JavaScript Escape String
Paste any text and get a valid JavaScript string literal you can drop into code. Choose single quotes, double quotes or a template literal; the tool escapes backslashes, quotes, line breaks, tabs and control characters, protects template literals from ${…} interpolation, can write non-ASCII characters as \uXXXX, and makes the string safe to place inside an inline <script> block.
- Runs in your browser
- No sign-up
- Free to use
How to use JavaScript Escape String
- Paste the text you want in your code.
- Choose the quote style.
- Turn on ASCII escaping or <script> safety if needed.
- Copy the literal into your JavaScript.
JavaScript Escape String features
Three quote styles
Single, double or backtick, each escaped correctly.
Complete escaping
Backslashes, quotes, \n, \r, \t, control characters, U+2028 and U+2029.
Template-safe
Escapes ${ so a template literal never interpolates.
ASCII option
Non-ASCII characters and emoji as \uXXXX surrogate escapes.
Inline script safety
Writes </script and <!-- with \x3C.
Multi-line output
Optionally one literal per line joined with +.
When to use JavaScript Escape String
- Embedding a block of HTML, SQL or Markdown in JavaScript code.
- Putting a Windows path with backslashes into a string.
- Generating test fixtures that contain quotes and emoji.
- Injecting server data into an inline script without breaking the page.
JavaScript Escape String FAQ
Which characters must be escaped in a JavaScript string?
The backslash, the quote character used to delimit the string, and line breaks. Other control characters are escaped for readability, and in template literals the backtick and ${ also need escaping.
Why escape </script>?
When JavaScript sits inside an HTML <script> element, the browser ends the script at the first </script>, even inside a string. Writing it as \x3C/script keeps the string intact and prevents injection.
Why are U+2028 and U+2029 escaped?
These line and paragraph separators were not allowed in string literals before ES2019 and still break some tools, so they are always written as escapes.
When should I escape non-ASCII characters?
When the file might be served or saved with the wrong encoding. \uXXXX escapes are pure ASCII and survive any encoding.
Is this the same as JSON escaping?
Close, but not identical. JSON only allows double quotes and does not use \x or \v escapes. For JSON, use JSON.stringify or the JSON tools.
Is my text sent anywhere?
No. Escaping happens in your browser.
How JavaScript string escaping works
A JavaScript string literal is text between quotes, and anything inside that could end the string or be misread needs an escape sequence starting with a backslash. The backslash itself becomes \, the quote character becomes ' or \", a line break becomes \n and a tab \t. Forgetting one of them is a classic source of syntax errors when text is pasted into code by hand.
Template literals, written with backticks, add two more rules. A backtick ends the literal, and the sequence ${ starts an embedded expression that is evaluated at run time. Text pasted into a template literal must therefore escape both; otherwise ${user.name} in the text would be executed as code. This tool escapes them whenever the backtick style is selected.
Some characters are invisible but still matter. Control characters are written as \xNN escapes so they are visible in code reviews, and the Unicode line separator U+2028 and paragraph separator U+2029 are always escaped because older JavaScript engines treated them as line breaks inside strings. Optionally, every non-ASCII character can be written as \uXXXX, with emoji split into their UTF-16 surrogate pairs.
Strings that end up in an inline script need extra care. HTML parsing happens before JavaScript, and the HTML parser ends a script element at the first </script> it sees, wherever it appears. A string containing user-supplied text could therefore close the script and inject HTML. Writing the less-than sign as \x3C avoids this without changing the string’s value.
Splitting at line breaks produces one literal per line joined with +, which keeps long text readable in source code. For the reverse direction, turning escapes back into text, use the JavaScript Unescape String tool; for JSON data, prefer JSON.stringify, which follows JSON’s slightly different rules.