Web support is still experimental. APIs and behavior can change in future releases without a major version bump. Expect breaking changes until the web path is stabilized.
- Inline marks: bold, italic, underline, strikethrough, inline code
- Headings (h1-h6)
- Blockquote, code block
- Ordered lists, unordered lists, checkbox lists
- Images (via
setImageref method and optionalonPasteImageswhen pasting image data) - Manual links (via
setLinkref method) - Mentions
- Automatic link detection
getHTML,setValue, selection mapping- Core callbacks:
onChange,onChangeState,onFocus,onBlur,onSelectionChange - Submit props:
submitBehaviorandonSubmitEditing.returnKeyTypeis only a hint, it maps to enterkeyhint (done,go,next,previous,search,send,default/enter). Not all values ofReturnKeyTypeOptionsare supported, the behavior of this prop is heavily dependent on the browser's capabilities. - Input theming via
placeholderTextColor,cursorColorandselectionColorprops - Keyboard shortcuts for formatting
useHtmlNormalizer- Setting text alignment via
setTextAlignment() textShortcuts
See Web Keyboard Shortcuts for the up-to-date list of Web keyboard shortcuts.
returnKeyLabel: ignored on web, it's not possible to set it inside a browser.- Context menu:
contextMenuItemsis ignored. - RN layout ref methods:
measure,measureInWindow,measureLayout, andsetNativePropsare no-ops. ViewProps: Props inherited fromViewbeyond the implemented subset are not forwarded.
- Customizing the styling using props:
style,htmlStyle,selectionColor. selectablepropuseHtmlNormalizeronLinkPressandonMentionPresscallbacks
ellipsizeMode: ignored on web.numberOfLines: ignored on web.- RN layout ref methods:
measure,measureInWindow,measureLayout, andsetNativePropsare no-ops.
On web, HTML is sanitized automatically with DOMPurify on both input and output. This reduces XSS risk, but you should still treat untrusted HTML with caution and apply your own server-side sanitization.
EnrichedTextsanitizes itschildrenbefore rendering.EnrichedTextInputsanitizes every HTML entry point —defaultValue, thesetValueref method, and pasted HTML — as well as its output fromgetHTMLand theonChangeHtmlcallback.
By default, sanitization strips links with non-standard protocols (e.g. custom://…). Both EnrichedText and EnrichedTextInput accept a web-only sanitizationConfig prop whose linkRegex field lets you control which link URIs survive.
linkRegex maps directly to DOMPurify's ALLOWED_URI_REGEXP, so it replaces the default allow-list rather than extending it — remember to keep the standard protocols you still want to permit:
<EnrichedText
sanitizationConfig={{
// Permit the usual protocols plus a custom "custom://" scheme.
linkRegex:
/^(?:(?:(?:f|ht)tps?|mailto|tel|custom):|[^a-z]|[a-z+.-]+(?:[^a-z+.:-]|$))/i,
}}
>
{html}
</EnrichedText>When sanitizationConfig is omitted, DOMPurify's built-in default is used.
Note:
sanitizationConfig.linkRegexonly controls what sanitization keeps. It is independent of the top-levellinkRegexprop, which controls autolink detection while typing. To both autolink and preserve a custom protocol, configure both.
To attach custom data to a mention, use the data- prefix (e.g. data-user-id) to make sure they survive sanitization. Attributes passed to the setMention ref method are properly sanitized.
Both EnrichedText and EnrichedTextInput are client-only components. They rely on browser-only APIs (DOMParser, DOMPurify, TipTap) and are not designed for server-side rendering (SSR).
If your application uses SSR (Next.js, Remix, Gatsby, etc.), make sure these components only render on the client.