URL & HTML Encoder

Free URL & HTML Entity Encoder / Decoder

Encode or decode a URL component, or convert HTML entities like & and < back and forth. Free, instant, nothing uploaded.

Last updated 3 September 2026

Two different jobs

URL encoding escapes characters that would otherwise break a URL's structure — spaces become %20, & becomes %26, and so on — so a value can safely sit inside a query string or path segment.

HTML entity encoding escapes characters that have a special meaning in HTML markup — <, > and & — so text displays literally instead of being mistaken for a tag or entity reference. A price like "<$50" needs entity-encoding before it can safely appear in a web page.

URL encoding and HTML entities solve different problems

They look similar and get confused constantly, but they protect against different things. URL encoding — percent-encoding — exists because certain characters have structural meaning inside a web address. A & separates parameters, a ? starts the query string, a # starts a fragment. If those characters appear inside a value rather than between values, they have to be escaped or the address is parsed wrongly.

HTML entities exist because certain characters have structural meaning inside a document. A raw < starts a tag, and a raw & starts an entity. Writing them as &lt; and &amp; tells the browser to display the character rather than act on it.

A worked example

Suppose a search box receives fish & chips. Putting that straight into a link produces ?q=fish & chips, and the server reads two parameters: q=fish and an empty chips. Percent-encoded, it becomes ?q=fish%20%26%20chips and arrives intact.

Now suppose the page echoes that search term back as Results for fish & chips. Here the URL encoding is wrong — the user would see the literal percent signs. What is needed is the HTML entity form, fish &amp; chips, which displays correctly. Same input, two different escapes, chosen by where the text is going: into an address, or into a document.

Common questions

When do I need URL encoding?

Whenever a value goes inside a URL and might contain characters that have a special meaning there — spaces, &, ?, # and others. Encoding replaces them with a %-escaped form so the URL still parses correctly.

Why do I see &amp; instead of & on a web page?

In HTML, & starts an entity reference, so a literal ampersand has to be written as &amp; to display correctly. The same applies to < and >, which would otherwise look like the start of a tag.

Is URL encoding the same as HTML entity encoding?

No — they solve different problems. URL encoding protects characters that are special inside a URL. HTML entity encoding protects characters that are special inside HTML markup. A value might need one, the other, or occasionally both, depending on where it ends up.

When do I use percent-encoding versus HTML entities?

Percent-encoding when the text is going into a web address — a query parameter, a path segment, a redirect target. HTML entities when the text is going into the visible body of a page. The same input needs different escaping depending on its destination.

Why does a space become %20 sometimes and + other times?

Both appear in the wild. %20 is the correct percent-encoding of a space and works anywhere in a URL. The + form comes from HTML form submission, where it is valid only inside the query string. In a path segment a + means a literal plus sign, not a space.

Does encoding text make it safe from injection attacks?

Only if you encode for the right context. HTML-entity encoding protects text placed in page content, but it does not protect text placed inside a JavaScript block, a CSS value or an SQL query — each of those needs its own escaping. Encoding is contextual, not universal.

The other tools