What it does
The string escape tool converts text into a form that can be placed inside a string literal, and converts escaped strings back into plain text. It supports nine targets: JSON, JavaScript, Java and C#, Python, SQL string literals, CSV fields, XML text and attributes, regular expressions and POSIX shell commands. Each one follows the rules of that language, so the result can be pasted directly into your code without syntax errors.
Typical uses are putting a multi-line message or a Windows path into a JSON config file, embedding a snippet of HTML in a JavaScript string, quoting a file name with spaces for a shell script, or turning a literal search term such as price (USD) into a regular expression that matches it exactly.
How to use
- Choose Escape or Unescape.
- Pick the language or format.
- Paste your text into the input, or click Sample. The result updates as you type.
- Copy the output, or press Use as input to reverse the conversion and check that it round-trips.
For JSON, JavaScript, Java/C# and Python you can also escape every non-ASCII character, which gives a pure ASCII string that survives any file encoding.
Example
The same line escaped for different targets:
Input: He said "hi" in C:\Temp
JSON: He said \"hi\" in C:\\Temp
SQL: He said "hi" in C:\Temp (only ' is doubled)
Regex: He said "hi" in C:\\Temp
Shell: 'He said "hi" in C:\Temp'
Rules per format
- JSON: escapes quotes, backslashes and control characters, exactly like
JSON.stringify. - JavaScript: also escapes single quotes, backticks, vertical tabs and the line separators U+2028 and U+2029.
- Java / C#: backslash escapes and
\uXXXX; unescaping also accepts Java octal escapes and C#\xand\Uescapes. - Python: backslash escapes with
\x,\uand\U; unknown escapes are kept as written. - SQL: doubles single quotes for standard SQL string literals.
- CSV: wraps the value in double quotes and doubles inner quotes when it contains a comma, quote, line break or surrounding spaces.
- XML: replaces the five predefined entities; unescaping also decodes numeric character references.
- Regex: puts a backslash before every character with a special meaning, so the pattern matches the text literally.
- Shell: wraps the value in single quotes, which disable all expansion in POSIX shells, and writes embedded quotes as
'\''.
FAQ
› What does escaping a string mean?
Some characters have a special meaning inside a string literal, such as the quote that ends it or a line break. Escaping replaces them with a safe sequence, usually a backslash followed by a letter, so the string can be pasted into source code, a query or a file without breaking it.
› Do I paste the quotes around the string?
No. Paste only the content. The escaped result is what goes between the quotes in your code. For CSV and shell, which quote whole values, the tool adds the surrounding quotes itself when they are needed.
› Is SQL escaping enough to stop SQL injection?
Doubling single quotes produces a valid string literal, which helps when you write a query by hand or prepare a migration script. In application code always use parameterized queries or prepared statements instead of building SQL from strings.
› Why does unescaping report an unknown escape sequence?
Each language accepts a different set of escapes. JSON, for example, has no \x or \0, so the tool reports the position of the first sequence the selected language would reject. Python keeps unknown escapes such as \d unchanged, just like the Python interpreter does.
› Is my text uploaded?
No. Escaping and unescaping run in your browser and nothing is sent to a server.