Call the free HTML encode API endpoint
curl -X POST https://aisenseapi.com/services/v1/html_encode \
-H "Content-Type: application/json" \
-d '{"data": "<b>\"Tom\" & Jerry</b>"}'{"html_encoded_data":"<b>"Tom" & Jerry</b>"}The other way is the HTML decode API endpoint.
What is escaped
| In | Out |
|---|---|
& | & |
< | < |
> | > |
" | " |
' | ' |
Nothing else changes: é stays é, since a page served as UTF-8 shows it as it is. Every & is escaped, an entity already in the text included, so escape text once, as it goes into the page.
Send the data as {"data": "..."} with Content-Type: application/json, or as the raw request body with any other content type. The raw body takes binary data as it is: curl --data-binary @file.bin -H "Content-Type: application/octet-stream".
Errors
| Status | error | When |
|---|---|---|
| 400 | No data to encode. | No data string and no body |
| 400 | The data is not UTF-8 text. | Bytes that are not text |
| 413 | Data over 1 MiB. | More than 1 MiB in one request |
Each refusal also carries fix, a sentence saying what to send instead.
Common uses
Show what people wrote
Put a comment, a name or a message into a page so it shows as text and never runs as markup.
Attributes
Fill a title, alt or value attribute with text that has quotes in it.
Reports from agents
Let an agent that writes an HTML report escape the values it did not write itself.
Privacy and limits
Nothing is stored. The HTML encode answer is worked out while the request is open and the data is gone with it. The access log records the path and the status, not the body.
The base URL is https://aisenseapi.com/services/v1. There is no key, no account and no sign-up step. One request carries at most 1 MiB of data, and the service-wide limit is 5000 requests per IP address per day. Every endpoint in the collection is listed on the Free public REST APIs reference, and the encodings side by side on Encoding APIs.