What you can do here
- JavaScript escape and JavaScript unescape
- Java escape and Java unescape
- C# escape and C# unescape
- SQL escape (quote doubling) and SQL unescape
- XML escape (entities) and XML unescape
- CSV escape (RFC 4180 quoting) and CSV unescape
Click a language, choose Escape or Unescape, and paste your text; the output updates as you type. Swap moves the result back into the input and flips the operation, so you can check that a value round-trips. Each combination has its own link, for example /escape-unescape?mode=javascript-escape or ?mode=xml-unescape.
What string escaping does
Every language that lets you write a string in source code reserves a few characters — usually the quote that ends the string, and whatever character introduces an escape sequence. To put those characters inside a string you have to encode them in a way the parser for that language understands. Escaping rewrites a raw value into that encoded form; unescaping reverses it. The rules are not interchangeable: a backslash is meaningful in a C# string and meaningless in a standard SQL string, and CSV solves the same problem with doubled quotes and a wrapper rather than escapes at all.
The rules this tool applies
| Target | On escape | Notes |
|---|---|---|
| C# | \→\\, "→\", and \0 \a \b \f \n \r \t \v; other control characters → \uXXXX |
Regular (non-verbatim) string literal. Unescape also reads \xH..H and \UXXXXXXXX. |
| Java | \→\\, "→\", and \b \f \n \r \t; other control characters → \uXXXX |
Unescape also reads octal escapes (\0–\377) and multi-u forms like \uu0041. |
| JavaScript | \ " ' ` and \b \f \n \r \t \v; U+2028/U+2029 → \u2028/\u2029; other control characters → \xXX |
Unescape reads \xXX, \uXXXX, \u{...}, octal, and line-continuation backslashes. |
| SQL | '→'' |
ANSI / standard SQL. No backslash escaping. See the MySQL caveat below. |
| XML | &→&, <→<, >→>, "→", '→' |
The five predefined entities. Unescape also resolves numeric references (©, ©). |
| CSV | If the field contains , " or a line break: double every " and wrap the whole field in "…" |
RFC 4180. A field without those characters is returned unchanged. The wrapping quotes are part of the output. |
Escape sequences by language
| Character | JavaScript | Java | C# | SQL | XML | CSV |
|---|---|---|---|---|---|---|
Double quote " | \" | \" | \" | unchanged | " | "" + wrap |
Single quote ' | \' | unchanged (\' read) | unchanged (\' read) | '' | ' | unchanged |
Backslash \ | \\ | \\ | \\ | unchanged* | unchanged | unchanged |
| Newline | \n | \n | \n | unchanged | unchanged | kept + wrap |
| Tab | \t | \t | \t | unchanged | unchanged | unchanged |
| Carriage return | \r | \r | \r | unchanged | unchanged | kept + wrap |
| NUL (U+0000) | \x00 | \u0000 | \0 | unchanged | not allowed | unchanged |
Backtick ` | \` | unchanged | unchanged | unchanged | unchanged | unchanged |
& < > | unchanged | unchanged | unchanged | unchanged | & < > | unchanged |
Comma , | unchanged | unchanged | unchanged | unchanged | unchanged | wrap in " |
* MySQL without NO_BACKSLASH_ESCAPES also treats backslash as an escape character; see the questions below.
Which target to pick
Choose the target that matches where the string will end up, not where it came from. A value pulled from a database that you are about to paste into a Java source file needs Java escaping. The same value going into an INSERT statement needs SQL. A value going into an XML attribute needs XML, and one going into a spreadsheet column needs CSV. C#, Java, and JavaScript look similar but differ in the details: JavaScript uses \xXX for low control characters where Java always uses \uXXXX, and only C# recognises \a and \v on unescape without complaint in every context.
Examples
SQL — quote doubling
raw: O'Brien
escaped: O''Brien
use: INSERT INTO users(name) VALUES ('O''Brien');
C# / Java / JavaScript — backslash escapes
raw: C:\temp "log"
C#/Java: C:\\temp\t\"log\"
JS: C:\\temp\t\"log\" (\t is a real tab in the raw input)
XML — entities
raw: Tom & Jerry <3
escaped: Tom & Jerry <3
use: <title>Tom & Jerry <3</title>
CSV — RFC 4180 quoting
raw: Redmond, WA
escaped: "Redmond, WA"
raw: She said "yes"
escaped: "She said ""yes"""
Common questions
Why does SQL not use a backslash?
The SQL standard defines the string delimiter as the single quote and gives no other character special meaning inside a literal, so the only thing to escape is the quote — done by doubling it. MySQL in its default configuration also treats backslash as an escape, but that is a MySQL extension, not standard SQL.
Does the MySQL backslash mode matter?
Yes. If your MySQL server does not have NO_BACKSLASH_ESCAPES set, a backslash in your data also needs doubling and this tool's SQL mode will under-escape it. Use a parameterised query rather than string building whenever you can.
Do I get the surrounding quotes?
Not for C#, Java, JavaScript, SQL, or XML — the tool transforms only the contents so you can drop the result between your own quotes. CSV is different: its quoting is the wrapper, so the quotes are included.
What happens to characters that do not need escaping?
They pass through unchanged. Escaping only touches the characters that would otherwise break the literal or change its meaning.
Is my input sent anywhere?
No. Everything runs locally in JavaScript in your browser. Nothing is uploaded.
What's the difference between escaping and encoding?
Escaping, which is what this tool does, rewrites the specific characters inside a string literal so a language's own parser — C#, Java, JavaScript, SQL, XML, or CSV — reads them correctly; the result is still meant to live inside source code or a data file written in that language. Encoding schemes like Base64 or URL encoding instead transform an entire value into a different representation for transport, such as fitting binary data into a URL, and are not tied to any single language's syntax.
How do I escape a string for JavaScript?
Choose JavaScript and Escape. Backslashes, both quote types and backticks get a backslash, line breaks and tabs become \n, \r and \t, and U+2028/U+2029 become \u2028/\u2029, so the result is safe inside '…', "…" or a template literal. In code, JSON.stringify(value) produces a double-quoted, escaped literal too.
Why is the CSV output sometimes not wrapped in quotes?
RFC 4180 only requires quotes when a field contains a comma, a double quote or a line break, so a plain value is returned unchanged. Tick Always wrap the CSV field in quotes if your importer expects every field quoted.
Is there a general text encoder/decoder for URLs and Base64?
Yes — URL encoding and Base64 are general-purpose encodings rather than a programming language's string-literal escaping, so they're not covered here. Use the URL Encoder and Base64 Encoder for those instead.