HTML entities represent characters that would otherwise be interpreted as markup — like <, >, and & — or characters outside the plain ASCII range, using a &name; or &#code; sequence instead.
Encoding turns raw text into a form that's safe to embed inside HTML markup without being mistaken for a tag or attribute; decoding reverses that, turning entity sequences back into the characters they represent.
Everything runs locally in your browser — decoding uses the browser's own HTML parser (never executing any script), and nothing you paste is sent to a server.
What are HTML entities for?
They let you represent characters that would otherwise be interpreted as markup (like <, >, &) or that aren't easily typed, by encoding them as a name (&) or numeric code (&) that browsers render as the literal character.
Why does my page show &amp; instead of &?
That's usually a sign of double-encoding — an already-encoded & was encoded a second time, turning & into &amp;; decode once to fix it.
Is decoding entities here safe from XSS?
Yes — this tool only converts text to text; it never renders the decoded output as live HTML, so no markup is executed.