Escape and Unescape Strings: JavaScript, Java, C#, SQL, XML and CSV

Pick a target language and the tool applies its real escaping rules — quote doubling for SQL, backslash escapes for C#, Java and JavaScript, predefined entities for XML, and RFC 4180 quoting for CSV. Runs entirely in your browser.

What you can do here

Click a language, choose Escape or Unescape, and paste your text; the output updates as you type. Swap moves the result back into the input and flips the operation, so you can check that a value round-trips. Each combination has its own link, for example /escape-unescape?mode=javascript-escape or ?mode=xml-unescape.

What string escaping does

Every language that lets you write a string in source code reserves a few characters — usually the quote that ends the string, and whatever character introduces an escape sequence. To put those characters inside a string you have to encode them in a way the parser for that language understands. Escaping rewrites a raw value into that encoded form; unescaping reverses it. The rules are not interchangeable: a backslash is meaningful in a C# string and meaningless in a standard SQL string, and CSV solves the same problem with doubled quotes and a wrapper rather than escapes at all.

The rules this tool applies

TargetOn escapeNotes
C# \→\\, "→\", and \0 \a \b \f \n \r \t \v; other control characters → \uXXXX Regular (non-verbatim) string literal. Unescape also reads \xH..H and \UXXXXXXXX.
Java \→\\, "→\", and \b \f \n \r \t; other control characters → \uXXXX Unescape also reads octal escapes (\0–\377) and multi-u forms like \uu0041.
JavaScript \ " ' ` and \b \f \n \r \t \v; U+2028/U+2029 → \u2028/\u2029; other control characters → \xXX Unescape reads \xXX, \uXXXX, \u{...}, octal, and line-continuation backslashes.
SQL '→'' ANSI / standard SQL. No backslash escaping. See the MySQL caveat below.
XML &→&amp;, <→&lt;, >→&gt;, "→&quot;, '→&apos; The five predefined entities. Unescape also resolves numeric references (&#169;, &#xA9;).
CSV If the field contains , " or a line break: double every " and wrap the whole field in "…" RFC 4180. A field without those characters is returned unchanged. The wrapping quotes are part of the output.

Escape sequences by language

CharacterJavaScriptJavaC#SQLXMLCSV
Double quote "\"\"\"unchanged&quot;"" + wrap
Single quote '\'unchanged (\' read)unchanged (\' read)''&apos;unchanged
Backslash \\\\\\\unchanged*unchangedunchanged
Newline\n\n\nunchangedunchangedkept + wrap
Tab\t\t\tunchangedunchangedunchanged
Carriage return\r\r\runchangedunchangedkept + wrap
NUL (U+0000)\x00\u0000\0unchangednot allowedunchanged
Backtick `\`unchangedunchangedunchangedunchangedunchanged
& < >unchangedunchangedunchangedunchanged&amp; &lt; &gt;unchanged
Comma ,unchangedunchangedunchangedunchangedunchangedwrap in "

* MySQL without NO_BACKSLASH_ESCAPES also treats backslash as an escape character; see the questions below.

Which target to pick

Choose the target that matches where the string will end up, not where it came from. A value pulled from a database that you are about to paste into a Java source file needs Java escaping. The same value going into an INSERT statement needs SQL. A value going into an XML attribute needs XML, and one going into a spreadsheet column needs CSV. C#, Java, and JavaScript look similar but differ in the details: JavaScript uses \xXX for low control characters where Java always uses \uXXXX, and only C# recognises \a and \v on unescape without complaint in every context.

Examples

SQL — quote doubling

raw:      O'Brien
escaped:  O''Brien
use:      INSERT INTO users(name) VALUES ('O''Brien');

C# / Java / JavaScript — backslash escapes

raw:      C:\temp	"log"
C#/Java:  C:\\temp\t\"log\"
JS:       C:\\temp\t\"log\"      (\t is a real tab in the raw input)

XML — entities

raw:      Tom & Jerry <3
escaped:  Tom &amp; Jerry &lt;3
use:      <title>Tom &amp; Jerry &lt;3</title>

CSV — RFC 4180 quoting

raw:      Redmond, WA
escaped:  "Redmond, WA"
raw:      She said "yes"
escaped:  "She said ""yes"""

Common questions

Why does SQL not use a backslash?

The SQL standard defines the string delimiter as the single quote and gives no other character special meaning inside a literal, so the only thing to escape is the quote — done by doubling it. MySQL in its default configuration also treats backslash as an escape, but that is a MySQL extension, not standard SQL.

Does the MySQL backslash mode matter?

Yes. If your MySQL server does not have NO_BACKSLASH_ESCAPES set, a backslash in your data also needs doubling and this tool's SQL mode will under-escape it. Use a parameterised query rather than string building whenever you can.

Do I get the surrounding quotes?

Not for C#, Java, JavaScript, SQL, or XML — the tool transforms only the contents so you can drop the result between your own quotes. CSV is different: its quoting is the wrapper, so the quotes are included.

What happens to characters that do not need escaping?

They pass through unchanged. Escaping only touches the characters that would otherwise break the literal or change its meaning.

Is my input sent anywhere?

No. Everything runs locally in JavaScript in your browser. Nothing is uploaded.

What's the difference between escaping and encoding?

Escaping, which is what this tool does, rewrites the specific characters inside a string literal so a language's own parser — C#, Java, JavaScript, SQL, XML, or CSV — reads them correctly; the result is still meant to live inside source code or a data file written in that language. Encoding schemes like Base64 or URL encoding instead transform an entire value into a different representation for transport, such as fitting binary data into a URL, and are not tied to any single language's syntax.

How do I escape a string for JavaScript?

Choose JavaScript and Escape. Backslashes, both quote types and backticks get a backslash, line breaks and tabs become \n, \r and \t, and U+2028/U+2029 become \u2028/\u2029, so the result is safe inside '…', "…" or a template literal. In code, JSON.stringify(value) produces a double-quoted, escaped literal too.

Why is the CSV output sometimes not wrapped in quotes?

RFC 4180 only requires quotes when a field contains a comma, a double quote or a line break, so a plain value is returned unchanged. Tick Always wrap the CSV field in quotes if your importer expects every field quoted.

Is there a general text encoder/decoder for URLs and Base64?

Yes — URL encoding and Base64 are general-purpose encodings rather than a programming language's string-literal escaping, so they're not covered here. Use the URL Encoder and Base64 Encoder for those instead.