Skip to main content

XML Escape / Unescape

API reference

Escape the special characters in text (&, <, >, " and ') into XML entities so it is safe inside an XML element or attribute, or unescape XML entities and numeric character references back to plain text.

Input

Escape mode only. Use all five for attribute values; element text only needs & < >.

Output

Result
Was this helpful?

More ways to use this tool

REST API

curl -X POST https://api.iotools.cloud/v1/tool/xml-escape-unescape \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "inputText": "<a href=\"x\">Tom & Jerry's</a>",
    "mode": "escape",
    "scope": "all"
  }'

Swap in your own key from your account. The tool's fields are the body — no wrapper.

Ask an AI agent

Use the IOTools `xml-escape-unescape` tool (XML Escape / Unescape) on this input:

YOUR_INPUT_HERE

Paste this at any agent connected to the IOTools MCP server, then add your input.

Embed widget

<iframe
  src="https://iotools.cloud/embed/xml-escape-unescape/"
  width="100%" height="520" frameborder="0" scrolling="no" loading="lazy"
  title="XML Escape / Unescape — iotools.cloud"
  sandbox="allow-scripts allow-forms allow-same-origin allow-downloads allow-popups allow-popups-to-escape-sandbox"
  allow="clipboard-write"
  style="width:100%;border:1px solid #e5e7eb;border-radius:12px;overflow:hidden"></iframe>
<script src="https://iotools.cloud/embed.js" async></script>

Drop this into your own page — free, no key required, just a link back.

Cost per API/MCP callFrom 5 credits
Need more credits?View pricing

Also available with

Guides

Escape the characters that are illegal in XML content — or turn XML entities back into readable text. Paste your input, pick a mode, and the result updates instantly. Everything runs in your browser, so nothing you type is uploaded.

What gets escaped

XML reserves five characters: & becomes &amp;, < becomes &lt;, > becomes &gt;, " becomes &quot; and ' becomes &apos;. Inside element text only & and < strictly need escaping (> is escaped by convention), while attribute values also need the quote character that delimits them. Use Element text only when the output goes between tags, and All five when it goes into an attribute.

How to use it

  1. Paste the text into the input box.
  2. Choose Escape to produce XML-safe text, or Unescape to decode it.
  3. Copy or download the result.

Unescape mode decodes the five predefined entities plus decimal (&#169;) and hexadecimal (&#xA9;) character references. HTML-only entities such as &nbsp; are not defined in XML, so they are left as-is; invalid character references are also left untouched.

Check that the result is well-formed with the XML Validator, or tidy a whole document with the XML Formatter.

Is my data private?

Yes. Escaping and unescaping use plain JavaScript in your browser; your text never leaves your device.

xmlentities&amp;&lt;cdataattributeencodedecodecharacter referencesoaprss

Love the tools? Lose the ads.

One payment clears every ad from your account, for good. No subscription, no tracking.