STRING_ESCAPE()
STRING_ESCAPE() is a SQL function in the String Functions category. SQL Server 2016+: escapes special characters in strings. Supports JSON and HTML/XML escaping. The syntax is STRING_ESCAPE(unencoded_string, type). It accepts unencoded_string, type. It returns escaped string. A typical example: SELECT STRING_ESCAPE('Hello <World> & '"Test"'', 'json'); -- Hello \u003CWorld\u003E \u0026 '"Test"'' -- Escapes for JSON: quotes, backslashes, control chars SELECT STRING_ESCAPE('<tag>value</tag>', 'html'); -- <tag>value</tag> -- Useful for: -- Generating safe JSON from SQL data -- Building HTML/XML safely -- Preventing XSS in dynamically generated pages A close relative is CONCAT(), which concatenates two or more strings into one string. Returns NULL if any argument is NULL. A close relative is SUBSTRING(), which extracts characters from a string starting at position `start` for `length` characters. A close relative is REPLACE(), which replaces all occurrences of `from_string` with `to_string` in a string. More about this category: String manipulation — CONCAT, SUBSTRING, REPLACE, TRIM, UPPER, LOWER, LENGTH.