JSON Toolbox LogoJSONToolbox

JSON Escape & Unescape

Escape raw text or JSON content into a JSON-safe string and unescape JSON string literals back to readable text. Handle quotes, backslashes, line breaks, tabs, control characters, and Unicode escapes directly in your browser.

Output will appear here...
All processing happens in your browser. No JSON is sent to our servers.

Key Features

Escape JSON Strings

Convert raw text or JSON content into a JSON-safe string representation with escaped quotes, backslashes, line breaks, tabs, and other required control characters.

Unescape JSON Strings

Decode valid JSON string escape sequences such as \" , \\, \n, \t, \r, and \uXXXX back into readable text or JSON content.

Handle Nested JSON Strings

Work with JSON stored inside another JSON string, log field, database column, environment variable, or API response. Review the escaping depth before applying the operation again.

JSON String and Document Modes

Distinguish between escaping a string value and serializing an entire JSON document. The output mode should make clear whether surrounding JSON string quotes are included.

Copy the Result

Copy the escaped or unescaped output to your clipboard for use in JSON payloads, code, logs, tests, configuration files, and debugging workflows.

Download Text

Download the result as a plain text file when the escaped content is large or needs to be reused in another tool.

Swap Directions

Move the output back into the input area to inspect the reverse operation. Repeated escaping increases the escaping depth, so use this only when another serialization layer is intentional.

Browser-Based Processing

Escaping and unescaping happen in your browser. The page does not require an account or upload the input to a remote service.

How to Use

1

Enter text or an escaped string

Paste raw text, a JSON string literal, escaped JSON from a log, or a field copied from an API response. Choose the operation that matches the current representation.

2

Choose Escape or Unescape

Use Escape to encode text for use inside a JSON string. Use Unescape to decode valid JSON escape sequences and recover the represented text.

3

Check the quoting mode

Confirm whether the output should include the surrounding JSON string quotes or only return the inner escaped content. This distinction affects how the result is embedded.

4

Review nested escaping

If the input already contains sequences such as \\" or \\\\, it may be escaped more than once. Do not apply Escape repeatedly unless another JSON or string serialization layer is required.

5

Copy or download

Copy the processed result or download it as text. Test the output with the parser or programming language that will consume it.

JSON Escape Example

Escape a JSON document so it can be stored as the value of another JSON string.

JSON Text
{"name":"Alice","message":"She said \"OK\"","path":"C:\\Users\\test"}
JSON String Literal
"{\"name\":\"Alice\",\"message\":\"She said \\\"OK\\\"\",\"path\":\"C:\\\\Users\\\\test\"}"

The output includes surrounding quotes because the entire JSON document is represented as one JSON string value. If your application expects only the inner content, use the output mode implemented by the page.

How to Escape and Unescape JSON Strings

What Is JSON String Escaping?

JSON string escaping converts text into a representation that can safely appear inside a JSON string. Double quotes, backslashes, and control characters have special meaning in JSON, so they must be represented with escape sequences when they occur as content.

For example, the text She said "hello" contains double quotes. As JSON string content, it can be represented as She said \"hello\". The escaping changes the representation, not the intended text.

JSON Escape Sequences

Standard JSON defines a limited set of escape sequences for string values:

  • \": double quote
  • \\: backslash
  • \n: line feed
  • \r: carriage return
  • \t: horizontal tab
  • \b: backspace
  • \f: form feed
  • \uXXXX: a Unicode escape using four hexadecimal digits

Escaping the forward slash as \/ is allowed but not generally required. JSON does not support every escape syntax accepted by programming languages, so sequences such as \a, \v, and \0 should not be assumed to be valid JSON escapes.

Escaping a String vs Escaping a JSON Document

A raw text string and a complete JSON document are related but different inputs. If you want to embed a JSON document inside another JSON string, the document must become string content:

{"event":"created"}

may become a JSON string literal similar to:

"{\"event\":\"created\"}"

The outer quotes indicate that the entire document is now one JSON string value. If you only need the inner escaped content, the surrounding quotes may be omitted depending on the target context.

How to Escape JSON

  1. Enter raw text or JSON: Paste the content you need to embed or serialize.
  2. Choose the output mode: Decide whether the result should include the complete JSON string literal or only its inner content.
  3. Escape once: Convert quotes, backslashes, and control characters according to JSON string rules.
  4. Review the output: Check the number of escaping layers and confirm that the destination expects a JSON string.
  5. Test with a parser: Use the target language or JSON parser to confirm that the result decodes to the intended value.

How to Unescape JSON

  1. Paste the escaped value: Use a string copied from a log, database field, environment variable, or API response.
  2. Identify the layer: Check whether the value includes outer quotes and whether it has been escaped more than once.
  3. Unescape one layer: Decode the JSON string representation.
  4. Inspect the result: Determine whether it is readable text or valid JSON that should be parsed next.
  5. Repeat only when necessary: Decode another layer only if the data was intentionally serialized multiple times.

Nested JSON and Double Escaping

Nested JSON is common when one JSON field contains another JSON document as a string:

{"payload":"{\"id\":1,\"status\":\"ok\"}"}

The outer document contains a string, and the string's content happens to be JSON text. To inspect the inner object, decode the string value and then parse the resulting JSON. Removing backslashes manually without respecting the serialization layers can corrupt the data.

