JSON Escape Online

Paste text or a JSON document and get it back escaped, ready to sit inside a JSON string. Quotes, backslashes, newlines, tabs and control characters are all handled.

Input
Output

Paste something on the left. It is processed on this page and never uploaded.

What escaping does

A JSON string cannot contain a raw double quote, a raw backslash, or a raw control character including newline and tab. Escaping replaces each with the sequence JSON defines: a quote becomes \", a backslash becomes \\, a newline becomes \n.

This is what you need when a JSON document has to be carried inside another JSON document, which happens more often than it should: a webhook payload stored as a string field, a log line holding a serialised request, a configuration value that is itself configuration.

Escaping is not encoding

Escaping makes text safe to sit inside JSON syntax. It does not make it safe to put in HTML, a URL, a shell command or a SQL statement. Each of those has its own rules and its own escape sequences, and using the wrong one is how injection bugs happen.

Characters outside the ASCII range are left as they are, because JSON is defined as Unicode text and a modern parser reads UTF-8 correctly. Turn on the ASCII option if something in your pipeline cannot.

Questions

What is the difference between escaping and stringifying?

Stringifying wraps the result in quotes and escapes the contents. Escaping produces only the contents, without the surrounding quotes, so you can paste it between quotes you already have. Both are offered here.

Does escaping protect against injection?

Against breaking out of a JSON string, yes. Against HTML, SQL or shell injection, no. Those are different contexts with different rules, and JSON escaping does nothing for them.

Other tools