DT Dev Tools

String Escaper

Escape and unescape strings for JSON, JavaScript, HTML, URL, and backslash sequences locally. This free tool converts in both directions without uploads.

🔒 Runs entirely in your browser — nothing is uploaded

Advertisement

What String Escaper does

String Escaper converts text to and from the escaped forms used by five common contexts. JSON escaping wraps your text as a valid JSON string literal, encoding quotes, backslashes, and control characters such as newline and tab. JavaScript escaping does the same for source code, additionally handling single quotes and backticks so the result is safe inside any JavaScript string delimiter. HTML escaping replaces the reserved characters &, <, >, and quotes with their entities so the text renders as data rather than markup. URL escaping percent-encodes a value for use in a query string or path segment, and backslash escaping handles the generic \n, \t, \r, and \\ sequences found in many configuration and log formats.

Every format works in both directions. Escaping prepares a raw value for embedding, and unescaping recovers the original text from an already-encoded string, which is useful when you copy a value out of a JSON payload, an HTML attribute, a URL, or a stack trace and want to read it in plain form. Switching between the five formats from a single control makes it easy to move a snippet through the exact transformation a given context requires without hunting for a separate tool.

Private browser-based workflow

All escaping and unescaping happen inside your browser with client-side JavaScript. The tool does not upload your text, tokens, URLs, markup, or log snippets to a server, and it does not require an account. That local-only model matters because the strings pasted into an escaper are frequently real values pulled from production data while debugging an encoding bug. Keeping the work on your machine reduces risk and keeps the output instant because nothing leaves the page between input and result.

The interface keeps the format selector, input, and output close together so you can verify the transformation before copying it. Results should still be reviewed in context: the correct escaping depends on exactly where the value will be placed, and a string that is safe in one position, such as an HTML text node, may need different handling in another, such as an attribute, a script block, or a URL.

Practical tips

Choose the format by the destination, not the source: text going into a JSON file needs JSON escaping, a value going into a query string needs URL escaping, and content rendered into a page needs HTML escaping. Be careful when chaining contexts — a value that lands inside a script tag in HTML may require both JavaScript and HTML escaping — because applying only one leaves an injection risk. When unescaping, confirm the input really uses the selected format, since mismatched formats can silently produce misleading output. For security-sensitive output, prefer your framework's built-in encoders, which understand the full context, and use this tool for inspection, preparation, and quick fixes.

How to use

  1. Choose formatPick JSON, JavaScript, HTML, URL, or backslash escaping.
  2. Escape or unescapeRun the conversion in either direction on your input.
  3. Copy resultReview the output and copy it back into your code.

Frequently asked questions

Which escape formats are supported?
JSON string, JavaScript string, HTML, URL component, and generic backslash sequences, in both escape and unescape directions.
What is the difference between JSON and JavaScript escaping?
JSON escaping produces a strict JSON string literal, while JavaScript escaping also handles characters like single quotes and backticks used in JS source.
Is my text uploaded?
No. Escaping and unescaping run entirely in your browser.
Advertisement