Use JSON.stringify and JSON.parse When Coding

When writing application code, prefer the standard JSON library instead of manually replacing characters. In JavaScript, JSON.stringify(value) produces a JSON representation with the required escaping, and JSON.parse(text) parses JSON and decodes valid string escapes. Similar standard-library functions exist in Python, Java, C#, Go, and other languages.

An online escape tool is useful for inspection and one-off transformations, but application code should rely on a tested serializer and parser.

JSON Escaping Is Not HTML Encoding

JSON escaping and HTML encoding target different contexts. JSON uses backslash sequences inside string values, while HTML uses entities such as " and &. Escaping a value for JSON does not automatically make it safe for HTML, JavaScript, SQL, URLs, or shell commands.

Unicode and Surrogate Pairs

Unicode characters can normally appear directly in JSON. A serializer may choose to leave them readable or emit Unicode escapes. Characters outside the Basic Multilingual Plane, including many emoji, may be represented using surrogate-pair escapes in UTF-16-based environments, so do not assume every visible character maps to one \uXXXX sequence.

Common Mistakes

  • Double escaping: Applying Escape to content that is already escaped.
  • Manual backslash removal: Deleting backslashes without parsing the JSON string.
  • Wrong context: Using JSON escaping where HTML, SQL, URL, or JavaScript-specific encoding is required.
  • Confusing text with an object: Unescaping a JSON string does not automatically parse the resulting text into an object.
  • Invalid escape sequences: Using language-specific escapes that are not valid in JSON.
  • Incorrect outer quotes: Embedding inner escaped content where the target expects a complete JSON string literal, or the reverse.

Browser-Based Privacy

This tool is designed to escape and unescape input in the browser rather than sending it to a remote service. That is convenient for development data, logs, and test fixtures, but it is not a secret-management system. Avoid entering credentials, access tokens, private keys, customer information, or confidential production logs into any online tool.

Related Articles

Related Tools

Frequently Asked Questions

What does JSON escaping do?

JSON escaping encodes text so it can safely appear inside a JSON string. It adds escape sequences for characters that would otherwise change the string syntax, including double quotes, backslashes, line breaks, tabs, carriage returns, backspace, and form feed.

What does JSON unescaping do?

JSON unescaping decodes valid JSON escape sequences back into the characters they represent. For example, \" becomes a double quote, \\ becomes one backslash, and \n becomes a line break.

Does Escape add surrounding double quotes?

There are two common outputs: a complete JSON string literal includes surrounding double quotes, while string content mode returns only the escaped characters inside the string. Check the selected mode or output description before embedding the result.

What is the difference between escaping a JSON string and escaping a JSON document?

A JSON string contains text and must escape characters that conflict with string syntax. A JSON document is already structured JSON. To embed the whole document inside another JSON string, serialize the document as text first and then escape or stringify that text.

Which characters must be escaped in a JSON string?

Double quotes and backslashes must be escaped. JSON also defines escapes for control characters including backspace, form feed, line feed, carriage return, and tab. A Unicode escape such as \uXXXX may be used for characters when needed. Escaping the forward slash is optional in standard JSON.

Can Unicode characters appear directly in JSON?

Yes. Valid Unicode characters such as Chinese text, accented letters, and emoji can generally appear directly in a JSON string. They do not need to be converted to \uXXXX unless a downstream system requires escaped Unicode or the output mode is configured to do so.

Why does my output contain too many backslashes?

The input may already be escaped, or the value may be nested inside more than one string serialization layer. Each additional JSON string layer adds another level of escaping. Inspect the actual representation and unescape one layer at a time.

How do I unescape JSON from an API response or log?

Copy the field containing the escaped JSON string, choose Unescape, and review whether the result becomes readable text or a valid JSON document. If it is still escaped, the value may contain multiple serialization layers.

Does this tool parse escaped JSON into an object?

Escaping and parsing are different operations. An unescape operation can recover the JSON text, but converting that text into an object requires JSON parsing. Use a JSON viewer or parser after unescaping when you need to inspect the structure.

What is the difference between JSON escaping and HTML encoding?

JSON escaping uses backslash sequences such as \" and \\ inside JSON strings. HTML encoding uses entities such as " and &. They solve different syntax and context problems and are not interchangeable.

Is JSON escaping the same as JavaScript string escaping?

They overlap but are not identical in every detail. JSON supports a specific set of escape sequences, while JavaScript string literals may support additional syntax such as single-quoted strings, hexadecimal escapes, or other language-specific forms. Use the escaping rules required by the target context.

Can I use this tool for JSONL?

Only when the input is processed as independent lines and each line is valid for the selected operation. JSONL may contain escaped newlines or multiline quoted content, so line-by-line processing is not always equivalent to parsing one JSON document.

Can I load input from a URL?

The recommended input is pasted text or a local file. Arbitrary URL loading can fail because of CORS and can expose remote or private data to the browser. Add URL input only if it is explicitly implemented with URL validation, size limits, and appropriate security controls.

Is there a size limit?

The practical limit depends on browser memory, input length, rendering, and the number of escaping layers. Small and medium strings should process quickly, while very large files may slow down the page or require local streaming tools.

Is my input uploaded to a server?

This page is designed to process the input in your browser without requiring a server upload. You should still avoid entering passwords, API keys, access tokens, private customer data, or confidential production logs into any browser-based tool.