⚙️ Settings
Escape / Unescape Tool — HTML Entities & JSON String Escaping
This tool converts text to HTML entities or JSON-safe escaped strings, and reverses the process too. It's built for developers who need to escape HTML special characters before embedding user-generated text in a web page, or who need to properly escape a string for safe inclusion in a JSON payload. Paste your text, choose a direction, and get correctly escaped or unescaped output instantly.
⚡ Key Takeaways
- Escapes text to HTML entities or JSON-safe strings, and reverses either process.
- HTML escaping and JSON escaping are not interchangeable — match the type to the context.
- Prevents user-generated text from being misread as live HTML markup.
- Essential when hand-building a JSON string containing quotes or line breaks.
What, Who, When & Why
| What it's for | Escapes text to HTML entities or JSON-safe strings, and reverses the process. |
|---|---|
| Who it's for | Developers who need to safely display user-generated text in HTML, or embed a string inside a JSON payload. |
| When to use it | Before rendering untrusted or special-character text in a web page, or hand-building a JSON string with quotes or line breaks. |
| Why it's needed | Unescaped special characters can break HTML rendering or JSON parsing, and in some cases create real security issues. |
| Best way to use it | Always match the escaping type to where the text will actually be used — HTML escaping doesn't make text safe for JSON, and vice versa. |
How to Use Escape / Unescape
- Paste your text into the Input box.
- Click Escape HTML to convert special characters (like
<,>,&) into their HTML entity equivalents. - Or click Escape JSON to escape characters that need special handling inside a JSON string (like quotes and newlines).
- Use the corresponding Unescape buttons to reverse either process.
Example
The literal text <div>Hello & welcome</div> (an actual HTML snippet, typed as plain characters) becomes, after HTML escaping, a version where each <, >, and & is replaced with its entity code — so it can be safely displayed as visible text on a web page rather than being interpreted as an actual HTML tag by the browser. This is exactly the transformation needed when displaying code snippets or user-submitted HTML as readable text instead of rendering it.
Key Features
- HTML escaping — converts characters like
<,>,&, and quotes into safe HTML entities. - HTML unescaping — converts HTML entities back into their original characters.
- JSON escaping — escapes quotes, backslashes, and control characters for safe inclusion in a JSON string.
- JSON unescaping — reverses JSON escaping back to the original text.
Practical Use Cases
- Displaying user input safely: escape text before rendering it in HTML to prevent it from being interpreted as markup, which also helps prevent certain injection issues.
- Building JSON payloads by hand: properly escape a string containing quotes or line breaks before inserting it into JSON.
- Debugging encoded text: unescape HTML entities or JSON escape sequences to read the original content when reviewing logs or API responses.
- Preparing code snippets: escape HTML so example code displays correctly on a web page instead of rendering as live markup.
- Documentation: safely show raw HTML or JSON examples within a webpage without them being executed or malformed.
Tips for Best Results
- Always match the escaping type to the actual context the text will be used in — HTML escaping doesn't make text safe for JSON, and vice versa.
- When debugging an API response with escaped characters, use Unescape to read the original text before troubleshooting further.
- For displaying code examples on a webpage, HTML-escape the code first so tags like
<script>show as visible text instead of executing.
Related Terminology
HTML entities are special codes (like < for <) used to display characters that would otherwise be interpreted as HTML markup. JSON escaping uses backslash sequences (like " for a quote or
for a newline) so special characters can be safely included inside a JSON string value. Both are forms of "encoding for context" — making text safe to include within a specific format without changing its underlying meaning.
Important Considerations
HTML escaping and JSON escaping serve different purposes and use different character sets — escaping for one context doesn't make text safe for the other. Always match the escaping type to where the text will actually be used, since using the wrong type of escaping can leave your text vulnerable to display issues or, in more serious cases, security problems if untrusted text is inserted without the correct escaping.
Related Tools
If you're preparing data for an API request body, the CSV ⇄ JSON Converter can help build the underlying JSON structure. For sanitizing SQL text instead, see the Query Sanitizer. To clean up whitespace in text before escaping it, use the Whitespace Trimmer.
Frequently Asked Questions
How do I escape HTML special characters?
Paste your text into the Input box and click Escape HTML — characters like <, >, and & are converted into their safe HTML entity equivalents.
What's the difference between HTML escaping and JSON escaping?
HTML escaping converts characters that have special meaning in HTML markup, while JSON escaping converts characters (like quotes and newlines) that have special meaning within a JSON string value — they're used in different contexts and aren't interchangeable.
