JS & SQL String Escape
Represent text as a single- or double-quoted JavaScript literal, or as a PostgreSQL standard string literal. Decoding reads only that string syntax, without eval or SQL execution. General JSON string conversion remains available in the existing JSON formatter.
Key features
- Choose JavaScript quote style and escape control characters.
- Decode JavaScript Unicode escapes, hexadecimal escapes, and line continuations.
- Double apostrophes for PostgreSQL standard strings while keeping backslashes as data.
How to use
- Choose the string syntax and encoding or decoding direction.
- Encode raw text, or decode one complete literal including its surrounding quotes.
- Review and copy the result. Use prepared statements and parameter binding for actual SQL values.
Use cases
- Create JavaScript string fixtures for tests.
- Read the contents of escaped string literals.
- Learn apostrophe handling in PostgreSQL standard strings.
Frequently asked questions
Can it execute code or template literals?
No. Decoding accepts one single- or double-quoted string, not template literals, concatenation expressions, or function calls. Legacy octal escapes are not supported.
Which SQL dialect and settings does it use?
The SQL mode handles ordinary PostgreSQL single-quoted strings with standard_conforming_strings=on. E strings, dollar quoting, identifiers, and other database dialects are not supported. NUL characters are rejected.
Does this prevent SQL injection?
No. This is a string notation aid for learning and static examples, not an injection defense. Pass runtime values through your database driver’s parameter binding.
Are surrounding quotes required for decoding?
Yes. Include the JavaScript quotes selected in the options, or PostgreSQL single quotes. Encoding includes those quotes in its output. The limit is 100,000 UTF-16 code units.
Privacy
Input and results are processed locally in your browser without upload or storage by this tool. XML and string inputs are not executed; results are shown as text. Shared site advertising and analytics may operate separately, but tool-use events do not include your input contents.
Comments & questions