Developer

JSON String Escaping: What Needs Escaping and When

ToolOrbit Engineering 2 min readUpdated
JSON String Escaping: What Needs Escaping and When

When you manually construct JSON strings, special characters like quotes and newlines can break the structure. This guide explains how to escape plain text into JSON-safe form and how to reverse escaped JSON back into the original text, using the ToolOrbit JSON Escape/Unescape tool.

What needs escaping in JSON

  • Double quotes must become \" inside a JSON string.
  • Backslashes become \\.
  • Newlines become \n, tabs become \t.
  • Non-printable characters are encoded as \uXXXX.
Hello "world"
Line two
->
"Hello "world"
Line two"

When to escape text

  • Embedding user input in a JSON payload.
  • Creating JSON strings inside JavaScript code.
  • Preparing API requests with dynamic fields.
  • Debugging JSON stored in config files or logs.

Using the tool

Paste raw text and choose Escape to get a JSON-safe string, or paste escaped JSON and choose Unescape to recover the original text. This is useful for fixing broken JSON fragments or preparing test data for APIs.

Note: The escaped output is a JSON string, not a full JSON document. If you need a full object or array, embed that string as a value inside your JSON structure.

Escaping vs URL encoding

JSON escaping makes a string safe *inside* a JSON document range: it produces the sequence of characters that, when parsed, yields your original text. URL (percent) encoding is a different grammar for a different container — query strings. The two are not interchangeable: a string escaped for JSON placed in a URL still breaks the URL, and vice versa. Keep the tool matched to the destination.

Real situations that need it

  • Injecting a user’s free-text answer into a payload your API sends further down.
  • Writing JSON snippets into a log line so the log stays parseable.
  • Copying a multi-line error message into a unit-test fixture.
  • Debugging a response where a raw quote broke the syntax before serialization.
The Unescape direction is the sharper tool for debugging: paste an escaped value and recover the human-readable original with its line breaks intact.

Escape pitfalls that are worth memorizing

The classic escape bugs are all symmetric: a quote unescaped halfway through a string, the backslash that half-escapes (“\n” producing a literal backslash-n), and control characters smuggling through as literal newlines. The fastest habit: escape once, and let the tool’s unescape direction show you what the parser will actually receive — if the round-trip does not come back exactly as you typed it, you found the leak.

  • Never hand-escape: build in the tool, then paste.
  • For API payloads, escaping an entire string once beats escaping each field separately.
  • Emoji and CJK pass through JSON unescaped by default — only quoting and control chars need the treatment.

Tools mentioned

More reading

View all guides
What Is Base64? How Encoding Works and Common Mistakes
Developer

What Is Base64? How Encoding Works and Common Mistakes

What Base64 encoding actually does, where it is used, and the mistakes that cause broken or oversized output.

2 min readUpdated
encodeURI vs encodeURIComponent: Which One to Use
Developer

encodeURI vs encodeURIComponent: Which One to Use

How percent-encoding works, the difference between encoding a whole URL and a single component, and the mistakes that break links.

2 min readUpdated
What Is a UUID? Version 4 vs Version 7 Explained
Developer

What Is a UUID? Version 4 vs Version 7 Explained

What a UUID looks like, why version 4 is the safe default, when version 7 is better, and best practices for IDs.

2 min readUpdated
How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption
Developer

How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption

What a hash function does, how to choose between SHA-256 and SHA-512, and why hashing is not encryption.

2 min readUpdated
What Is a JWT? Header, Payload and Signature Explained
Developer

What Is a JWT? Header, Payload and Signature Explained

A JSON Web Token has three parts. Learn what the header, payload and signature contain, how to read the claims, and why decoding is not verifying.

2 min readUpdated
What Is HTML Encoding? Entities & Escaping Explained
Developer

What Is HTML Encoding? Entities & Escaping Explained

Learn how HTML encoding works, why escaping prevents XSS and layout breaks, and how to encode and decode named, decimal, and hex entities.

2 min readUpdated
Unix Time Explained: Seconds, Milliseconds and Time Zones
Developer

Unix Time Explained: Seconds, Milliseconds and Time Zones

What a Unix timestamp is, how to tell seconds from milliseconds, how time zones come into it, and the values worth recognising.

2 min readUpdated
Binary, Octal, Decimal and Hex: How Number Bases Work
Developer

Binary, Octal, Decimal and Hex: How Number Bases Work

How positional number bases work, why very large values need exact arithmetic, and the hex and binary values you meet every day.

2 min readUpdated