SQL Comment Stripper
Remove all single-line (--) and multi-line (/* */) comments from SQL code with our free SQL Comment Stripper. Strip comments from SQL queries, schema definitions, and stored procedures while preserving string literals and identifier quotes. Perfect for deobfuscating SQL injection payloads, cleaning schema files for production deployment, and auditing SQL code. Free, private, and no signup required.
Strip all single-line (--) and multi-line (/* */) comments from SQL code while preserving string literals, identifiers, and SQL structure.
Strip Options
Paste your SQL code above, configure the strip options, and click Strip Comments to remove all comments from your SQL. The tool preserves string literals and identifier quotes so your SQL remains valid. Try loading an example to see how it works!
Why Use Our SQL Comment Stripper?
Complete SQL Comment Removal
Strip every type of SQL comment from your code: single-line comments (--), multi-line block comments (/* */), and end-of-line comments. Handles inline comments within larger SQL statements, header comment blocks documenting procedures, and scattered documentation comments throughout your schema files.
String-Literal & Identifier Preservation
Intelligently preserves string literals ('...'), quoted identifiers ("...", `...`), and bracket identifiers ([...]) so comments inside strings are never mistaken for actual comments. Your SQL remains syntactically valid after stripping - no broken strings, no malformed identifiers.
Comment Detection & Statistics
Get detailed analysis of all detected comments: see every comment with its type (single-line or multi-line), line number, and snippet. Track how many comments were removed, the total size reduction percentage, and before/after line counts. Side-by-side comparison of original vs cleaned SQL.
100% Browser-Local & Private
All SQL comment stripping runs entirely in your browser. Your SQL code never leaves your device. No server uploads, no API calls, no data storage, and no tracking. Perfect for cleaning sensitive database queries, proprietary schema definitions, or confidential data processing scripts.
Common Use Cases for SQL Comment Stripper
Deobfuscating SQL Injection Payloads
SQL injection payloads often use inline comments (/**/) to bypass WAF filters and keyword detection. Stripping all comments reveals the actual SQL commands and data extraction logic, making it easier to understand the attacker's intent and identify what data is being targeted.
Minifying SQL for Production Deployments
Remove documentation comments and verbose annotation headers from SQL schema files before deploying to production. Stripping comments reduces file size and removes internal documentation that shouldn't be visible in production environments while keeping all executable SQL intact.
SQL Query Analysis & Debugging
When analyzing complex SQL queries with extensive inline documentation, strip all comments to see the bare query structure. This makes it easier to understand the actual query logic, identify performance bottlenecks, and spot optimization opportunities without visual noise from comments.
Security Audit of SQL Code
Security auditors can strip comments from SQL code to reveal the bare logic for analysis. Hidden comments sometimes contain sensitive information like connection strings, server addresses, or development notes that should not be present in production code.
Educational Tool for SQL Syntax
Learn the difference between SQL code and SQL comments by seeing them side by side. Understand how single-line (--) and multi-line (/* */) comments work in SQL, and see exactly which parts of your code are comments versus executable statements.
CTF Challenge Preparation & Analysis
Capture The Flag challenges often hide clues or payloads inside SQL comments. Strip comments from provided SQL files to reveal hidden data, backdoor credentials, or steganographic content embedded in database setup scripts and query files.
Understanding SQL Comment Stripping
What is SQL Comment Stripping?
SQL comment stripping is the process of removing all comment syntax from SQL code while preserving the executable statements. SQL supports two comment styles: single-line commentsstarting with -- that run to the end of the line, andmulti-line block comments enclosed in /* */that can span multiple lines. Comments in SQL are commonly used for documentation, debugging, or obfuscating injection payloads. Stripping comments reveals the bare SQL statements without any annotation noise.
How Our SQL Comment Stripper Works
The tool tokenizes your SQL input character by character, tracking whether it is inside a string literal, quoted identifier, bracket identifier, or comment. When a -- sequence is found at the start of a comment (preceded by whitespace or a delimiter), the rest of that line is removed. When a /* sequence is found, all content up to the matching */ is removed, even if it spans multiple lines. The tool correctly handles escaped quotes within strings and nested quote contexts. After comment removal, you can optionally collapse multiple consecutive blank lines into one and trim leading/trailing whitespace.All processing is done client-side. No data is uploaded to any server.
What Gets Stripped & Preserved
- Stripped: Single-line
--comments, multi-line/* */block comments, inline end-of-line comments, documentation comment blocks, header/footer annotation sections. - Preserved: String literals (
'...'), double-quoted identifiers ("..."), backtick-quoted identifiers (`...`), SQL keywords, all executable statements (SELECT, INSERT, CREATE, etc.), and code formatting structure. - Optional: Empty lines left after comment removal can be collapsed to keep the output clean and compact.
Privacy & Limitations
This tool runs entirely in your browser. Your SQL code is never uploaded to any server. Important limitations: The tool removes comments but does not reformat or beautify your SQL - indentation and line breaks from the original code are preserved. Nested block comments are not supported as SQL does not allow nesting /* */comments. Comments within string literals (e.g.SELECT '-- not a comment') are correctly preserved. The tool works with any SQL dialect including MySQL, PostgreSQL, SQL Server, SQLite, Oracle, and MariaDB.
Related Obfuscator Tools
JavaScript Number Obfuscator
Obfuscate numeric literals in JavaScript code by converting them to math expressions, hex, octal, binary, and bitwise tricks.
JavaScript All-In-One Obfuscator
Combine multiple JS obfuscation techniques - variable renaming, string encoding, dead code, numbers, and control flow.
JavaScript Variable Name Deobfuscator
Analyze obfuscated JavaScript variable, function, and class names and suggest meaningful names based on usage context.
Java Control Flow Flattener
Flatten Java control flow into a switch-based dispatcher for obfuscation. Configurable depth with size analysis.
JavaScript Domain Lock Obfuscator
Add domain-locking to your JavaScript code with runtime hostname checks, encrypted allowed domain lists, and custom blocking.
CSS Variable Name Obfuscator
Rename CSS custom properties (--variable) and update all var() references across CSS, HTML, and JS. Shows full rename mapping.
Pixel Shuffle Image Obfuscator
Scramble and descramble images using seed-based pixel permutation. Fisher-Yates shuffle with Mulberry32 PRNG, lossless PNG output.
Image Noise Layer Obfuscator
Add controlled Gaussian, Uniform, or Salt & Pepper noise to obscure image details. Seed-based deterministic reversal, adjustable intensity.
Rust Integer/Literal Obfuscator
Obfuscate Rust numeric literals using hex, octal, binary, math expressions, bitwise tricks, and arithmetic combos. Supports i32, u64, f32, usize.
.NET String Encryptor/Obfuscator
Obfuscate C# string literals using hex escapes, Convert.FromBase64String, XOR encryption, char arrays, StringBuilder, and Unicode escapes.
.NET Integer/Number Obfuscator
Obfuscate .NET numeric literals using hex, binary, bitwise, arithmetic, Convert.ToInt32/64, type suffixes, and unchecked expressions. Supports int, long, float, decimal.
Swift String Obfuscator
Obfuscate Swift string literals using hex byte arrays, Data + Base64 encoding, XOR Data, Unicode scalars, and split concatenation. Copy generated code.
Bash Variable Name Obfuscator
Replace Bash variable names with short obfuscated names. Preserves builtins, special variables ($?, $@, $#), and environment variables (PATH, HOME). Complete mapping table.
Dart String Obfuscator
Obfuscate Dart string literals using hex escapes, String.fromCharCodes, Base64 decode, XOR encryption, split concatenation, and StringBuffer + writeCharCode calls.