Escape a String
Escape text so it can sit inside a JSON string, a JavaScript literal, a SQL query, a shell command or a regex.
Free No signup Runs in your browser — nothing uploaded
Result
What it does
Escape a String operates on the text you paste, line by line, and shows the result as you type. Nothing is sent anywhere and there is no length limit beyond what your browser will hold.
When you need it
The kind of tidying that is tedious by hand and error-prone in a spreadsheet: a list pasted out of an email, an export with inconsistent casing, a column of addresses with duplicates in it.
Limits and caveats
Line endings are normalised, and leading and trailing whitespace is treated as significant unless the tool says otherwise. Nothing is stored: reload the page and the text is gone. Everything happens in your browser, so the file never leaves your device.
How to use the Escape a String
- Paste your content, or load a file.
- The result appears as you type.
- Copy or download the output.
Frequently asked questions
- Why does SQL double the quote instead of using a backslash?
- Because doubling is the standard every engine accepts. Backslash escaping is a MySQL extension and produces a broken query on PostgreSQL, SQLite and SQL Server.
- Is this enough to stop SQL injection?
- No. Escaping a value by hand is a last resort — use a parameterised query, where the value never becomes part of the statement at all. This is for the cases where you genuinely cannot, like a one-off script.
- Do my files get uploaded?
- No. This tool runs entirely in your browser, so the file never leaves your device.