Developer Tools

SQL WHERE Clause Generator

Add conditions row by row and get a correct WHERE clause with placeholders for your driver and the matching list of parameters. The generator handles the parts that are easy to get wrong: brackets around OR groups, IN lists with one placeholder per value, BETWEEN ranges, IS NULL instead of = NULL, and LIKE patterns where %, _ and other special characters in the search text are escaped.

  • Runs in your browser
  • No sign-up
  • Free to use
Start from an example
Conditions

AND binds tighter than OR: a AND b OR c means (a AND b) OR c, and the generated SQL adds those brackets.

Text matching

    How to use SQL WHERE Clause Generator

    1. Add a row per condition: column, operator and value.
    2. Join conditions with AND or OR.
    3. Choose the placeholder style and database.
    4. Copy the WHERE clause and the parameters.

    SQL WHERE Clause Generator features

    Operators

    =, ≠, <, ≤, >, ≥, in, not in, between, contains, starts with, ends with, NULL checks.

    Correct precedence

    OR groups wrapped in brackets.

    Placeholders

    ?, $1, :name, @name, %s, %(name)s or inline values.

    Parameter list

    Values in order, or by name, as JSON.

    Safe LIKE

    Search text escaped so % and _ match literally.

    NULL handling

    = NULL rewritten as IS NULL.

    When to use SQL WHERE Clause Generator

    • Building filters for a search page or report.
    • Writing parameterised queries for PDO, JDBC, psycopg or .NET.
    • Checking AND/OR precedence in a complex condition.
    • Teaching safe query construction.

    SQL WHERE Clause Generator FAQ

    Why are some conditions in brackets?

    AND is evaluated before OR. a AND b OR c means (a AND b) OR c; the generator writes the brackets so the meaning is visible.

    Why does each IN value get its own placeholder?

    Drivers bind single values, not lists. IN (?, ?, ?) with three parameters is the portable way.

    What does ESCAPE '!' do?

    In a contains or starts-with search, % and _ in your text would act as wildcards. They are prefixed with ! and ESCAPE '!' tells the database to treat them literally.

    Which placeholder style do I need?

    PDO and JDBC use ?, PostgreSQL drivers $1, PDO and SQLAlchemy also :name, SQL Server and .NET @name, and Python’s DB-API %s or %(name)s.

    When are inline values fine?

    For ad-hoc queries you run yourself. In application code, always pass values as parameters.

    Is anything uploaded?

    No. The clause is generated in your browser.

    Correct, parameterised conditions

    The WHERE clause decides which rows a query touches, and small mistakes in it have big effects: a missing bracket around an OR returns too many rows, = NULL returns none, and user input pasted into the SQL opens the door to SQL injection. Building the clause from structured conditions avoids all three.

    Each row is one condition. Conditions are combined with AND unless a row starts with OR, and because AND binds more tightly than OR, the generator groups the conditions between ORs in brackets. The result reads the way the logic actually works.

    Values are never written into the SQL in placeholder mode. Each value becomes a placeholder in the style of your driver, and the parameters are listed separately as JSON, in order for positional styles or by name for named ones. IN lists get one placeholder per value and BETWEEN gets two.

    Text searches need special care. A search for 50%_off with LIKE would treat % and _ as wildcards. The contains, starts with and ends with operators escape them with ! and add ESCAPE '!', which behaves the same in every database. A note reminds you that patterns starting with % cannot use an ordinary index.

    In PostgreSQL, the case-insensitive option uses ILIKE, since LIKE is case-sensitive there; MySQL, SQL Server and SQLite compare case-insensitively with their usual collations.

    Other useful tools