λ μ λμ½λ μ½λ ν¬μΈνΈλ₯Ό μ§μ μ°Έμ‘°ν©λλ€ — μμ§ < λλ μμ‘μ§ < — μ΄λ¦μ΄ μλ μ΄λ€ μ½λ ν¬μΈνΈλΌλ ννν μ μμ΅λλ€. λ κ³μ΄ λͺ¨λ κ°μ λ¬Έμλ‘ λμ½λ©λ©λλ€.
μΈμ½λ©μ΄ μ€μν μ΄μ λ νμκ° νμμ μ΄κΈ° λλ¬Έμ
λλ€. <script>λ₯Ό 보면 μμλ₯Ό λ§λ€λ € νκ³ , κ·Έλ₯ &λ₯Ό 보면 μν°ν° μ΄λ¦μ μ°ΎκΈ° μμν©λλ€. μ΄ λ°μ΄νΈλ€μ μ΄μ€μΌμ΄ννλ©΄ λΈλΌμ°μ κ° μ΄λ₯Ό ν
μ€νΈλ‘ μ·¨κΈνκ² λ§λλλ€. κ·Έλμ μΈμ½λ©μ΄ XSS(ν¬λ‘μ€ μ¬μ΄νΈ μ€ν¬λ¦½ν
) λ°©μ΄μ 첫 λ²μ§Έ λ°©ν¨μ΄κΈ°λ ν©λλ€. 곡격μκ° μ μ΄ν μ
λ ₯μ΄ <, >, "λ₯Ό μ΄μ€μΌμ΄νν μ± HTMLλ‘ μΆλ ₯λλ©΄, <script>alert(1)</script> κ°μ νμ΄λ‘λλ μ€νλμ§ μκ³ λ¬΄ν¨ν ν
μ€νΈλ‘ λ λλ§λ©λλ€. λμ½λ©μ μλ°©ν₯μΌλ‘, &name; / &#NN; / &#xHH; ν¨ν΄μ μ€μΊν΄ λμ λ¬Έμλ‘ μΉννλ―λ‘ μλ³΅μ΄ λ¬΄μμ€μ
λλ€.
μμ£Ό μ°λ κ²½μ°
- μ¬μ©μ λκΈμ΄λ νΌ μ λ ₯μ HTML νμ΄μ§μ μμ νκ² νμνκΈ°
- HTML νκ·Έλ₯Ό ν¬ν¨ν μ½λ μ‘°κ°μ΄ νμ±λμ§ μκ³ λ³΄μ΄κ² μΆλ ₯νκΈ°
- νν 리μΌ/λ¬Έμ νμ΄μ§μ© μν λ§ν¬μ μ€λΉ
- λ°μ¬ν/μ μ₯ν XSSμ λν ν νλ¦Ώ λ°©μ΄ κ°ν
- μν°ν° ν¬μ±μ΄λ‘ μμ§/μ μ₯λ ν μ€νΈ λμ½λ©
μ¬μ© μ
script νκ·Έμ μ°νΌμλκ° ν¬ν¨λ μ‘°κ°μ μλ‘ λλλ€.
<script>alert("a & b")</script>
HTML μΈμ½λ©μ κ±°μΉλ©΄ λΈλΌμ°μ κ° μ€ν λμ ν μ€νΈλ‘ λ λλ§νλ μν°ν° λ¬Έμμ΄μ΄ λ©λλ€.
<script>alert("a & b")</script>
μ΄ μΆλ ₯μ λμ½λ©νλ©΄ μλ μ‘°κ°μ΄ κ·Έλλ‘ λμμ΅λλ€. λͺ¨λ μν°ν°κ° ν λ¬Έμμ λ§€νλλ―λ‘ λν΄μ§κ±°λ μνλ κ²μ μμ΅λλ€.
μμ£Ό 묻λ μ§λ¬Έ
μ΄λ€ λ¬Έμλ₯Ό μΈμ½λ©ν΄μΌ νλμ?
