Escape / Unescape

Escape or unescape strings for JavaScript, JSON, HTML, SQL, or CSV.

The Escape / Unescape tool converts a string between plain text and the escaped form that is safe for a particular context, supporting JavaScript, JSON, HTML, SQL, and CSV. Escaping makes special characters inert so they cannot break the surrounding code or markup, which is how you protect a value before you embed it in a string literal, a template, or a query. Unescaping reverses the process so you can read what was stored. It is especially helpful when you are debugging a string that looks broken because of quotes or backslashes, or when you need to produce the exact escaped form a language expects. Escaping is what makes data safe to embed in a context that has its own syntax, and the exact form depends entirely on that context. A string placed inside a JSON document must have its quotes and backslashes escaped; a value inserted into HTML must have its markup characters replaced with references; a literal inside SQL must have quotes handled the way the database expects; and a CSV field must be quoted if it contains a comma or a newline. Getting the target right is the whole point, because the same input needs a different transformation in each case, and using the wrong one leaves the value able to break out of its context. That is precisely how injection vulnerabilities arise: a value that is untrusted and unescaped is interpreted as code or markup rather than data. The reverse direction is equally practical for debugging, because a string that was stored escaped often looks broken when you read it raw, with backslashes and quote sequences obscuring what the original text actually was. Running it in the browser keeps internal values local.

Private by design. Every tool runs 100% in your browser — your code, text, and tokens never leave your device. Nothing is uploaded or stored.
Output

Result appears here.

Frequently Asked Questions

When do I need HTML escaping?

Escape <, >, &, and quotes before inserting untrusted text into markup so it displays as text instead of executing as tags.

What about URL escaping?

Reserved characters are percent-encoded so a value survives a query string or path segment without breaking parsing.

Does it run locally?

Yes, entirely in your browser.

Related tools from our network

A focused set of free calculators and guides across related topics — no account required.