Developer

String Escape & Unescape

Escape or unescape strings for JSON, JavaScript, HTML entities and URL encoding. Handy for embedding text safely in code. 100% client-side and private.

Last reviewed by the Radiatus Cloud team

Need this built for your product?

We design, build & host secure software & APIs.

Talk to an engineer

Escape and unescape strings

Different contexts require different escaping, and getting it wrong causes bugs or vulnerabilities. This tool escapes and unescapes strings for JSON, JavaScript, HTML entities and URL encoding, so you can prepare a string correctly for wherever it is going.

Why escaping is context-specific

A string safe in one context is dangerous in another: a quote breaks a JSON string, an angle bracket is markup in HTML, a space needs encoding in a URL. Each context has its own escaping rules, and applying the wrong one, or none, produces broken output or, worse, an injection vulnerability. Escaping a string for its destination, and unescaping to read escaped input, is a constant need. Having all the common escapings, JSON, JavaScript, HTML, URL, in one tool means you apply the right one for the context rather than hand-escaping and hoping.

The right escaping, every time

It runs entirely in your browser, so nothing you paste is uploaded and the result is yours to copy straight into a project, which lets you work on private code and data without anything leaving your machine.

Related tools

  • JSON Formatter — Format and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.
  • JSON Validator — Validate JSON syntax with precise line and column errors, and check documents against a JSON Schema. Runs locally in your browser, nothing uploaded.
  • Regex Tester — Test regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.
  • HTML Minifier — Minify HTML by removing comments and redundant whitespace, without breaking inline elements or pre blocks. Runs entirely in your browser.

Frequently Asked Questions

Why is escaping context-specific?

Because a character safe in one context is dangerous in another: a quote breaks JSON, an angle bracket is markup in HTML, a space needs URL encoding. Each has its own rules.

What contexts does it handle?

JSON, JavaScript, HTML entities and URL encoding, in both directions, so you can escape for a destination or unescape input.

What happens if I escape wrongly?

Broken output at best, and at worst an injection vulnerability, since unescaped input in the wrong context can be interpreted as code or markup.

Can it unescape too?

Yes. It works both ways, so you can read escaped input as well as prepare a string for output.

Is my string uploaded?

No. The tool runs entirely in your browser.

Privacy & Security

All processing happens locally in your browser — nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste text, pick a format and choose Escape or Unescape. Output updates live.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.