String escape tool
Paste a string and escape it for the format you need — or unescape an already-escaped value back to plain text.
About this tool
Every language that embeds strings in source code has to solve the same problem: how do you put a quote character inside a quoted string. The answers differ, and so do the consequences of getting them wrong. In JSON, escaping is strictly defined — double quotes only, backslash escapes for control characters, and \u notation for anything else — which is why a string with a raw newline in it is invalid JSON rather than merely ugly. JavaScript and Python allow single or double quotes and add their own escapes. Java has no raw string literal before text blocks. Regex escaping is a different problem again, since the characters needing protection are the metacharacters . * + ? [ ] ( ) { } | ^ $ and the backslash itself. SQL escaping deserves particular care: escaping quotes in a string you are concatenating into a query is not a defence against injection, it is a workaround for not using parameterised queries. This tool escapes and unescapes for JavaScript, JSON, Python, Java, SQL, and regex, entirely in your browser.
- 1
Paste your string into the input field.
- 2
Select the target language or format: JavaScript, JSON, Python, Java, SQL, or regex.
- 3
Choose Escape or Unescape — the result appears instantly.
- 4
Click Copy to use the escaped string in your code.
Escape a user-supplied string before embedding it in a SQL query or JSON payload.
Escape special characters in a pattern before using it as a regex literal.
Unescape a JSON-encoded string copied from an API response or log file.
Escape for JavaScript
He said "hello"
New lineHe said \"hello\"\nNew lineEscape for JSON
Path: C:\Users\AlicePath: C:\\Users\\AliceThe escaped string still breaks the parser
Cause: It was escaped for the wrong target. JSON does not permit single-quoted strings or trailing commas, and a Python-escaped string pasted into a JSON file will often carry constructs JSON rejects.
Fix: Escape for the format that will actually parse the string. When a value passes through several layers — a JSON body inside a shell command inside a YAML file — each layer needs its own escaping pass, applied in order.
Backslashes multiply on every round trip
Cause: Escaping an already-escaped string doubles each backslash. This happens when a value is escaped in application code and again by a serialiser that assumed it was raw.
Fix: Unescape once here to see how many layers are present, then remove the redundant escaping step. Serialisers almost always escape for you — the bug is usually escaping by hand before handing the value over.
Escaping quotes to build a SQL query
Cause: Manual escaping is not injection-safe. Character-set tricks, comment sequences, and second-order injection all defeat it, and one missed code path is enough.
Fix: Use parameterised queries or prepared statements so the value never becomes part of the query text. Reserve SQL escaping here for reading and understanding existing queries, not for constructing new ones.
These answers explain common string escape tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.
What characters does JSON escaping handle?
JSON escaping replaces double quotes, backslashes, and control characters (newline, tab, carriage return, and others) with their escape sequences so the string is valid inside a JSON value.
How is SQL escaping different from JSON?
SQL string escaping (ANSI standard) doubles any single quotes inside the string — turning ' into ''. This prevents SQL injection when a value is embedded in a single-quoted SQL literal.
What does regex escaping do?
Regex escaping adds a backslash before every character that has special meaning in a regular expression: . ^ $ * + ? { } [ ] | ( ) \. This makes the string safe to use as a literal match pattern.
When would I need to escape a JavaScript string?
When building a string literal programmatically — for example injecting content into a script tag or a template. JavaScript escaping handles quotes, backslashes, newlines, and other control characters.