Developer TOOL

Markdown Preview

Render a documented subset of Markdown as HTML: headings, emphasis, lists, code, block quotes, links and rules. Furtu builds React elements and lets React escape the text, so raw HTML in your source is shown as characters and a javascript: link loses its target. Nothing is fetched and no image is loaded, because a preview that makes requests is not a local preview.

Processed locally in your browser — your file is never uploaded

DEVELOPERMarkdown Preview
Processed locally
Input
Output

The convention used by issue trackers. Off, paragraphs are joined the way strict Markdown joins them.

Off, a URL is text. On, http and https addresses become links, subject to the same scheme check as an explicit link.

Useful for checking which constructs the preview did not support.

Your text never leaves this page.

How markdown preview works

  1. Paste MarkdownThe subset above is rendered as you type.
  2. Read the notesUnsupported HTML, dropped links and unclosed fences are reported.
  3. Toggle the sourceSwitch to the plain text to see exactly what was in the document.

What you get

See your Markdown rendered — safely, with nothing able to execute. Everything happens inside this page: the file is read by your browser, transformed in memory and handed straight back to you as a download. There is no upload queue, no waiting for a server, and nothing left behind when you close the tab.

Supported formats

This tool works on text you paste or type, so there is no file format to worry about. Nothing you type is sent anywhere.

Limitations, stated up front

  • The supported subset is small on purpose. Tables, footnotes, reference links, task lists, underlined headings and raw HTML are not implemented.
  • No syntax highlighting inside code blocks. The language is shown as a label and the text is left alone.
  • The output is static HTML, so anything interactive — a script, a form, an embedded video — is out of scope.

Why Furtu will not render raw HTML

A Markdown preview is the one place where pasted text, an HTML parser and script execution meet. The safe way to do it is not to sanitise an HTML string after the fact, which is where filter bypasses come from, but to never build an element the parser did not ask for. This renderer constructs React elements from a fixed list of tags and lets React escape every text node and every attribute, so a script tag in the source is a handful of visible characters and nothing more. Link targets go through a scheme allow-list as well, because a link is the one attribute that can act without a script tag at all.

Frequently asked questions

Why is my HTML showing as text?

On purpose. Markdown allows raw HTML, and rendering it would mean pasting a document could inject a script, a style sheet or a tracking pixel into the page. Furtu escapes every HTML tag it finds and tells you how many there were, so you can see what was in the source without it becoming part of the page.

Why do my images not appear?

A preview that loads an image makes a request, and that request tells somebody else which address read the document and from where. Furtu shows the alternative text instead. For an image that already exists on disk, the image tools in Furtu are the honest route.

Which Markdown does it support?

A deliberate subset: headings, paragraphs, ordered and unordered lists, block quotes, horizontal rules, fenced code blocks with a language label, inline code, bold, italic, bold-italic, strikethrough, links, autolinks, backslash escapes and hard line breaks. Tables, footnotes, reference links, task lists, definition lists, underlined headings and raw HTML are not rendered — each appears as its own text rather than as something broken.

What is this safe against?

Injection, specifically. Tags can only come from the list above, because that is the only way this renderer creates an element; every piece of text is escaped by React when it is rendered; and a link target is checked against an allow-list of http, https, mailto and tel, plus relative paths and fragments. A javascript: or data: URL keeps its text and loses its target. Furtu never assigns your input to a raw markup sink.

Is my Markdown uploaded?

No. It is parsed in your browser. If you are previewing an unreleased README or a draft announcement, it stays on your device.