100% local — your data never leaves your browser

SQL Escape — A Literal for the Query You Type

Double the single quotes and wrap the result: a complete ANSI SQL string literal, ready to paste into the query you are writing by hand in a client.

Instant Private Zero cookies

Text input

SQL Escaped output

What this tool does

Two things: it doubles every single quote — the way ANSI SQL writes a quote inside a string literal — and wraps the result, so what comes back is a complete literal.

O'Brien   →   'O''Brien'

There is no backslash escaping in standard SQL, so nothing else is transformed.

The wrapping is what makes the round trip exact. Without it, a lone apostrophe escapes to '', which the unescape tool reads as an empty quoted string — the character disappears. PostgreSQL’s quote_literal() and Node’s SqlString.escape() return the wrapped form for the same reason. Turn Wrap in quotes off if you want only the inside, to paste between quotes you type yourself; that form is not reversible.

Read this before using it

Escaping quotes is not a defence against SQL injection. It is a syntax aid, not a security boundary. Any value that comes from a user, a request, a file or another system belongs in a parameterised query — a placeholder that the driver binds separately, so the value never becomes part of the statement text and no amount of quoting can change the query’s meaning.

This tool is for the other case: a literal you are typing yourself into a migration, a fixture or a one-off SELECT, where the text contains an apostrophe and you want the right form without counting quotes.

Dialect caveat

The ANSI rule is the safest common denominator, but it is not universal. MySQL, unless it runs with NO_BACKSLASH_ESCAPES, also treats \ as an escape character inside literals — so a value ending in a backslash is not fully handled by doubling quotes alone. Check your dialect before relying on this for anything but hand-written SQL.

Private by design

Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.

Frequently asked questions

Does this protect me from SQL injection?
No, and you should not use it for that. Escaping quotes is not a security boundary: the only reliable defence is a parameterised query, where the value never becomes part of the statement text. Use this tool for SQL you write by hand, not for SQL built from user input.
Why is only the single quote doubled?
Because that is what the ANSI standard says. In standard SQL a string literal is delimited by single quotes and an inner quote is written twice — there is no backslash escape.
Is that enough for MySQL?
Not necessarily. Unless NO_BACKSLASH_ESCAPES is enabled, MySQL also treats the backslash as an escape character inside string literals, so a trailing backslash can change how the following quote is read. This tool applies the ANSI rule only.
Why does the output include the surrounding quotes?
Because that is the whole literal, and it is the only form that survives a round trip. A lone apostrophe escaped without wrapping gives `''`, which is indistinguishable from an empty quoted string. Switch **Wrap in quotes** off if you want just the inside.

Related converters