Skip to main content
Version: 1.28 (Current)

Sanitize Html

Audience: Low-code Engineers

Skill Prerequisites: HTML, Tokens

Cleans a piece of HTML and stores the result in a token. It can remove tags, remove tags together with their content, strip attributes, remove scripts and add rel="nofollow" to links. Broken HTML is repaired along the way, for example unclosed tags are closed.

It uses the HtmlSanitizer library. Unlike the library's defaults, the action starts permissive: it keeps every tag, attribute, class and CSS property unless you tell it to remove them.

note

This action requires the Scripting feature (Standard.Scripting) to be licensed. If it isn't licensed, the action fails with an error.

Typical Use Cases​

  • Clean HTML typed by users before you save it or show it on a page, for example when a field has Secure Input turned off
  • Clean HTML received from a Server Request or an incoming email before you store it
  • Clean the HTML made by Markdown to Html when the markdown comes from users or an AI model
  • Remove tags you don't want in an email or PDF, such as iframe or style
  • Add rel="nofollow" to every link in user content

Don't use it to​

  • Prevent SQL injection. Use bind tokens in Run SQL Query instead.
  • Extract the main content of a web page. Use Clean HTML instead.
  • Replace text patterns. Use Regex Replace instead.
  • Sanitize several values at once. Use one action per value.
Action NameDescription
Markdown to HtmlConverts Markdown to HTML. Sanitize its output when the markdown isn't trusted.
Display MessageShows a message. Token values are inserted without encoding, so sanitize user HTML first.
Clean HTMLExtracts the main content from a full HTML page.
Regex ReplaceReplaces text that matches a regular expression.
Send EmailSends an email. Sanitize user HTML before you put it in the body.
Generate PDFCreates a PDF from an HTML template.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
Html ContentThe HTML to clean, usually a token such as [Comments].Yesempty stringNo
Convert links to nofollowSets rel="nofollow" on every <a> tag. An existing rel value is replaced.NoFalseNo
Disable scriptsRemoves <script> tags with their content. It also removes a built-in list of attributes from every tag: the on... event handlers (such as onclick, onload, onerror) and href, src, action, formaction, xlink:href and srcdoc. See What Disable scripts removes.NoTrueNo
Toggle between Exclude/Allow HTML tag listsUnchecked (Exclude mode): only the tags in Excluded Tags are stripped. Checked (Allow mode): every tag is stripped except the ones in Allowed Tags.NoFalse (Exclude mode)No
Excluded TagsShown in Exclude mode. Tags to strip, for example iframe. The tag is removed but its content stays. All other tags are kept.Yesempty listNo
Allowed TagsShown in Allow mode. The only tags to keep, for example p, b, a. Every other tag is removed but its content stays. With an empty list, all tags are stripped.Yesempty listNo
Removable TagsTags to remove together with everything inside them, for example style.Yesempty listNo
Removable attributesAttributes to remove from every tag, for example style or class. All other attributes are kept.Yesempty listNo
Output Token NameThe token name that gets the cleaned HTML, for example CleanComments.Noempty stringNo

Tag and attribute names aren't case-sensitive.

Output Parameters Reference​

ParameterDescription
Output Token NameHolds the cleaned HTML. If Output Token Name is empty, nothing is stored.

How the HTML is processed​

  • Excluded or not allowed tags are unwrapped. The tag goes, its text and child tags stay and are processed too.
  • Removable Tags are deleted with all their content.
  • Attributes are all kept, except the ones in Removable attributes and, when Disable scripts is on, the built-in script list.
  • Classes and inline CSS are kept. To drop them, add class or style to Removable attributes.
  • URLs aren't checked. A link like href="javascript:..." isn't cleaned. It's only removed when Disable scripts is on, because that removes every href.
  • HTML comments are removed.
  • Broken HTML is repaired. The HTML is parsed and written back out, so unclosed tags are closed and special characters in text are encoded, for example & becomes &amp;.
  • Only the body content is returned. If you pass a full page, the <html>, <head> and <body> wrappers aren't in the result.
  • Empty input is returned as-is.

