Escape / Unescape

Escape or unescape text in over thirty formats, from JSON, HTML, XML and URL to C, Python, shell, SQL, base64, ROT13, Morse and punycode.

Input

Related tools

What it does

One tool for over thirty text escaping and encoding formats: the common ones (JSON, HTML, XML, URL, regex) plus far more obscure territory, including C, Python, Java and JS/TS string-literal escapes, shell/batch/PowerShell/SQL/CSV/LDAP quoting, binary-to-text encodings (base64, base64url, base32, base58, ascii85, uuencode, quoted-printable), classic ciphers (ROT13, ROT47), Morse code, the NATO phonetic alphabet, and punycode for internationalized domain names. Every reversible format round-trips: escape, then unescape, and you get your original text back.

How to use it

Paste your text, pick a format from the dropdown, and choose Escape/Encode or Unescape/Decode. The result updates instantly with its own copy button. Malformed input for any decode direction (a truncated base64 string, an unterminated escape sequence, an out-of-range punycode digit) raises a specific error explaining what is wrong and how to fix it, instead of silently returning garbage.

Why this one

Most escaping sites online handle one format, bury the tool under ads, and quietly mangle malformed input. This one covers over thirty formats, common and obscure, in a single page, runs entirely in your browser, and never sends your text anywhere: your files and inputs never leave your device.

FAQ
What is the difference between the URL, URL full URI, and URL form-encoded options?
Component encoding (encodeURIComponent) escapes everything except unreserved characters, and is right for a single query parameter or path segment. Full URI encoding (encodeURI) leaves URL structure characters like / and ? alone, for encoding a whole URL. Form-encoded matches application/x-www-form-urlencoded, the format browsers use for HTML form submissions, where a space becomes + instead of %20.
Why do some formats like ROT13 have both Escape and Unescape do the same thing?
ROT13 and ROT47 are self-inverse Caesar ciphers: applying the same shift twice returns the original text, so encoding and decoding are literally the same operation. Both directions are still exposed for consistency with every other format.
How does punycode handle a full domain name like café.com?
It splits on dots and encodes each label independently, only touching labels that contain non-ASCII characters and prefixing them with xn--, exactly like a browser converts an internationalized domain name before a DNS lookup. ASCII-only labels, like com, pass through untouched.

Keyboard shortcuts: press ? anywhere on this page to see them.