J\

JSON Escape & Unescape

Escape text and decode JSON string layers with explicit stopping rules

JSON & Data
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
JSON string

Processed locally in the browser; input is not autosaved. Maximum input: 1 MiB.

Pasting or editing can normalize CRLF and lone CR to LF; byte counts then refer to text-area content. To inspect original file bytes, read a UTF-8 file and leave it unedited. A file BOM is retained for checking.

Maximum output: 4 MiB. Decoding accepts JSON strings and preserves empty results. Unpaired surrogates are rejected to prevent silent replacement during UTF-8 export.

Body-only mode still requires JSON string-body syntax. HTML-sensitive escaping covers <, >, &, U+2028 and U+2029; it is not a general HTML attribute, URL or script sanitizer. Nested decoding stops after at most 5 layers and reports why it stopped.

Result

Process again after changing input or options to generate a current result.

About this tool

Turn multiline text into a JSON string value, or decode a quoted JSON string returned inside another response. The tool applies JSON string grammar to quotes, backslashes, controls and Unicode. Optional ASCII output writes UTF-16 code units as escapes; supplementary characters use pairs. Body-only mode omits outer quotes but still requires correct string-body escapes. Nested decoding stops after five layers and distinguishes ordinary text, an invalid next layer and the layer limit. Empty strings remain usable results. Unpaired surrogates are rejected because UTF-8 export would replace them. Input is limited to 1 MiB and output to 4 MiB; large previews are capped while copy and download retain the full accepted result. Pasting or editing can normalize CRLF and lone CR to LF. For original byte counts, read a UTF-8 file and leave the text unedited; BOM bytes are retained.

Scenario Recipes

01

Embed a multiline message in an API fixture

Goal: Create a complete JSON string value and verify its decoded text.

  1. Choose escape mode, paste a message with a real newline and emoji, and keep surrounding quotes enabled.
  2. Process and copy the complete result into one value position in the fixture. Use ASCII output only if the destination requires it.
  3. Switch to decode mode, paste that quoted value and process. Check the restored newline and emoji before using the complete fixture.

Result: The quoted JSON literal and decoded raw text represent the same Unicode string.

Failure Clinic (Common Pitfalls)

The raw-escape input fails

Cause: Removing outer quotes does not permit unescaped inner quotes or real control characters.

Fix: Escape inner quotes and use \n for a newline, or use escape mode on the raw text first.

Nested decoding stops with quotes remaining

Cause: The next layer may be malformed or the five-layer limit may have been reached.

Fix: Read the stop reason. Inspect the remaining text before choosing to decode again.

The output is empty but processing succeeded

Cause: The input was an empty string or decoded to one.

Fix: Use the zero-byte result as intended; the output remains downloadable and copyable.

Pasted byte counts differ from the file

Cause: Browsers can normalize CRLF and lone CR to LF in text areas.

Fix: Read the original UTF-8 file and keep it unedited for byte or newline comparisons. Editing switches to the normalized text-area content.

Production Snippets

One string, two representations

text

Raw text: first line<LF>δ½ ε₯½ πŸ˜€
JSON string: "first line\nδ½ ε₯½ πŸ˜€"
ASCII JSON: "first line\n\u4f60\u597d \ud83d\ude00"

Decoding either JSON value restores the same raw text.
The angle-bracket LF marker above stands for a real newline.

Frequently Asked Questions

How does body-only input work?

The tool supplies the outer JSON double quotes. Internal quotes, backslashes and control characters must still follow JSON string-body syntax; raw newlines are not valid in decode mode.

Is an empty decoded string an error?

No. The literal "" decodes to an empty result with zero UTF-8 bytes. It remains available for copying and downloading.

Why is an unpaired surrogate rejected?

A lone UTF-16 surrogate cannot be represented unchanged in UTF-8. Browser Blob export would replace it. A valid pair such as \uD83D\uDE00 decodes to πŸ˜€ and occupies four bytes.

Does HTML-sensitive escaping sanitize HTML?

No. It escapes <, >, &, U+2028 and U+2029 inside the JSON representation. HTML attributes, URLs, templates and executable scripts still need handling appropriate to their destination.

When does nested decoding stop?

After one layer if nested mode is off; otherwise when the text no longer begins as a JSON string, the next string layer is invalid, or five layers have decoded. The reason is displayed.

Does copying a long preview lose text?

No. The preview stops at 65,536 UTF-16 code units, but copy and download use the full accepted result up to 4 MiB. Editing input or an option invalidates the old output. Read a UTF-8 file to preserve original CRLF text; pasting or editing can normalize line endings.

Keep browsing