String Escaper – Escape & Unescape Strings Online
Escape or unescape text for JSON, JavaScript, HTML, and other formats. Your text stays in your browser during normal use.
String escaper
JSON uses JSON.stringify rules, including control characters and unpaired surrogates.
Ready. Text stays in this browser.
0 characters · 0 lines
Output
Escaped or unescaped text appears here as you type.
Waiting for input
Advertisement
String Escaper Quick Answer
A string escaper rewrites characters that a format treats as syntax. Escaping does not change the meaning of the text. It changes how that text is written so a parser can tell data from syntax.
Escaping and encoding are different jobs. Escaping protects a string inside a language: quotes in JSON, tags in HTML, metacharacters in a regex. Encoding changes how bytes are represented for transport. Percent-encoding a URL is encoding. Turning a newline into \n inside JSON is escaping.
Context decides the rules. The same quote is \" in JSON, " in HTML, and untouched in a CSV field that is already wrapped in quotes. Using one format’s rules in another format is how strings get double-escaped or silently broken.
How to Escape or Unescape a String
- Paste or type the raw text, or the escaped text you want to read.
- Choose Escape to produce the encoded form, or Unescape to turn it back into readable text.
- Choose JSON, JavaScript, HTML, URL, regex, SQL, CSV, or XML. Quote and URL options appear only when that format uses them.
- The output updates as you type. Fix the format if the result is not the context you are pasting into.
- Copy the output or download it as a .txt file. The input stays on this page until you clear it.
What Can You Escape With This Tool?
JSON String Escaping
JSON escaping prepares text for a JSON string. Quotes, backslashes, and controls such as newline, tab, carriage return, backspace, and form feed follow JSON.stringify. Use it when a value is going into an API body. Surrounding quotes are optional, for when you need the whole literal instead of only the body.
Hello "World" becomes Hello \"World\". After you escape a fragment, the JSON Formatter can show whether the surrounding document is valid JSON.
JavaScript String Escaping
JavaScript escaping builds a string literal for single quotes, double quotes, or backticks. The chosen delimiter is escaped, and backticks also escape ${ so a template does not interpolate. Line and paragraph separators are written as \u2028 and \u2029.
Use it when pasting a path, a multiline log line, or user text into source. C:\Users\John becomes C:\\Users\\John.
HTML Escaping
HTML mode escapes &, <, >, quotes, and apostrophes so they render as text. It does not execute the input. It also does not decode the whole named-entity catalog. For , ©, and numeric entities beyond those five characters, use the HTML Entity Encoder & Decoder.
URL Encoding
URL mode percent-encodes text. Component mode uses encodeURIComponent, which encodes /, ?, and &. Full URI mode uses encodeURI and leaves URL structure characters alone. Decoding uses the matching function and reports a bad % instead of dropping characters. For query strings and full addresses, the URL Encoder & Decoder is the dedicated tool.
Regex Escaping
Regex mode escapes literal text for a pattern, using RegExp.escape when the browser has it and the same syntax-character rules otherwise. Unescape is disabled: \d and an escaped literal are not safely reversible. Build the pattern here, then try it in the Regex Tester.
SQL String Escaping
SQL mode doubles single quotes, which is the standard SQL string rule. O'Brien becomes O''Brien. It does not add MySQL backslash escapes. Escaping a literal is not a substitute for a parameterized query. Application code should pass values as parameters.
CSV Escaping
CSV mode quotes a field that contains a comma, a quote, or a line break, and doubles quotes inside that field. A plain value with none of those characters is left alone. Unescape accepts either a plain field or one quoted pair.
XML Escaping
XML mode escapes &, <, >, quotes, and apostrophes with the five predefined entities, including '. Unescape also reads numeric character references. Control characters that XML 1.0 forbids are rejected instead of being written into the result.
String Escaping Examples
Quotes
A JSON string body escapes the quote. The letters stay as written.
Before
Hello "World"After
Hello \"World\"Windows path
Each backslash in a JavaScript string has to be written twice.
Before
C:\Users\John\DocumentsAfter
C:\\Users\\John\\DocumentsNewline and tab
The line break and tab become \n and \t instead of raw control characters.
Before
A line
indentedAfter
A line\n\tindentedHTML markup
Tags and the ampersand become text, so they are not treated as markup.
Before
<div>Hello & welcome</div>After
<div>Hello & welcome</div>Regex metacharacters
Parentheses, plus, and question mark are escaped so a pattern can search for them literally.
Before
price (USD) + tax?After
\x70rice\x20\(USD\)\x20\+\x20tax\?Nested JSON quotes
Quotes and the backslash inside an API fragment are escaped again when the fragment is placed inside another JSON string.
