XML Escape / Unescape
Escape the special characters in text (&, <, >, " and ') into XML entities so it is safe inside an XML element or attribute, or unescape XML entities and numeric character references back to plain text.
Input
Escape mode only. Use all five for attribute values; element text only needs & < >.
Output
More ways to use this tool
REST API
curl -X POST https://api.iotools.cloud/v1/tool/xml-escape-unescape \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"inputText": "<a href=\"x\">Tom & Jerry's</a>",
"mode": "escape",
"scope": "all"
}'Swap in your own key from your account. The tool's fields are the body — no wrapper.
Ask an AI agent
Use the IOTools `xml-escape-unescape` tool (XML Escape / Unescape) on this input:
YOUR_INPUT_HEREPaste this at any agent connected to the IOTools MCP server, then add your input.
Embed widget
<iframe
src="https://iotools.cloud/embed/xml-escape-unescape/"
width="100%" height="520" frameborder="0" scrolling="no" loading="lazy"
title="XML Escape / Unescape — iotools.cloud"
sandbox="allow-scripts allow-forms allow-same-origin allow-downloads allow-popups allow-popups-to-escape-sandbox"
allow="clipboard-write"
style="width:100%;border:1px solid #e5e7eb;border-radius:12px;overflow:hidden"></iframe>
<script src="https://iotools.cloud/embed.js" async></script>Drop this into your own page — free, no key required, just a link back.
| Cost per API/MCP call | From 5 credits |
|---|---|
| Need more credits? | View pricing |
Also available with
Guides
Escape the characters that are illegal in XML content — or turn XML entities back into readable text. Paste your input, pick a mode, and the result updates instantly. Everything runs in your browser, so nothing you type is uploaded.
What gets escaped
XML reserves five characters: & becomes &, < becomes <, > becomes >, " becomes " and ' becomes '. Inside element text only & and < strictly need escaping (> is escaped by convention), while attribute values also need the quote character that delimits them. Use Element text only when the output goes between tags, and All five when it goes into an attribute.
How to use it
- Paste the text into the input box.
- Choose Escape to produce XML-safe text, or Unescape to decode it.
- Copy or download the result.
Unescape mode decodes the five predefined entities plus decimal (©) and hexadecimal (©) character references. HTML-only entities such as are not defined in XML, so they are left as-is; invalid character references are also left untouched.
Related tools
Check that the result is well-formed with the XML Validator, or tidy a whole document with the XML Formatter.
Is my data private?
Yes. Escaping and unescaping use plain JavaScript in your browser; your text never leaves your device.