---
url: /process-functions/script-escape.md
description: Escapes a string so it can be used in a SQL query.
---

# script.escape

Escapes a string so it can be used in a SQL query. Use it on values from users, such as prompt answers.

It escapes quotes, backslashes and control characters with a backslash, as MySQL and MariaDB expect. Other databases, such as SQL Server and PostgreSQL, escape differently, so use parameters with those.

::: tip Prefer parameterised queries
Where you can, pass values as parameters instead, such as with [DatasourceClient](/process-functions/datasourceclient)'s `?` placeholders. The database then treats each value as data, never as part of the SQL, so it's safe whatever the value contains. Escaping depends on catching every special character, and it's easy to miss a value. Use `script.escape` where parameters aren't available, such as with [script.processUpdateQuery](/process-functions/script-processupdatequery).
:::

```js
script.escape(inputStr)
```

## Parameters

| Parameter | Type | Description |
|---|---|---|
| `inputStr` | `string` | The string to escape. |

## Returns

The escaped string.

## Examples

::: code-group

```js [escape.js]
const valueForSQL = script.escape("It's usually not ok to have a single quote in a SQL statement.");
```

```text [Result]
It\'s usually not ok to have a single quote in a SQL statement.
```

:::

## Related

* [script.processUpdateQuery](/process-functions/script-processupdatequery)
