String Escape / Unescape
Escape text for 11 languages and formats, or turn escapes back into text.
Converted in your browser; nothing is uploaded.
Format
About the String Escape / Unescape
Paste text and get it ready to put inside source code or a data file: quotes, backslashes, line breaks and special characters are escaped the way each language requires. Or paste an escaped string — copied from a log, a JSON response or source code — and get the plain text back. Eleven formats are covered: JSON strings, JavaScript (single, double or template quotes), HTML entities, XML, CSV fields, SQL string literals (standard, MySQL and PostgreSQL), regular expressions, POSIX shell arguments, C/C++, Java and C#, Python, and Unicode code points in eight notations (U+00E9, \u00E9, \u{E9}, é …).
After every conversion a round-trip check reads the result back with the same rules and confirms that it gives exactly your text, so you can paste it with confidence. Unescaping is strict: an invalid escape such as \x in JSON is reported with its line and column instead of being guessed at.
How to use it
- Choose Escape (text → escaped) or Unescape (escaped → text).
- Paste your text and pick the format, for example JSON string or SQL string.
- Set the options that appear, such as the quote style or whether to escape non-ASCII characters.
- Copy the result. The round-trip check under it shows whether reading it back gives your text exactly. Swap turns the result into the input and flips the direction.
Examples
She said "hi" C:\temp
"She said \"hi\"\n\tC:\\temp"
O'Brien
'O''Brien'
it's here
'it'\''s here'
<b>Tom & Jerry</b>
<b>Tom & Jerry</b>
café 😀
'caf\xe9 \U0001f600'
caf\u00e9 \ud83d\ude00
café 😀
Format JSON string or Unicode code points, direction Unescape.
Common uses
- Putting text with quotes and line breaks into JSON, a JavaScript string or a config file.
- Reading escaped strings from logs and API responses (\n, \u00e9, &).
- Writing a literal value into an SQL statement for a one-off query or a migration script.
- Matching text literally in a regular expression (file names, prices, URLs).
- Passing a file name or a message with spaces and quotes as one shell argument.
What each format escapes
- JSON (RFC 8259):
"\and control characters (\n,\t,\u0000); optionally/and every non-ASCII character (\u00e9, emoji as a surrogate pair). Unescaping accepts the string with or without its quotes; a quoted string copied with indentation, its line break or a final,or;is read without them (this applies to JavaScript, SQL, C-like and Python strings too). - JavaScript (ECMA-262): the chosen quote,
\, line breaks, U+2028/U+2029 and control characters (\x1b);${in template literals. Octal escapes are refused, as in strict mode. - HTML (WHATWG):
& < > " 'always; non-ASCII optionally as names (é) or numbers. Unescaping knows all 2,231 named references and decodes them as browsers do, including names without the final semicolon (©2026→ ©2026). - XML (XML 1.0, 5th edition): the five predefined entities; tabs and line breaks as references for attribute values. Characters XML cannot hold at all (most control characters) are reported. Unescaping also reads CDATA sections and explains that HTML names such as
are not defined in XML. - CSV (RFC 4180): a value with the delimiter, a quote or a line break is put in quotes and its quotes are doubled. Tick Each line is a separate value for a whole column.
- SQL: standard SQL doubles single quotes; MySQL also uses backslash escapes (
\\,\',\n,\0,\Z); PostgreSQLE'…'strings use C-style escapes; SQL Server can take anN'…'prefix. - Regular expressions: JavaScript escapes its syntax characters
^ $ \ . * + ? ( ) [ ] { } |and/; the Python flavour escapes the same characters as Python’sre.escape, which is also safe for PCRE, PHP and Java (a vertical tab is written\x0B, because\vmeans any vertical whitespace there). Unescaping follows the flavour:\x{…}and\Q…\Eare read for PCRE, PHP and Java (with a note that Python does not accept them) and refused for JavaScript, which writes\u{…}instead. - Shell: single quotes (the POSIX way, with
'\''for a quote inside), backslashes, or$'…'. Words with only safe characters stay unquoted, as with Python’sshlex.quote. - C/C++, Java, C#: each language’s escapes; control characters as octal (
\033) in C and Java,\u001Bin C#; non-ASCII optionally as\u00E9(C also as UTF-8 bytes\303\251); C# verbatim strings. In C and C++ a second?in a row is written\?, so??=cannot turn into a trigraph. - Python: exactly what
repr()writes (orascii(), with Escape non-ASCII too). Unescaping understands\x,\u,\U, octal, raw strings and\N{NAME}, including the name aliases Python accepts, such as\N{NBSP}and\N{LINE FEED}. - Unicode code points: every non-ASCII character (or every character) in the notation you choose.
The round-trip check
After escaping, the result is unescaped again with the same rules and compared with your text, character by character; after unescaping, the result is escaped and read back. A pass means the conversion loses nothing — no dropped backslash, no broken emoji, no line ending changed. If a check ever fails, the message says at which character the texts differ, so you know not to rely on that result.
Escaping is not security
Escaping makes a value fit the syntax of a format. It is not a substitute for the protections each platform provides: use query parameters (prepared statements) for SQL, pass arguments as a list instead of building a shell command, and let a template engine escape HTML. This tool is for writing literals by hand, reading escaped data and checking what an escape means.
Limitations
- Works on up to 10 million characters at a time; split longer files into parts with the Text Splitter first.
- Unescaping reads one string, value or argument at a time; it does not parse whole programs, JSON documents or CSV tables.
- JavaScript template literals with ${…} placeholders, shell text with $VAR or $(…) expansions and Python f-strings cannot be unescaped, because only running them gives the value.
- Regular expression unescaping accepts only escaped literal text; patterns with classes such as \d or quantifiers such as * are reported, not converted.
- The HTML entity list (about 12 KB compressed) and, for Python’s \N{…} escapes, the Unicode name list (about 420 KB compressed) are downloaded from this site the first time they are needed.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
How do I escape quotes in a JSON string?
Choose Escape and JSON string: every " becomes \", every backslash \\, and line breaks become \n. The result, with its quotes, can be pasted as a JSON value.
How do I escape a single quote in SQL?
Double it: O'Brien becomes 'O''Brien'. That is standard SQL and works in PostgreSQL, SQLite, SQL Server and Oracle. MySQL also accepts \'. In application code, use query parameters instead.
How do I turn \u00e9 or \n back into normal text?
Choose Unescape and JSON string (for \uXXXX, \n, \t), JavaScript, Python or Unicode code points, depending on where the text came from. Invalid escapes are reported with their position.
What does the round-trip check prove?
That reading the result back with the same rules gives exactly your text, so the conversion lost nothing — no dropped backslash, no broken emoji.
Is my text uploaded?
No. Escaping and unescaping run in your browser; nothing you paste leaves your device.