When you manually construct JSON strings, special characters like quotes and newlines can break the structure. This guide explains how to escape plain text into JSON-safe form and how to reverse escaped JSON back into the original text, using the ToolOrbit JSON Escape/Unescape tool.
What needs escaping in JSON
- Double quotes must become \" inside a JSON string.
- Backslashes become \\.
- Newlines become \n, tabs become \t.
- Non-printable characters are encoded as \uXXXX.
Hello "world" Line two -> "Hello "world" Line two"
When to escape text
- Embedding user input in a JSON payload.
- Creating JSON strings inside JavaScript code.
- Preparing API requests with dynamic fields.
- Debugging JSON stored in config files or logs.
Using the tool
Paste raw text and choose Escape to get a JSON-safe string, or paste escaped JSON and choose Unescape to recover the original text. This is useful for fixing broken JSON fragments or preparing test data for APIs.
Escaping vs URL encoding
JSON escaping makes a string safe *inside* a JSON document range: it produces the sequence of characters that, when parsed, yields your original text. URL (percent) encoding is a different grammar for a different container — query strings. The two are not interchangeable: a string escaped for JSON placed in a URL still breaks the URL, and vice versa. Keep the tool matched to the destination.
Real situations that need it
- Injecting a user’s free-text answer into a payload your API sends further down.
- Writing JSON snippets into a log line so the log stays parseable.
- Copying a multi-line error message into a unit-test fixture.
- Debugging a response where a raw quote broke the syntax before serialization.
Escape pitfalls that are worth memorizing
The classic escape bugs are all symmetric: a quote unescaped halfway through a string, the backslash that half-escapes (“\n” producing a literal backslash-n), and control characters smuggling through as literal newlines. The fastest habit: escape once, and let the tool’s unescape direction show you what the parser will actually receive — if the round-trip does not come back exactly as you typed it, you found the leak.
- Never hand-escape: build in the tool, then paste.
- For API payloads, escaping an entire string once beats escaping each field separately.
- Emoji and CJK pass through JSON unescaped by default — only quoting and control chars need the treatment.