What this does
Escapes text so it can be pasted safely inside a string literal, command line, pattern, or field, and does the reverse: turns an escaped string back into plain text. If the escaped text is malformed, you get the exact line and column of the problem.
Formats
- JSON:
\" \\ \n \r \t \b \fand\uXXXXfor other control characters, identical toJSON.stringify. Unescape accepts exactly the escapes JSON allows. - JavaScript: also escapes the single quote, and unescapes
\xHH,\u{…}, legacy octal,\0, and line continuations. - Java and C: Java uses
\uXXXXand octal; C adds\a \v \? \xHH \UXXXXXXXX. In C, byte escapes are decoded as UTF-8 and rejected if they do not form valid text. - Shell: single quotes with the
'\''idiom, or double quotes escaping\ " $ `. Unescape reads any mix of quoting and backslashes. The$'…'form is not supported. - Regular expression: escapes syntax characters so text matches literally. Unescape reverses it, and refuses real regex tokens like
\d, since those are not text. - HTML:
& < > "and', optionally numeric entities for non-ASCII. Unescape understands every HTML5 named entity and numeric reference. - CSV field: quotes only when needed and doubles inner quotes; choose the delimiter.
- SQL: doubled single quotes (standard), or backslash escapes for MySQL.
Example
He said "hi" followed by a line break and C:\temp, escaped as JSON, becomesHe said \"hi\"\nC:\\temp. Switch to Unescape (or press Swap) to get the original back.
Security note
Escaping is not a substitute for parameterized SQL queries or for avoiding shell invocation with untrusted input. Use it for building literals and for reading data, not as your only defense.
Privacy
This runs entirely in your browser. Nothing is uploaded.