Before
{"label":"size","value":"6\" widget"}After
{\"label\":\"size\",\"value\":\"6\\\" widget\"}Common Ways People Search for String Escaping
The usual question is “how do I escape a string?” The useful version is “escape it for which parser?” Escaping quotes in a string means escaping the delimiter that literal uses. A JSON string and a JavaScript string both use backslashes, but a template literal also cares about ${.
“How do I escape a JSON string?” means quotes, backslashes, and controls. “How do I unescape a string?” or “how do I remove backslashes from an escaped string?” means reversing one layer and reading the result before doing it again. “How do I escape special characters?” depends on whether those characters are markup, a pattern, or a URL.
Regex questions are about matching the characters literally. URL questions are about percent-encoding. HTML questions are about showing < and & as text. This page covers those conversions and links to the tool that goes deeper when the job is only entities, only URLs, only patterns, or only a JSON document.
Common String Escaping Mistakes
Using the wrong context
HTML entities will not make a JSON string valid, and JSON escapes will show up as raw backslashes in an HTML page.
Confusing encoding with escaping
Percent-encoding is for URLs. Base64 is for bytes. Neither one is how a JavaScript literal escapes a newline. Compare byte encodings with the Base64 Encoder & Decoder when that is actually the job.
Double escaping
Running escape twice produces \\\\ where one backslash belonged. Unescape one layer, check the text, then decide if another layer is really there.
Incomplete backslash handling
Replacing \n before \\ turns a literal backslash plus n into a newline. This tool scans sequences from the left instead of doing that replacement chain.
Forgetting newlines and tabs
A line break pasted into JSON or JavaScript is a control character, not the two letters \n, until it is escaped.
Treating HTML escaping as complete XSS protection
Escaping the five characters is the right step for HTML text. It does not sanitize URLs, event-handler attributes, or CSS. Context still matters.
Using SQL escaping instead of parameters
Doubling quotes fixes a string literal. It does not replace prepared statements, and it does not understand every vendor’s backslash rules.
Hand-escaping regex characters
A short list that misses / or { still compiles and then matches the wrong text. Escape the literal, then test the pattern.
Related Developer Tools
- Need to clean and validate JSON after escaping it? Use the JSON Formatter.
- Need every HTML named entity, not only the five markup characters? Use the HTML Entity Encoder & Decoder.
- Need to encode a query string or a full address? Use the URL Encoder & Decoder.
- Need to see what a pattern matches? Use the Regex Tester.
- Need to encode bytes rather than escape syntax? Use the Base64 Encoder & Decoder.
- Need to compare text before and after escaping? Use the Text Diff Tool.
- Browse the rest of the set on Developer Tools.
Frequently Asked Questions
What is a string escaper?
A string escaper rewrites characters that would be special in a particular format. The same characters stay readable, but quotes, backslashes, markup, or pattern syntax no longer break that format.
What does string escaping do?
It inserts the escape form required by one context. JSON turns a newline into \n. HTML turns < into <. A regex turns ( into \(. The character is still the data; the representation changed.
How do I escape a string online?
Paste the text, choose Escape, choose the format you are pasting into, and copy the output. Unescape does the reverse when that format has a defined decode step.
What is the difference between escape and unescape?
Escape turns raw text into the form a format expects. Unescape turns that form back into raw text. Unescape once for each time the text was escaped. A second pass is a separate step, not an automatic extra.
How do I escape a JSON string?
Choose JSON. Quotes, backslashes, and control characters follow JSON string rules. Turn on surrounding quotes when you need a complete JSON string literal rather than only the body.
How do I escape a JavaScript string?
Choose JavaScript, then single quotes, double quotes, or backticks. The selected delimiter is escaped. Backticks also escape ${ so a template literal does not interpolate.
How do I escape special characters in a regex?
Choose Regex and paste the literal text you want to find. Metacharacters such as . * + ? ( ) and / are escaped. Test the pattern in the Regex Tester before you rely on it.
Is string escaping the same as URL encoding?
No. URL encoding turns characters into %HH bytes for a URL. Backslash escaping is for string literals and patterns. This page can percent-encode, and the URL Encoder & Decoder is the dedicated tool for query strings and full URLs.
Can I unescape a double-escaped string?
Yes, one layer at a time. If JSON was escaped twice, unescape twice and check the text after each pass. Doing both layers in one step would guess, so this tool does not.
Is my text uploaded to a server?
No. Escape, unescape, copy, and download run in your browser. EverydayTools does not receive the text for processing. Do not leave secrets on a shared or unlocked computer.
Privacy and Accuracy
Your text stays in your browser during normal use. Escape, unescape, copy, and download do not send it to EverydayTools for processing. The page can remember the format and options on this device. It does not store the text.
Match the format to the place you will paste the result. A converted string can still be wrong for a different parser, and SQL quote doubling does not replace parameterized queries.