String Escaper – Escape & Unescape Strings Online

Escape or unescape text for JSON, JavaScript, HTML, and other formats. Your text stays in your browser during normal use.

String escaper

JSON uses JSON.stringify rules, including control characters and unpaired surrogates.

Ready. Text stays in this browser.

0 characters · 0 lines

Output

Escaped or unescaped text appears here as you type.

Waiting for input

Advertisement

String Escaper Quick Answer

A string escaper rewrites characters that a format treats as syntax. Escaping does not change the meaning of the text. It changes how that text is written so a parser can tell data from syntax.

Escaping and encoding are different jobs. Escaping protects a string inside a language: quotes in JSON, tags in HTML, metacharacters in a regex. Encoding changes how bytes are represented for transport. Percent-encoding a URL is encoding. Turning a newline into \n inside JSON is escaping.

Context decides the rules. The same quote is \" in JSON, " in HTML, and untouched in a CSV field that is already wrapped in quotes. Using one format’s rules in another format is how strings get double-escaped or silently broken.

How to Escape or Unescape a String

  1. Paste or type the raw text, or the escaped text you want to read.
  2. Choose Escape to produce the encoded form, or Unescape to turn it back into readable text.
  3. Choose JSON, JavaScript, HTML, URL, regex, SQL, CSV, or XML. Quote and URL options appear only when that format uses them.
  4. The output updates as you type. Fix the format if the result is not the context you are pasting into.
  5. Copy the output or download it as a .txt file. The input stays on this page until you clear it.

What Can You Escape With This Tool?

JSON String Escaping

JSON escaping prepares text for a JSON string. Quotes, backslashes, and controls such as newline, tab, carriage return, backspace, and form feed follow JSON.stringify. Use it when a value is going into an API body. Surrounding quotes are optional, for when you need the whole literal instead of only the body.

Hello "World" becomes Hello \"World\". After you escape a fragment, the JSON Formatter can show whether the surrounding document is valid JSON.

JavaScript String Escaping

JavaScript escaping builds a string literal for single quotes, double quotes, or backticks. The chosen delimiter is escaped, and backticks also escape ${ so a template does not interpolate. Line and paragraph separators are written as \u2028 and \u2029.

Use it when pasting a path, a multiline log line, or user text into source. C:\Users\John becomes C:\\Users\\John.

HTML Escaping

HTML mode escapes &, <, >, quotes, and apostrophes so they render as text. It does not execute the input. It also does not decode the whole named-entity catalog. For &nbsp;, &copy;, and numeric entities beyond those five characters, use the HTML Entity Encoder & Decoder.

URL Encoding

URL mode percent-encodes text. Component mode uses encodeURIComponent, which encodes /, ?, and &. Full URI mode uses encodeURI and leaves URL structure characters alone. Decoding uses the matching function and reports a bad % instead of dropping characters. For query strings and full addresses, the URL Encoder & Decoder is the dedicated tool.

Regex Escaping

Regex mode escapes literal text for a pattern, using RegExp.escape when the browser has it and the same syntax-character rules otherwise. Unescape is disabled: \d and an escaped literal are not safely reversible. Build the pattern here, then try it in the Regex Tester.

SQL String Escaping

SQL mode doubles single quotes, which is the standard SQL string rule. O'Brien becomes O''Brien. It does not add MySQL backslash escapes. Escaping a literal is not a substitute for a parameterized query. Application code should pass values as parameters.

CSV Escaping

CSV mode quotes a field that contains a comma, a quote, or a line break, and doubles quotes inside that field. A plain value with none of those characters is left alone. Unescape accepts either a plain field or one quoted pair.

XML Escaping

XML mode escapes &, <, >, quotes, and apostrophes with the five predefined entities, including &apos;. Unescape also reads numeric character references. Control characters that XML 1.0 forbids are rejected instead of being written into the result.

String Escaping Examples

Quotes

A JSON string body escapes the quote. The letters stay as written.

Before

Hello "World"

After

Hello \"World\"

Windows path

Each backslash in a JavaScript string has to be written twice.

Before

C:\Users\John\Documents

After

C:\\Users\\John\\Documents

Newline and tab

The line break and tab become \n and \t instead of raw control characters.

Before

A line
	indented

After

A line\n\tindented

HTML markup

Tags and the ampersand become text, so they are not treated as markup.

Before

<div>Hello & welcome</div>

After

&lt;div&gt;Hello &amp; welcome&lt;/div&gt;

Regex metacharacters

Parentheses, plus, and question mark are escaped so a pattern can search for them literally.

