When you need to escape text for JSON
A JSON string is wrapped in double quotes, so some characters inside it must be written differently. You run into this when hand-writing a request body in Postman or curl, putting an error message or a stack trace into a JSON log line, storing an HTML snippet or SQL query in a config file, or building a test fixture. Paste the raw text here and copy the escaped version into the place between the quotes; the JSON formatter will then accept the document.
Escaping follows RFC 8259 exactly, the same rules as JSON.stringify in every browser:
"becomes\"and a backslash becomes\\, so Windows paths likeC:\Usersturn intoC:\\Users.- Line breaks, carriage returns and tabs become
\n,\rand\t; backspace and form feed become\band\f. - Every other control character below U+0020 becomes a
\u00XXescape, because JSON forbids them raw. - Unpaired surrogate halves become
\uD8XXescapes so the output is always valid UTF-8.
Options
Escape non-ASCII as \uXXXX writes every character outside printable ASCII as an escape: é becomes \u00e9 and an emoji becomes a surrogate pair such as \ud83d\ude00. Use it when the JSON passes through a system that mangles UTF-8, such as an old database driver, a Windows code page, a mail gateway or an HTTP header. The value is identical after parsing; only its spelling changes.
Escape / as / writes forward slashes as \/. JSON allows this optional escape, and it matters when JSON is embedded in an HTML <script> block: without it, a string containing </script> ends the script element early, which can break the page or open an injection hole. PHP’s json_encode does this by default for the same reason.
Add surrounding quotes wraps the result in double quotes, giving a complete JSON string literal rather than just its inside.
Unescaping
Switch to Unescape when you have the inside of a JSON string, for example a message copied from Kibana, CloudWatch or a docker logs line, where every quote appears as \" and line breaks as \n. The tool decodes every escape and shows the original text, including real line breaks. If you paste a whole literal with its outer quotes, the quotes are removed first.
Invalid escapes are not silently dropped or guessed. \x41, \', a \u without four hex digits, or a lone backslash at the end are each underlined in the input and listed with their line and column, with a hint on how to fix them. The output appears once every escape is valid. Raw line breaks and stray quotes, which strict JSON would reject, are accepted as themselves because they are what you see when a log viewer has already decoded part of the text.
To decode a whole stringified JSON document, possibly encoded twice, the JSON Stringify tool peels off one level at a time and shows each level.
Large inputs and privacy
Escaping and unescaping run in a background worker, so multi-megabyte inputs such as a minified bundle or a long log extract do not freeze typing. The text never goes to a server: there is no upload, and the page works offline once loaded. That matters for log lines and configs, which often contain tokens, email addresses or customer data. The security page explains how PasteKit keeps pasted data on your machine.
Examples
Error message with quotes, a tab and a Windows path
Quotes and backslashes gain a backslash, and the line break and tab become \n and \t, so the result can sit inside “…” in any JSON document.
Upload failed: "Q3 report.pdf"
at C:\Users\ada\DownloadsUpload failed: \"Q3 report.pdf\"\n\tat C:\\Users\\ada\\DownloadsUnescape a JSON payload copied from a log
The escaped quotes become real quotes and the escaped \n inside the message becomes a real line break.
{\"level\":\"warn\",\"msg\":\"retry in 5s\nattempt 2\"}{"level":"warn","msg":"retry in 5s
attempt 2"}ASCII-only output for a legacy system
Accented letters, CJK characters and the emoji are written as \u escapes; parsing the JSON gives back exactly the same text.
Café – Tōkyō 東京 😀Escape non-ASCII as \uXXXXCaf\u00e9 \u2013 T\u014dky\u014d \u6771\u4eac \ud83d\ude00A string that is safe inside a <script> tag
With the slash escaped, </script> can no longer close the surrounding script element, and the quotes make it a complete literal.
</script><script>alert("hi")</script>Escape forward slash as \/, Add surrounding quotes"<\/script><script>alert(\"hi\")<\/script>"Common errors and how to fix them
| Error | Cause | Fix |
|---|---|---|
"\x" is not a valid JSON escapeExplained | The text uses an escape from another language, such as \x41 (C, Python) or ' (JavaScript single-quoted strings). JSON only knows " \ / \b \f \n \r \t and \uXXXX. | Replace it with the JSON form, for example \u0041 for \x41 or a plain apostrophe for '. |
\u must be followed by four hex digits, but found "\u12" | A Unicode escape is cut short, or the text contains a literal backslash followed by u, as in a Windows path like C:\users. | Complete the escape to four hex digits, or double the backslash (C:\users) if it was meant literally. |
A backslash at the end has nothing to escape | The input ends with a single backslash, often because the copied text was cut off. | Copy the complete value, or write \ for a literal backslash. |
Frequently asked questions
What is the difference between escaping and stringifying?
Escaping gives the inside of a string literal for any text. Stringifying, on the JSON Stringify page, takes a JSON document, optionally minifies it, and gives a complete quoted literal plus code snippets.
Do I need to escape single quotes?
No. JSON strings are always double-quoted, so an apostrophe is an ordinary character and ' is not even a valid JSON escape.
Why escape forward slashes at all?
Only for JSON embedded in HTML. The escape stops a value containing </script> from ending the script block early; everywhere else it is optional and harmless.
Is \u00e9 the same as é after parsing?
Yes. Every JSON parser decodes both spellings to the same character, so ASCII-only output changes the bytes on the wire but not the data.
How do I escape a whole JSON document?
Paste it here to get the escaped text, or use JSON Stringify, which can minify it first and also produces JavaScript, Python, Java and C# string literals.