What Disable scripts removes​

Disable scripts is on by default. Besides <script> tags, it removes these attributes from every tag:

  • Mouse: onclick, ondblclick, onmousedown, onmouseup, onmouseover, onmouseout, onmousemove, onmouseenter, onmouseleave, oncontextmenu
  • Keyboard: onkeydown, onkeypress, onkeyup
  • Form: onsubmit, onchange, oninput, oninvalid, onreset, onselect
  • Focus: onfocus, onblur, onfocusin, onfocusout
  • Window: onload, onbeforeunload, onunload, onresize, onscroll, onerror
  • Media: onplay, onpause, onended, ontimeupdate, onvolumechange, onwaiting
  • Drag and clipboard: ondrag, ondrop, ondragstart, ondragover, oncopy, oncut, onpaste
  • Animation and pointer: onanimationstart, onanimationend, onanimationiteration, ontransitionend, ontoggle, onpointerdown, onpointerup, onwheel
  • URL attributes: href, src, action, formaction, xlink:href, srcdoc

This means links lose their target and images lose their source, even safe ones. If you need to keep links and images, turn Disable scripts off and remove scripts yourself: add script to Removable Tags and the event attributes you care about to Removable attributes. Keep in mind that javascript: links then pass through.

Before and after​

Input used in all three samples:

<p onclick="steal()">Hi <b>there</b></p><script>alert(1)</script><a href="https://example.com">Site</a>

Default settings (Exclude mode, empty lists, Disable scripts on):

<p>Hi <b>there</b></p><a>Site</a>

Disable scripts off, Removable Tags script, Removable attributes onclick, Convert links to nofollow on:

<p>Hi <b>there</b></p><a href="https://example.com" rel="nofollow">Site</a>

Allow mode, Allowed Tags p, Disable scripts off, Removable Tags script:

<p onclick="steal()">Hi there</p>alert(1)Site

The last sample shows two traps of Allow mode: attributes on allowed tags are kept, and the script's code stays as text. See Considerations.

Considerations​

  • Scripting license. The action needs the Standard.Scripting feature. If it isn't licensed, the action fails with an error.
  • Removable Tags run last. Stripped tags are unwrapped first, so their content stays. In Allow mode, a tag in Removable Tags, including the script tag added by Disable scripts, must also be in Allowed Tags for its content to be deleted. In Exclude mode, don't put it in Excluded Tags.
  • One list for both modes. Excluded Tags and Allowed Tags are the same setting. If you switch modes, your list stays but its meaning flips. Check the list after switching.
  • Attributes are always a deny list. Even in Allow mode, only the attributes you list (plus the Disable scripts list) are removed.
  • The defaults aren't a full XSS filter. Out of the box, the action keeps iframe, object, form, style tags and inline styles. For untrusted input, use Allow mode with a short list, or add risky tags to Removable Tags.
  • Compared to Secure Input. The Secure Input option on form fields uses an allow list of tags, attributes and CSS properties, removes classes and keeps href and src. This action gives you finer control but starts from "keep everything".
  • Display Message doesn't encode tokens. Display Message inserts token values as HTML. Sanitize user content before you show it there.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Remove scripts and event handlers​

This action uses the default settings. Scripts, event attributes, href and src are removed. The result is stored in CleanComments.

{
"Title": "Sanitize Html",
"ActionType": "Parsing.SanitizeHtml",
"Description": "Remove scripts from the comments",
"Parameters": {
"HtmlContent": "[Comments]",
"ForceAnchorNoFollow": false,
"DisableScripts": true,
"IsAllowedMode": false,
"TagsList": [],
"RemovableTags": [],
"RemovableAttributes": [],
"OutputTokenName": "CleanComments"
}
}

This action keeps a short list of tags and keeps links. Disable scripts is off so href survives. script, style and iframe are deleted with their content, which is why they're also in the allowed list. Event attributes and inline styles are removed, and links get rel="nofollow".

{
"Title": "Sanitize Html",
"ActionType": "Parsing.SanitizeHtml",
"Description": "Keep basic formatting in the bio",
"Condition": "[Bio] != \"\"",
"Parameters": {
"HtmlContent": "[Bio]",
"ForceAnchorNoFollow": true,
"DisableScripts": false,
"IsAllowedMode": true,
"TagsList": [
"p",
"br",
"b",
"strong",
"i",
"em",
"ul",
"ol",
"li",
"a",
"script",
"style",
"iframe"
],
"RemovableTags": [
"script",
"style",
"iframe"
],
"RemovableAttributes": [
"style",
"onclick",
"onmouseover",
"onerror",
"onload"
],
"OutputTokenName": "CleanBio"
}
}

javascript: links aren't removed in this setup. If users can't be trusted with links, keep Disable scripts on.

Revised 09/27/2026