What this tool does
Two things: it doubles every single quote — the way ANSI SQL writes a quote inside a string literal — and wraps the result, so what comes back is a complete literal.
O'Brien → 'O''Brien'
There is no backslash escaping in standard SQL, so nothing else is transformed.
The wrapping is what makes the round trip exact. Without it, a lone apostrophe escapes to '', which the unescape tool reads as an empty quoted string — the character disappears. PostgreSQL’s quote_literal() and Node’s SqlString.escape() return the wrapped form for the same reason. Turn Wrap in quotes off if you want only the inside, to paste between quotes you type yourself; that form is not reversible.
Read this before using it
Escaping quotes is not a defence against SQL injection. It is a syntax aid, not a security boundary. Any value that comes from a user, a request, a file or another system belongs in a parameterised query — a placeholder that the driver binds separately, so the value never becomes part of the statement text and no amount of quoting can change the query’s meaning.
This tool is for the other case: a literal you are typing yourself into a migration, a fixture or a one-off SELECT, where the text contains an apostrophe and you want the right form without counting quotes.
Dialect caveat
The ANSI rule is the safest common denominator, but it is not universal. MySQL, unless it runs with NO_BACKSLASH_ESCAPES, also treats \ as an escape character inside literals — so a value ending in a backslash is not fully handled by doubling quotes alone. Check your dialect before relying on this for anything but hand-written SQL.
Private by design
Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.