What does it mean to escape text for JSON?
Escaping text for JSON means rewriting the few characters that would otherwise break a JSON string. A JSON string starts and ends with a double quote, so a quote in the middle of your text looks like the end of the string and the parser gets confused. A raw line break causes the same trouble, because JSON doesn't allow one inside a string.
The fix is a backslash. A quote becomes \", a line break becomes \n and a backslash itself becomes \\. Every JSON parser reads these sequences and gives back exactly the text you started with, so escaping is simply a safe way to carry that text inside a string.
It isn't encryption and it isn't compression. Nothing is hidden and nothing is lost.
Which characters need escaping?
The JSON specification (RFC 8259) is short on this point. Inside a string, three kinds of character must be escaped:
- The double quote
", written as\" - The backslash
\, written as\\ - Control characters below U+0020, such as the line feed
\n, the carriage return\rand the tab\t. A control character without a short form is written as a Unicode escape, for example\u0001
Everything else can stay as it is. Accented letters, Urdu and Arabic text, Chinese characters and emoji are all valid inside a UTF-8 JSON string, and this tool leaves them alone. Single quotes never need escaping, because JSON only uses double quotes. The forward slash may be written as \/, but you don't have to.
A worked example
Say you want to send this message through an API:
She said "hello"
C:\Users\SamPasted straight into JSON, it fails twice over: the quotes end the string early, and the line break and backslashes aren't valid. Escaped, it becomes one safe line:
{"message": "She said \"hello\"\nC:\\Users\\Sam"}When this comes in handy
Most people land here in the middle of a practical job, like:
- Writing a JSON request body by hand for a curl command or an API client.
- Putting a multi-line message, an HTML snippet or a SQL query into a config file.
- Preparing test data that contains quotes, apostrophes or file paths.
- Pasting a stack trace or a log line into a JSON payload.
- Adding examples that contain JSON strings to API documentation.
Escaping in your own code
If you're doing this inside a program, don't write the replacements yourself. Every major language has a serializer that does it correctly. In JavaScript, JSON.stringify returns the escaped string wrapped in quotes, so slice the quotes off if you only want the inside:
const text = 'She said "hello"\nC:\\Users\\Sam';
const escaped = JSON.stringify(text).slice(1, -1);import json
escaped = json.dumps(text)[1:-1]Mistakes that break JSON
A few slips cause most of the 'unexpected token' errors people hit after escaping:
- Escaping the whole document instead of one value. Run an entire JSON object through an escape tool and you get a string, not an object. Escape only the text that goes inside a string value.
- Escaping twice. If you see doubled backslashes where you expected single ones, the text was already escaped once. Use JSON Unescape to peel a layer off.
- Forgetting the backslashes in Windows paths.
C:\Usershas to be writtenC:\\Usersinside JSON. - Adding quotes twice. This tool leaves the outer quotes off, so add them yourself, once.
- Wrapping a string in single quotes. JSON strings only use double quotes. Single quotes are fine inside the text, but they can't wrap it.
Is it safe to paste private text here?
Everything happens in your browser. The text you paste is processed on your own device with JavaScript and isn't sent to our servers, so API payloads and internal messages stay with you. The Privacy Policy covers the details.