String Escape / Unescape

Works offlineNothing is uploadedFree, no sign-up

Escaped in this tab — your strings never leave it.

One string, six escapings: JSON, HTML, URL, Base64, SQL and regex — both directions wherever a true inverse exists. Regex escaping is honestly one-way, and broken input comes back as a clear refusal instead of mangled text.

Six languages, one collision

Every escaping exists because text keeps landing inside other text: a quote inside a JSON string, a < inside HTML, an apostrophe inside a SQL literal. The host language has delimiters; your data may contain them; escaping is the treaty that keeps the two apart.

The treaties differ in reversibility. JSON, HTML, URL, Base64 and SQL define exact inverses, and this page implements both directions with strict validation — a Base64 string hiding invalid UTF-8 returns a refusal, not mojibake. Regex defines armour only, which is why its tab has one direction and a note instead of a pretence.

Frequently asked questions

Which escaping do I need where?

JSON for string values in APIs and config; HTML when text lands inside markup (the five specials & < > " '); URL for query-string values; Base64 to move bytes through text-only channels; SQL's doubled quote for string literals; regex when a user's search term must match itself literally inside a pattern.

Why does Base64 grow my text by a third?

It maps every 3 bytes onto 4 characters from a 64-symbol alphabet, so the output is 4/3 the size before padding. It is not compression and not encryption — just armour that survives channels which would mangle raw bytes. Cyrillic and ə cost more because UTF-8 spends 2 bytes per such letter first.

Why is regex escaping one-way?

Because escaping is not invertible without knowing intent: in a\.b the backslash might be armour this tool added or a literal backslash your pattern already had. Every other mode here has a spec that answers that question; regex does not, so the tool refuses to guess.

Is escaping enough to stop SQL injection or XSS?

It is the mechanism, but not the strategy. For SQL, parameterised queries beat hand-escaped literals every time — use this when you genuinely must build a literal. For HTML, escaping at output time is exactly what template engines do; doing it by hand is for the places without one.

Related tools