>_devtools

String Escape & Unescape

Escape and unescape text for JSON, JavaScript, Java, C, shell, regex, HTML, CSV, and SQL strings, with error positions.

What this does

Escapes text so it can be pasted safely inside a string literal, command line, pattern, or field, and does the reverse: turns an escaped string back into plain text. If the escaped text is malformed, you get the exact line and column of the problem.

Formats

  • JSON: \" \\ \n \r \t \b \f and \uXXXX for other control characters, identical to JSON.stringify. Unescape accepts exactly the escapes JSON allows.
  • JavaScript: also escapes the single quote, and unescapes \xHH,\u{…}, legacy octal, \0, and line continuations.
  • Java and C: Java uses \uXXXX and octal; C adds\a \v \? \xHH \UXXXXXXXX. In C, byte escapes are decoded as UTF-8 and rejected if they do not form valid text.
  • Shell: single quotes with the '\'' idiom, or double quotes escaping\ " $ `. Unescape reads any mix of quoting and backslashes. The $'…' form is not supported.
  • Regular expression: escapes syntax characters so text matches literally. Unescape reverses it, and refuses real regex tokens like \d, since those are not text.
  • HTML: & < > " and ', optionally numeric entities for non-ASCII. Unescape understands every HTML5 named entity and numeric reference.
  • CSV field: quotes only when needed and doubles inner quotes; choose the delimiter.
  • SQL: doubled single quotes (standard), or backslash escapes for MySQL.

Example

He said "hi" followed by a line break and C:\temp, escaped as JSON, becomesHe said \"hi\"\nC:\\temp. Switch to Unescape (or press Swap) to get the original back.

Security note

Escaping is not a substitute for parameterized SQL queries or for avoiding shell invocation with untrusted input. Use it for building literals and for reading data, not as your only defense.

Privacy

This runs entirely in your browser. Nothing is uploaded.