How to Convert Markdown to HTML Online (Sanitized, Copy-Ready)
Convert Markdown to HTML in your browser: CommonMark and GFM output, an allowlist sanitizer that runs before you copy, a preview of the exact same HTML, and a standalone .html download.
What the converter actually does
Markdown is a compact way to write a document; HTML is what a browser reads. Markdown to HTML puts a Markdown pane on the left and the generated HTML on the right, and it updates as you type. The parser is CommonMark plus the GitHub extensions, so you get headings, paragraphs, ordered and unordered lists, tables with header rows, fenced code blocks that keep their language as a class, task lists, strikethrough, blockquotes, links and images with alt text — the constructs that appear in a README, a changelog or a documentation page.
The output is an HTML fragment, not a whole site: no <html>, <head> or <body>, and no stylesheet of its own. That is what you want when you are pasting into a CMS field, an email template, a JSX component or an existing page, because the fragment inherits the styles of whatever you drop it into. When you do want a file you can open on its own, the download button wraps the same fragment in a minimal standalone page.
The HTML is sanitized, and here is what that means
Markdown lets you write raw HTML, and that HTML is a real hole in a converter: a line of <script> in a README someone sent you would otherwise end up in your page. So the tool filters the whole result through an allowlist before it is displayed, copied or downloaded. Scripts, event handlers such as onclick, unsafe URLs including javascript: and data: values, iframes, <style> blocks, embedded SVG and form controls do not survive, and any tag outside the allowlist is unwrapped — its text stays, the tag goes. An <a> whose href was rejected keeps its words and loses the link. HTML comments and doctypes are dropped.
Allowlisted inline HTML is kept, because plenty of legitimate Markdown uses it: <mark>, <sub>, <sup>, <kbd>, <abbr> and <del> all pass through unchanged. A <mark> in a tutorial or a <kbd> in a keyboard-shortcut table is exactly why you wanted a converter rather than a regex. What does not pass is anything that can execute or phone home, and the tool says so on the page rather than leaving you to trust it.
Read the preview before you publish. A sanitizer is a filter over the HTML you wrote, not a guarantee about the page you are building: it cannot tell whether a heading level is right, whether a link points where you meant, or whether the fragment is safe in the specific place you are pasting it. A Content-Security-Policy is still the right defence for the page itself.
Copy, preview, and the standalone .html download
The HTML pane and the Preview tab are built from one string, so what you see rendered is exactly what you copy. That matters more than it sounds: converters that render from a different pass than they export regularly drift, and you end up debugging markup you never actually copied. Here, the same sanitized fragment feeds the pane, the preview, the clipboard and the file.
Copy puts that fragment on your clipboard. Download writes it into a standalone document — a doctype, a charset tag, one inline stylesheet for readable tables, quotes, code and images, and no scripts at all — which you can open, hand to a colleague or drop into a static host. The filename comes from the file you opened if you opened one, so notes.md becomes notes.html, and the name field is editable. When you are pasting rather than opening a file there is no source name at all, so the default is the placeholder markdown.html and the tool labels it as one. Path separators and other characters that are unsafe in a filename are replaced.
The optional highlight tokens, described accurately
Reading a code block in a wall of raw HTML is unpleasant, so there is a checkbox that wraps fenced code in span elements such as <span class="tok tok-keyword">. It is off by default, and that default is the honest choice: leave it off and the HTML you copy and download is clean, and turn it on when you are scanning a long snippet and want the keywords, strings, numbers and comments to stand out.
The highlighter behind it is a small one built into the tool, not a full parser. It is regex-based and covers JavaScript, TypeScript, JSON, HTML, CSS, Python, shell, SQL, YAML and Markdown. On ordinary code it is genuinely useful; on unusual or deliberately obfuscated syntax it can mark something as a keyword that is not one, which is why it is opt-in and why the tokens are described as decoration rather than correctness. If you need exact, parser-grade highlighting for a language the tool does not know, keep it off and highlight in your editor.
Limits: the 200,000 character cap, and privacy
Input is capped at 200,000 characters. The editor stops accepting input at the cap and says so, and a file larger than that is refused with the limit spelled out rather than being silently truncated — a large specification or a whole documentation tree belongs in an editor with real file handling, not in a browser pane. The counters above the panes show characters in, words, characters of HTML out, the size of that HTML in bytes, and the heading count, so you can see what a conversion actually cost before you ship it.
Everything runs in this tab. The Markdown, the generated HTML and any file you open with Open .md file are read locally and never uploaded; there is no server-side conversion step to leak anything to. A genuinely unparsable input — an unclosed fence, pathological nesting — surfaces as a plain message asking you to look at the structure rather than a blank pane or a stack trace, and empty input is simply an empty state, not an error.
Try it free — Markdown to HTML
Paste Markdown, get clean CommonMark/GFM HTML that is sanitized before you copy it, preview it, or download it as a standalone .html file.
Open Markdown to HTML