String Escaper
Escape and unescape strings for any language
Escape or unescape text for JSON, JavaScript, SQL, regex, shell, C, CSV, XML and URL contexts.
- Escape
- JSON
- SQL
- Shell
How to use String Escaper
- Choose Escape or Unescape under Direction and pick a Format, such as JSON string, a JavaScript, Python, Java, C, C# or Go literal, SQL, Regular expression, shell or PowerShell, CSV field, XML / HTML, URL component or a Unicode escape style.
- Paste or drop your text into Text (or Escaped text when unescaping), or press Try an example. The result updates as you type, and the hint under the options says where the output goes.
- For language string formats, tick Escape non-ASCII too to turn every character outside ASCII into an escape sequence.
- Check the round-trip note under the output, which confirms that unescaping the result gives back your text exactly. Copy or download the output, or press Use output as input to reverse the direction.
How it works
Each format has its own escaper and parser, written to that language’s literal rules. For string literals the output is the text that goes between the quotes: backslashes, the quote character and line breaks are escaped, other control characters use the language’s hex, octal or \u escapes, and U+2028/U+2029 are escaped where they would break a literal. The JavaScript template format also escapes ${, Java avoids \u for line breaks and quotes, and with Escape non-ASCII too C writes non-ASCII as UTF-8 octal bytes.
Shell and PowerShell output is a complete quoted word, quotes included. Standard SQL doubles single quotes and MySQL uses backslash escapes. A CSV field is quoted only when it contains a quote, comma, line break or leading or trailing space (RFC 4180). XML escapes &, < and >, plus quotes, tabs and line breaks in attributes, and the URL format uses encodeURIComponent.
Unescaping reads the sequences that language accepts, including \x, octal, \u, \u{…}, \U and surrogate pairs, decodes byte escapes as UTF-8, and points to the line and column of the first invalid escape. Everything runs in your browser.
Limits
- Escaping refuses text with a lone surrogate (half of an emoji) in every format except SQL, CSV, XML / HTML, shell and PowerShell.
- Unescaping expects the literal’s contents without the surrounding quotes, except for shell, PowerShell and CSV, which take the whole quoted word or field. Shell input must be one word: unquoted spaces are reported.
- Raw and verbatim strings (Python
r"…", C#@"…", Go backticks) aren’t supported, and unescaping a shell"…"word refuses an unescaped$or backtick rather than expanding it. - XML unescaping decodes numeric references and a fixed set of common named entities (such as
&, ,©,—); other named entities are left as written. - Opened or dropped files must be text and at most 10 MB.
Privacy
Escaping and unescaping run entirely in your browser, and nothing is uploaded or saved; the site’s Content Security Policy blocks requests to other servers. Copy share link puts your text, the direction, the format and the non-ASCII option in the link’s # fragment, which browsers don’t send to servers, so anyone with the link can read the text. Send to… hands text between tools through this tab’s session storage and removes it as soon as the receiving tool reads it.
Frequently asked questions
Should I use this to build SQL queries?
Prefer query parameters (prepared statements), which keep data and SQL apart. Escaping by hand is for when you really need a literal, for example in a migration or a one-off script. Pick SQL (MySQL backslash) only if your MySQL server doesn’t use NO_BACKSLASH_ESCAPES.
Why does the shell output include quotes?
A shell value is only safe as a complete word. In single quotes nothing is expanded, so a single quote inside has to close the quote, add an escaped \' and reopen it: it's becomes 'it'\''s'.
What is the difference between JSON and JavaScript escaping?
JSON only allows \", \\, \/, \b, \f, \n, \r, \t and \uXXXX, so with Escape non-ASCII too emoji become surrogate pairs. JavaScript also accepts \x, \v, \0, \u{…} and line continuations, and escapes whichever quote you picked.
Why does the C output turn é into two escapes?
With Escape non-ASCII too, C and C++ get each character as its UTF-8 bytes in octal, because a plain string literal is a sequence of bytes. é is the two bytes \303\251.
Which characters does the regex format escape?
The metacharacters \ ^ $ . * + ? ( ) [ ] { } | and /, so the text matches literally inside /…/ and also with the u flag, which rejects unnecessary escapes.
What does the round-trip check mean?
After escaping, the output is unescaped again and compared with your text. A green check means the escaped form reads back exactly; a warning means something wouldn’t survive the round trip.
