Encode <, >, & and quotes for HTML, or decode entities back to characters.
If a string can contain < or & and you drop it into HTML, the browser will treat it as markup. Encoding turns those characters into entities. Decoding turns entities back into characters when you are reading source. This is not the same as JSON escape, and it does not remove tags the way the HTML-strip tools do. It rewrites characters.
&, <, > and both kinds of quotes.&#xHHHH;. Turn it off when the page is UTF-8 and only the markup characters must change.中, hex entities such as 中, and a short list of names: amp, lt, gt, quot, apos, nbsp, copy, reg, trade, mdash, ndash, hellip, laquo, raquo, bull, middot, euro, pound, yen, cent, sect, para, deg, plusmn, times, divide, micro. A name that is not in that list is left unchanged.Encode does not wrap the result in a tag and does not add a doctype. A bare & that is already the start of an entity will be escaped again if you encode twice, so & appears. Decode once to undo one layer. Named entities outside the list above, including many HTML5 names, stay as you pasted them. Numeric entities that are not a valid code point stay as text.
If you encoded, the ampersand itself was escaped, so you see the entity source. Switch to Decode to turn a known name into the character.
This page covers the names people hit in ordinary text, plus any numeric entity. An unknown name is kept so a typo is visible instead of being dropped.