String Escape and Unescape Tool

Quote or recover a string using the explicitly selected JSON, JavaScript, SQL, shell, CSV or regex context.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Convert string controls

Showing an example. Edit to see your own.

Escape accepts up to 50,000 characters. Unescape accepts formatted text up to 300,002 characters and returns at most 50,000. NUL is refused in every format; JavaScript uses a JSON-compatible double-quoted subset.

JavaScript strings use a JSON-compatible double-quoted subset, not every JavaScript literal form. Each format only formats text; it does not make arbitrary SQL queries or shell commands safe.

Processed in your browser. Your inputs stay on this device.

How to use String Escape and Unescape Tool

  1. Choose the target string context and Escape or Unescape.
  2. Paste literal text, or a quoted value in the supported form for that context.
  3. Convert it and check quotes, backslashes and line breaks.
  4. Copy the result into the intended string position rather than treating it as a whole program.

Example: String Escape and Unescape Tool

Quote one POSIX shell word containing an apostrophe.

You add
Escape; context: POSIX shell word; text: can't say "yes".
You get
The quoted form is 'can'\''t say "yes"'. Unescape in the same context recovers can't say "yes" without running a command.

Supported inputs and limits

Escape accepts up to 50,000 raw characters; Unescape accepts up to 300,002 formatted characters and returns at most 50,000. NUL is refused in every mode. Contexts are JSON strings, a JSON-compatible JavaScript double-quoted subset, standard SQL single-quoted literals, POSIX shell words, CSV fields and JavaScript regular-expression literal text. Only the selected documented grammar is accepted. No query or command is executed and no pattern is matched. SQL quoting is not a substitute for parameters; shell word quoting does not validate a surrounding command; CSV quoting alone does not neutralise spreadsheet formulas.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

A quoted value has a boundary

The surrounding quotes and the characters inside them work together. A backslash copied from one context can have another meaning in a different grammar. Use a round trip to inspect the intended literal text, and keep parsing or execution outside this conversion page.

Questions about String Escape and Unescape Tool

Why do SQL and JavaScript quotes look different?

They follow different string grammars. The SQL mode uses the documented standard single-quoted literal form; JavaScript and JSON have their own escape rules.

Does shell quoting make a whole command safe?

It quotes one supported shell word. It does not validate a command, its arguments or the program being called. Do not treat a recovered value as something this page has approved to execute.

Can I use this instead of query parameters?

SQL literal quoting is useful for inspecting text, but application database queries should use their parameter interface. A quoted string does not validate the surrounding query.

Why is an escape sequence rejected?

JavaScript mode accepts a JSON-compatible double-quoted subset, so forms such as single quotes, \x escapes or \v are refused. Other modes also require their named quoted form; check the selected context before unescaping.

Does quoting a CSV field neutralise a formula?

CSV mode quotes separators, quotes and line breaks. Spreadsheet apps may still treat a formula-leading cell as a formula. Use a data-only import or an explicit formula-safe export when that distinction matters.

Project manager: Tony Hines · Content updated 1 October 2026 · Report a problem