λ³Έλ¬Έ μ½ν
μΈ μμ νμμ μΈ λ€ λ¬Έμλ <(λ³΄λ€ μμ), >(λ³΄λ€ νΌ), &(μ°νΌμλ), "(ν°λ°μ΄ν)μ
λλ€. μμ±κ°μμλ κ°μ κ°μΌ λ°μ΄ν λ¬Έμ(" λλ ')λ μ΄μ€μΌμ΄νν΄μΌ ν©λλ€. μ΄ λ¬Έμλ€μ μΈμ½λ©νλ©΄ λΈλΌμ°μ κ° μ¬μ©μ ν
μ€νΈλ₯Ό μ΄μ μλ HTML λ§ν¬μ
μΌλ‘ μ·¨κΈνμ§ μμ΅λλ€.
μ΄λ¦ μν°ν°μ μ«μ μν°ν°μ μ°¨μ΄λ?
μ΄λ¦ μν°ν°λ <, &μ²λΌ μ½κΈ° μ¬μ΄ μ΄λ¦μ μλλ€. μ«μ μν°ν°λ μ λμ½λ μ½λ ν¬μΈνΈλ₯Ό μ§μ μ°Έμ‘°νλ©°, μμ§(<) λλ μμ‘μ§(<) νμμ΄ μμ΅λλ€. λμ κ°μ λ¬Έμλ‘ ν΄μλ©λλ€. μ΄λ¦ μν°ν°κ° μ½κΈ° νΈνκ³ , μ«μ μν°ν°λ μ΄λ¦μ΄ μλ λͺ¨λ μ½λ ν¬μΈνΈλ₯Ό ννν μ μμ΅λλ€.
HTML μΈμ½λ©μ΄ XSSλ₯Ό λ§λμ?
λ€, HTML ν
μ€νΈλ μμ±μΌλ‘ μΆλ ₯λλ μ½ν
μΈ μ νν΄μ κ·Έλ μ΅λλ€. <, >, "λ₯Ό μ΄μ€μΌμ΄ννλ©΄ λΈλΌμ°μ κ° κ³΅κ²©μκ° λ£μ <script> νκ·Έλ₯Ό μ€μ μμλ‘ νμ±νμ§ λͺ»νλ―λ‘, νμ΄λ‘λκ° μ€νλλ λμ 무ν¨ν ν
μ€νΈλ‘ λ λλ§λ©λλ€. μ΄κ²μ΄ λ¬Έλ§₯μ λ°λ₯Έ μΆλ ₯ μ΄μ€μΌμ΄νμ΄λ©°, λ°μ¬ν/μ μ₯ν XSSμ λν 1μ°¨ λ°©μ΄ μλ¨μ
λλ€.
μΈμ½λ©ν ν μ€νΈλ₯Ό λμ½λ©νλ©΄ μ κ°μ 보μ΄λμ?
λμ½λ©μ΄ μΈμ½λ©μ μ νν μμ΄κΈ° λλ¬Έμ
λλ€. λμ½λλ λ¬Έμμ΄μ νμΌλ©° <λ < κ°μ μν°ν°λ₯Ό μ°Ύμ κ°κ°μ΄ κ°λ¦¬ν€λ λ¬Έμλ‘ μΉνν΄ μλ ν
μ€νΈλ₯Ό λλ €μ€λλ€. μ΄ ν
μ€νΈλ₯Ό λ€μ μΈμ½λ©νλ©΄ κ°μ μν°ν°κ° λμ€λ―λ‘ μλ³΅μ΄ λ¬΄μμ€μ
λλ€.
μ ν μ€νΈκ° μΈλΆλ‘ μ μ‘λλμ?
μλλλ€. μΈμ½λ©κ³Ό λμ½λ©μ μ μ μΌλ‘ λΈλΌμ°μ μμμ λ¬Έμμ΄ μΉνμΌλ‘ μ΄λ£¨μ΄μ§λλ€. μλ²λ‘ μ μ‘λλ κ²μ μμΌλ―λ‘ ν νλ¦Ώ, μμ€ μ½λ, λ―Όκ°ν λ΄μ©μλ μμ ν©λλ€.