More tools
- Clean Image: Inspect and remove hidden image metadata
- JWT Decoder: Decode and verify JSON Web Tokens
- Diff Checker: Compare two texts line by line
- JS Runner: Run JavaScript and TypeScript in your browser
- JSON Formatter: Format, validate and minify JSON
- Encode / Decode: Base64, URL, HTML entity and hex
- Hash Generator: MD5, SHA and HMAC of any text
- UUID Generator: Generate UUID v4 and v7 in bulk
- Timestamp Converter: Unix time ↔ human dates
- Regex Tester: Test regular expressions live
- URL Parser: Break a URL into its parts
- HTTP Status Codes: Look up any HTTP status code
- MIME Type Lookup: File extension ↔ MIME type
- Password Generator: Strong random passwords and passphrases
- Random String Generator: Random tokens, IDs and keys
- Slug Generator: Turn titles into URL slugs
- Case Converter: camelCase, snake_case, Title Case and more
- Word Counter: Count words, characters and reading time
- JSON to TypeScript: Generate TypeScript types from JSON
- JSON Diff: Compare two JSON documents structurally
- JSON to SQL: Turn JSON arrays into SQL inserts
- YAML ↔ JSON: Convert between YAML and JSON
- XML ↔ JSON: Convert between XML and JSON
- CSV ↔ JSON: Convert between CSV and JSON
- CSV Viewer: View, sort and filter CSV files
- SQL Formatter: Format and beautify SQL queries
- cURL ↔ Fetch: Convert cURL commands to fetch and back
- Markdown Editor: Write Markdown with a live preview
- Text Cleaner: Remove duplicate lines, empty lines and extra spaces
- Find & Replace: Find and replace in any text
- Cron Expression Builder: Build and explain cron schedules
- User-Agent Parser: Identify browser, OS and device from a user agent
- HTTP Headers Inspector: Paste response headers and get them explained
- JWT Generator: Create and sign test JSON Web Tokens
- Certificate Inspector: Decode PEM certificates and keys
- Meta Tag Inspector: Check a page's SEO and social tags
- UTM Builder: Build campaign URLs with UTM parameters
- URL Cleaner: Strip tracking parameters from links
- Robots.txt Generator: Create and test a robots.txt file
- Sitemap Generator: Create an XML sitemap from a list of URLs
- Image Compressor: Shrink JPEG, WebP and AVIF images in your browser
- Image Resizer: Resize images by pixels, percentage or to fit a box
- Image Converter: Convert between PNG, JPEG, WebP and AVIF
- Image to Base64: Encode images as Base64 data URIs and decode them back
- SVG Optimizer: Minify and sanitize SVG files
- Favicon Generator: Make favicon.ico, Apple and Android icons from an image or emoji
- Color Converter: HEX, RGB, HSL, OKLCH and contrast checks
- Number Base Converter: Binary, octal, decimal, hex and float bits
- IP / CIDR Calculator: Subnets, masks and IP ranges for IPv4 and IPv6
- JSONPath Query: Query JSON with JSONPath expressions
- JSON Schema Validator: Validate JSON against a schema, or generate one
- Semver Checker: Check versions against semver ranges
- chmod Calculator: Unix permissions: rwx ↔ octal
- .env Diff: Compare and validate .env files
- TOTP Generator: Generate and verify 2FA codes
- Unicode Inspector: See every character, code point and hidden symbol
- Mock Data Generator: Generate realistic fake data
- QR Code Generator: Create QR codes for links, Wi-Fi and contacts
- Lorem Ipsum Generator: Placeholder text in paragraphs, sentences or words
- Date Calculator: Date differences, business days and durations
- Unit Converter: Convert bytes, lengths, weights, temperatures and more
- Query CSV with SQL: Run SQL queries on CSV files
- PDF Merge & Split: Merge, split, reorder and rotate PDFs
- PDF Metadata Cleaner: See and remove hidden PDF metadata
- Office Metadata Cleaner: Remove author and revision data from Word, Excel and PowerPoint
- Images to PDF: Combine images into one PDF
- Image Editor: Crop, rotate, resize and adjust images
- Encrypt / Decrypt Text: Encrypt text with a passphrase (AES-GCM)
- SSH Key Generator: Generate Ed25519 and RSA SSH keys locally
- Email Header Analyzer: Trace an email's path and check SPF, DKIM and DMARC
- JSON to Code: Generate Go, Python, Rust, Java, C# and Kotlin models from JSON
- docker run ↔ Compose: Convert docker run commands to docker-compose and back
- Color Palette Extractor: Pull the dominant colours out of any image
- Password Strength Checker: How long would your password take to crack?
- SPF / DKIM / DMARC Checker: Validate and explain email DNS records
- Kubernetes YAML Checker: Validate and explain Kubernetes manifests
- .gitignore Generator: Build a .gitignore from presets
- CSP Builder: Build and check a Content-Security-Policy
- JSON-LD Generator: Create schema.org structured data
- Open Graph Image Generator: Make 1200×630 social preview images
- CSS Generator: Gradients, shadows, clamp() and more
- Time Zone Meeting Planner: Find meeting times across time zones