Skip to content
Created by Iternal Technologies, the AI Strategy ExpertsBy Iternal (opens in a new tab)

Escape & Encode

SQL Escape

Text

Paste or type text. Apostrophes are doubled so the result can sit inside a SQL string literal.

SQL literal

About SQL Escape

SQL Escape turns text into a SQL string literal. An apostrophe is written as two apostrophes, which is how standard SQL puts a quote inside a literal. Paste a name, a path or a sentence and the output updates as you type.

Wrap in quotes is on by default, so the result is a complete literal you can paste into a statement. Escape backslashes writes each backslash as two backslashes for MySQL when NO_BACKSLASH_ESCAPES is off, and it does that before doubling apostrophes. Letters, emoji, line breaks and every other character stay as they are.

This prepares one literal. It is not a query builder, and it does not make a concatenated query safe against every engine. Everything runs in your browser and the text you paste is never uploaded. Swap sends the result to SQL Unescape so you can check the round trip.

Frequently asked questions

What does escaping a SQL string change?

An apostrophe becomes two apostrophes so it can sit inside a single-quoted SQL literal. With the default settings the output is wrapped in single quotes. Other characters, including emoji and line breaks, are left unchanged.

Does this make a concatenated query safe?

No. This tool prepares a literal and does not make a concatenated query safe against every engine. Use a parameter binding when the value comes from someone else.

When should I escape backslashes?

Turn the option on for MySQL when NO_BACKSLASH_ESCAPES is off. Each backslash is written as two backslashes before apostrophes are doubled. The option does not turn a line break into a backslash-n sequence.

Can I get the inside of the literal without quotes?

Yes. Turn off Wrap in quotes. Apostrophes are still doubled, but the surrounding single quotes are left off so you can drop the text into quotes you already have.

Is the text I paste uploaded anywhere?

No. Escaping runs in your browser and the text you paste is never uploaded, logged or stored. Google Analytics records page views and feature use, never content.

  • SQL Unescape

    Decode doubled apostrophes in a SQL string literal back to plain text, with an optional MySQL backslash mode. Runs in your browser; your text is never uploaded.

  • JSON Escape / Unescape

    Turn text into a valid JSON string literal, or decode one back to plain text.

  • URL Encode / Decode

    Percent-encode text for a URL, or decode a percent-encoded string.

  • Base64 Encode / Decode

    Encode text as Base64, or decode Base64 back to text.

  • HTML Escape / Unescape

    Escape text for HTML, or decode entities back to characters.

Iternal · AI Blueprint Builder

Plan the AI initiative, not just the output

The AI Blueprint Builder scores each use case across value, feasibility, cost, governance, risk, adoption and readiness before you commit budget. Free to start, about 60 minutes.

Open the AI Blueprint Builder (opens in a new tab)