Can I reverse the escaping to get my original text back?
Yes, use the corresponding Unescape option to convert escaped HTML entities or JSON sequences back into the original characters.
Why does it matter which type of escaping I use?
Using the wrong type of escaping can leave your text displaying incorrectly, or in more serious cases, create a security issue if untrusted text isn't properly escaped for the context it's placed in.
WITH recent_orders AS (
SELECT
customer_id,
order_id,
order_date,
total_amount
FROM orders
WHERE order_date >= DATEADD(day, -30, GETDATE())
)
SELECT
customer_id,
COUNT(order_id) AS order_count,
SUM(total_amount) AS total_spent
FROM recent_orders
GROUP BY customer_id
ORDER BY total_spent DESC;
WITH RECURSIVE employee_hierarchy AS (
-- Anchor: top-level rows (no manager)
SELECT
employee_id,
manager_id,
employee_name,
1 AS level
FROM employees
WHERE manager_id IS NULL
UNION ALL
-- Recursive: join children to their parent's result
SELECT
e.employee_id,
e.manager_id,
e.employee_name,
eh.level + 1
FROM employees e
INNER JOIN employee_hierarchy eh
ON e.manager_id = eh.employee_id
)
SELECT *
FROM employee_hierarchy
ORDER BY level, employee_name;
-- Note: SQL Server / Oracle: drop the RECURSIVE keyword (just WITH employee_hierarchy AS (...))
SELECT
o.order_id,
c.customer_name,
o.order_date,
p.product_name,
oi.quantity
FROM orders o
INNER JOIN customers c
ON o.customer_id = c.customer_id
LEFT JOIN order_items oi
ON o.order_id = oi.order_id
LEFT JOIN products p
ON oi.product_id = p.product_id
WHERE o.order_date >= '2026-01-01'
ORDER BY o.order_date DESC;
SELECT
DATE_TRUNC('month', order_date) AS order_month, -- PostgreSQL
-- FORMAT(order_date, 'yyyy-MM') AS order_month, -- SQL Server
-- DATE_FORMAT(order_date, '%Y-%m') AS order_month, -- MySQL
COUNT(*) AS order_count,
SUM(total_amount) AS revenue
FROM orders
GROUP BY DATE_TRUNC('month', order_date)
ORDER BY order_month;
SELECT
customer_id,
order_id,
order_date,
total_amount,
ROW_NUMBER() OVER (
PARTITION BY customer_id
ORDER BY order_date DESC
) AS order_rank,
SUM(total_amount) OVER (
PARTITION BY customer_id
ORDER BY order_date
ROWS BETWEEN UNBOUNDED PRECEDING AND CURRENT ROW
) AS running_total
FROM orders;
CREATE PROCEDURE GetCustomerOrders
@CustomerId INT,
@StartDate DATE = NULL,
@EndDate DATE = NULL
AS
BEGIN
SET NOCOUNT ON;
SELECT
order_id,
order_date,
total_amount
FROM orders
WHERE customer_id = @CustomerId
AND (@StartDate IS NULL OR order_date >= @StartDate)
AND (@EndDate IS NULL OR order_date <= @EndDate)
ORDER BY order_date DESC;
END;
-- Call it: EXEC GetCustomerOrders @CustomerId = 101, @StartDate = '2026-01-01';
MERGE INTO customers AS target
USING staging_customers AS source
ON target.customer_id = source.customer_id
WHEN MATCHED THEN
UPDATE SET
target.customer_name = source.customer_name,
target.email = source.email,
target.updated_at = GETDATE()
WHEN NOT MATCHED THEN
INSERT (customer_id, customer_name, email, created_at)
VALUES (source.customer_id, source.customer_name, source.email, GETDATE());
#FACC15
rgb(250, 204, 21)
rgb(98%, 80%, 8%)
hsl(46, 96%, 53%)
hsv(46, 92%, 98%)
cmyk(0%, 18%, 92%, 2%)
Tools for analysts, developers & QA engineers
33 free, browser-based utilities — text and list tools, SQL helpers, converters, and small productivity apps. Everything runs locally; nothing you type or paste is ever uploaded.
For Analysts
Clean lists, build SQL fragments, and reshape data without opening a spreadsheet.
For Developers
Format SQL, convert data formats, and handle everyday text and encoding tasks.
For QA Engineers
Generate test data, compare text output, and sanitize queries before sharing them.