Before

price (USD) + tax?

After

\x70rice\x20\(USD\)\x20\+\x20tax\?

Nested JSON quotes

Quotes and the backslash inside an API fragment are escaped again when the fragment is placed inside another JSON string.

Before

{"label":"size","value":"6\" widget"}

After

{\"label\":\"size\",\"value\":\"6\\\" widget\"}

Common Ways People Search for String Escaping

The usual question is “how do I escape a string?” The useful version is “escape it for which parser?” Escaping quotes in a string means escaping the delimiter that literal uses. A JSON string and a JavaScript string both use backslashes, but a template literal also cares about ${.

“How do I escape a JSON string?” means quotes, backslashes, and controls. “How do I unescape a string?” or “how do I remove backslashes from an escaped string?” means reversing one layer and reading the result before doing it again. “How do I escape special characters?” depends on whether those characters are markup, a pattern, or a URL.

Regex questions are about matching the characters literally. URL questions are about percent-encoding. HTML questions are about showing < and & as text. This page covers those conversions and links to the tool that goes deeper when the job is only entities, only URLs, only patterns, or only a JSON document.

Common String Escaping Mistakes

Using the wrong context

HTML entities will not make a JSON string valid, and JSON escapes will show up as raw backslashes in an HTML page.

Confusing encoding with escaping

Percent-encoding is for URLs. Base64 is for bytes. Neither one is how a JavaScript literal escapes a newline. Compare byte encodings with the Base64 Encoder & Decoder when that is actually the job.

Double escaping

Running escape twice produces \\\\ where one backslash belonged. Unescape one layer, check the text, then decide if another layer is really there.

Incomplete backslash handling

Replacing \n before \\ turns a literal backslash plus n into a newline. This tool scans sequences from the left instead of doing that replacement chain.

Forgetting newlines and tabs

A line break pasted into JSON or JavaScript is a control character, not the two letters \n, until it is escaped.

Treating HTML escaping as complete XSS protection

Escaping the five characters is the right step for HTML text. It does not sanitize URLs, event-handler attributes, or CSS. Context still matters.

Using SQL escaping instead of parameters

Doubling quotes fixes a string literal. It does not replace prepared statements, and it does not understand every vendor’s backslash rules.

Hand-escaping regex characters

A short list that misses / or { still compiles and then matches the wrong text. Escape the literal, then test the pattern.

Frequently Asked Questions

What is a string escaper?

A string escaper rewrites characters that would be special in a particular format. The same characters stay readable, but quotes, backslashes, markup, or pattern syntax no longer break that format.

What does string escaping do?

It inserts the escape form required by one context. JSON turns a newline into \n. HTML turns < into &lt;. A regex turns ( into \(. The character is still the data; the representation changed.

How do I escape a string online?

Paste the text, choose Escape, choose the format you are pasting into, and copy the output. Unescape does the reverse when that format has a defined decode step.

What is the difference between escape and unescape?

Escape turns raw text into the form a format expects. Unescape turns that form back into raw text. Unescape once for each time the text was escaped. A second pass is a separate step, not an automatic extra.

How do I escape a JSON string?

Choose JSON. Quotes, backslashes, and control characters follow JSON string rules. Turn on surrounding quotes when you need a complete JSON string literal rather than only the body.

How do I escape a JavaScript string?

Choose JavaScript, then single quotes, double quotes, or backticks. The selected delimiter is escaped. Backticks also escape ${ so a template literal does not interpolate.

How do I escape special characters in a regex?

Choose Regex and paste the literal text you want to find. Metacharacters such as . * + ? ( ) and / are escaped. Test the pattern in the Regex Tester before you rely on it.

Is string escaping the same as URL encoding?

No. URL encoding turns characters into %HH bytes for a URL. Backslash escaping is for string literals and patterns. This page can percent-encode, and the URL Encoder & Decoder is the dedicated tool for query strings and full URLs.

Can I unescape a double-escaped string?

Yes, one layer at a time. If JSON was escaped twice, unescape twice and check the text after each pass. Doing both layers in one step would guess, so this tool does not.

Is my text uploaded to a server?

No. Escape, unescape, copy, and download run in your browser. EverydayTools does not receive the text for processing. Do not leave secrets on a shared or unlocked computer.

Privacy and Accuracy

Your text stays in your browser during normal use. Escape, unescape, copy, and download do not send it to EverydayTools for processing. The page can remember the format and options on this device. It does not store the text.

Match the format to the place you will paste the result. A converted string can still be wrong for a different parser, and SQL quote doubling does not replace parameterized queries.