Markdown to HTML

Convert Markdown to safe, clean HTML.

Reverse
Input
MARKDOWN input
Output
Result
Options

Leave off for untrusted input, raw HTML can contain scripts.

About this tool


This converts the Markdown people actually write (headings, emphasis, links, lists, tables, task lists, blockquotes and fenced code blocks) into clean semantic HTML with no wrapper classes or framework assumptions.

The default that matters most is that raw HTML in the source is escaped rather than passed through. Markdown permits inline HTML, which means a document from an untrusted source can carry a script tag. Escaping by default makes the output safe to render; you can opt into passthrough when you trust the input.

How to use it

  1. Paste or upload your markdownDrop a file onto the input pane, use the file picker, or paste the text directly.
  2. Adjust the options if neededThe defaults suit most input; open Options to change the behaviour.
  3. Convert to HTMLPress Convert to HTML, or use Ctrl+Enter (Cmd+Enter on macOS).
  4. Copy or downloadCopy the result, or download it as a .html file.

Worked examples


Each example below is executed against this tool by the test suite, so what you see is what the tool actually produces.

Common Markdown constructs

Input

# Title

Some **bold** and a [link](https://example.com).

- one
- two

Output

<h1>Title</h1>
<p>Some <strong>bold</strong> and a <a href="https://example.com">link</a>.</p>
<ul>
  <li>one</li>
  <li>two</li>
</ul>

Clean semantic HTML with no added classes or wrapper elements.

Raw HTML is neutralised

Input

Before <script>alert(1)</script> after

Output

<p>Before &lt;script&gt;alert(1)&lt;/script&gt; after</p>

The script tag is escaped, so the browser displays it rather than running it.

What to watch for


The details that decide whether a conversion is correct, and where information can be lost without any error being raised.

Raw HTML is escaped unless you allow it
Because Markdown allows embedded HTML, converting untrusted input with passthrough enabled is a cross-site scripting vector. By default a <script> tag in the source becomes visible text. Enable "Allow raw HTML" only for documents you control, such as your own README.
Dangerous link schemes are blocked
Even with raw HTML disabled, a Markdown link can carry a javascript: URL. Those are rejected along with vbscript: and data: URLs, except data: images, which are a legitimate way to embed a small picture. The link renders as plain text instead.
Fenced code blocks and language hints
Triple-backtick blocks become <pre><code>, and a language hint becomes a class="language-x" attribute, which is the convention highlight.js and Prism expect. Code content is always escaped, so a snippet containing markup displays rather than executing.
Tables and task lists
GitHub-style pipe tables become real <table> markup, with the colons in the separator row translated into text-align styles. Task list items become disabled checkboxes, matching how GitHub renders them.
Hard line breaks need two trailing spaces
A single newline inside a paragraph is just a space in the output, which is standard Markdown behaviour and often surprises people. Two trailing spaces produce a <br />, and a blank line starts a new paragraph.

Limitations


  • Supports CommonMark plus tables, task lists and strikethrough, not footnotes, definition lists or math.
  • Reference-style link definitions are not resolved.
  • Processing happens in your browser, so very large inputs are bounded by available memory. Files above roughly 10 MB are handled but will feel slower, and multi-hundred-megabyte files are better suited to a command-line tool.

Questions


Is the output safe to insert into a page?
With the default settings, yes, raw HTML is escaped and dangerous URL schemes are stripped. If you enable "Allow raw HTML", the output is only as safe as your source.
Why did my single line break disappear?
Standard Markdown treats a single newline as a space. Use two trailing spaces for a line break, or a blank line for a new paragraph.
Which Markdown flavour is this?
CommonMark for the core syntax, plus the GitHub extensions people rely on: tables, task lists and strikethrough. Footnotes, definition lists and math are not supported.