What this tool does
Your text becomes a JSON string literal: surrounding quotes, and every character that cannot appear raw replaced by its escape.
"becomes\", a backslash becomes\\;- a newline becomes
\n, a tab\t, a carriage return\r; - other control characters become
\u00XX.
é and 😀 stay as they are. JSON is Unicode, and a legible string is better than a wall of escapes.
Two characters that plain encoders leave raw
U+2028 (line separator) and U+2029 (paragraph separator) come out as \u2028 and \u2029. A standard JSON encoder leaves them literal.
Both spellings are valid JSON. The escaped one is safer, and the reason is historical and still live: in JavaScript before ES2019, those two characters were line terminators, so a string literal containing one raw was a syntax error. Anything that takes JSON and evaluates it as JavaScript — an old eval, a JSONP endpoint, a bundler inlining a data file — hits that. Escaping costs three extra characters and removes the whole class of failure.
A lone surrogate does not produce broken output
Text can contain half of a surrogate pair — a string sliced at the wrong index, a truncated field out of a database. The output escapes it as \ud800 rather than emitting it raw.
That matters because a raw lone surrogate cannot be encoded in UTF-8 at all. Escaped, the JSON is still valid, still UTF-8, and the damaged character is visible in the output rather than corrupting the file that carries it.
What is not escaped
The forward slash. \/ is legal JSON, and some encoders emit it so that </script> never appears in the output, but it is not required and it makes the result harder to read.
If you are embedding the result in an HTML page, handle </script> at the HTML level — an HTML parser closes the element at that sequence wherever it appears, and no amount of JSON escaping changes that.
Private by design
Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.