SQL Parameter Binder for MyBatis, Hibernate and JDBC Logs

Paste a MyBatis log with ==> Preparing and ==> Parameters lines, a Hibernate log with binding parameter lines, or any parameterized SQL plus its values, and get executable SQL with every placeholder replaced by a correctly quoted literal. The binder understands JDBC ? markers, PostgreSQL $1..$n (including repeated and two-digit numbers), and named :name, @name and #{name} parameters. It walks the SQL character by character, so question marks, colons and dollar signs inside strings, quoted identifiers, comments, dollar-quoted bodies and :: casts are left alone, and it reports any placeholder without a value and any value left over. Nothing is uploaded: everything runs in your browser.

Samples:
Parameters are read from the log itself; switch Input to "SQL + parameter list" to type them separately.
MyBatis log · 2 statements · 9 placeholders · 9 parameters · all placeholders bound

Do more than sql parameter binder for mybatis, hibernate and jdbc logs — meet Chat2DB

Chat2DB is an AI-powered SQL client for Windows, macOS and Linux. Write SQL in natural language, format and optimize queries automatically, and manage MySQL, PostgreSQL, Oracle and 20+ other databases in one workspace.

How ORMs and drivers log SQL parameters

Almost every Java, Node.js or Python data layer sends SQL to the database as a prepared statement: the statement text with placeholders goes first, and the parameter values travel separately in a binary bind message. That is why logs never show the final SQL - the database itself never sees one. Each framework prints the two halves in its own format, and this binder stitches them back together.

MyBatis

With the mapper namespace logger at DEBUG (for example logging.level.com.example.mapper=debug in Spring Boot, or mybatis.configuration.log-impl=org.apache.ibatis.logging.stdout.StdOutImpl), MyBatis prints "==> Preparing:" with every #{...} already turned into ?, then "==> Parameters:" with each value followed by its Java class in parentheses, and finally "<== Total" or "<== Updates". A null value is printed as a bare null. ${...} placeholders are string substitutions and are already inlined in the Preparing line. With the batch executor one Preparing line is followed by several Parameters lines; each becomes its own statement here.

Hibernate and Spring Data JPA

spring.jpa.show-sql or the org.hibernate.SQL logger prints the SQL with ? markers. Values come from a separate TRACE logger: org.hibernate.type.descriptor.sql.BasicBinder in Hibernate 5 (binding parameter [1] as [VARCHAR] - [abc]) and org.hibernate.orm.jdbc.bind in Hibernate 6 (binding parameter (1:VARCHAR) <- [abc]). The JDBC type in the brackets decides whether the value is quoted. Note that Hibernate prints a real NULL and the string "null" identically, so the binder treats [null] as SQL NULL.

Plain JDBC, node-postgres and other drivers

JDBC PreparedStatement uses positional ? markers (?? is the escape for a literal question mark in the PostgreSQL driver, which matters for jsonb operators such as ?, ?| and ?& - in ? mode every single ? outside strings and comments is treated as a placeholder). node-postgres, pgx, asyncpg and PostgreSQL's own PREPARE use $1, $2 ... and may repeat the same number; $10 is a different parameter from $1. Named styles such as :name (JPA, SQLAlchemy text(), Oracle), @name (SQL Server, Dapper) and #{name} (MyBatis mapper XML) take a JSON object or name=value lines. Quotes, comments, dollar-quoted bodies and :: casts are never touched.

Why the inlined SQL is not the same as the prepared statement

The output is meant for debugging: paste it into a SQL client, run EXPLAIN on it, or share a reproducible query in a bug report. It is not equivalent to what the application executed. With bind parameters the database can reuse a cached plan (PostgreSQL switches to a generic plan after five executions, Oracle and SQL Server cache plans per statement text), whereas literal values can produce a different, sometimes better, sometimes worse, plan - so a slow query may be fast when inlined, or the reverse. Implicit type conversion also differs: a bound VARCHAR compared to a numeric column is handled by the driver, while a quoted literal is cast by the server. Most importantly, never copy the inlined form back into application code. Building SQL by concatenating values is exactly how SQL injection happens; keep using placeholders in production and use this tool only to read logs.

How to use

  1. Paste a MyBatis or Hibernate log (timestamps, thread names and several statements are fine), or plain SQL with ?, $n or named placeholders. The input type is detected automatically; override it with the Input and Placeholders selectors if needed.
  2. For plain SQL, enter the parameters one per line or as a JSON array (JSON object or name=value lines for named placeholders). Wrap a value in single quotes to force a string, and use Quote every value, Booleans and Backslash escapes to match your database.
  3. Check the summary and any mismatch warnings, then copy the executable SQL into your SQL client to run or EXPLAIN it.

Frequently asked questions

How do I see the actual SQL with parameters from a MyBatis log?

MyBatis never logs the final SQL; it logs the Preparing statement with ? markers and a separate Parameters line such as 1(Integer), abc(String), null. Copy both lines (or a whole block of log output, prefixes included) into the binder. It pairs each Preparing line with the Parameters line that follows, splits the values on their (Type) suffixes so strings containing commas or parentheses stay intact, quotes String, Timestamp and LocalDateTime values, leaves Integer, Long and BigDecimal unquoted, and turns a bare null into NULL.

Why are some question marks or $1 in my SQL not replaced?

Placeholders inside single-quoted strings, double-quoted or backtick identifiers, -- and /* */ comments and PostgreSQL $$ dollar-quoted bodies are not parameters, so they are kept as written, and :: casts are never mistaken for :name parameters. A ?? is the JDBC escape for a literal ? and is output as a single ?. If a real placeholder has no value, it is left in place and listed in the warnings, as is any parameter that was never used. PostgreSQL jsonb operators ?, ?| and ?& look exactly like JDBC markers, so check those by hand.

Where can I run and EXPLAIN the bound SQL?

Paste the output into any SQL client connected to a development copy of the database. Chat2DB (https://chat2db.ai/download, or the web version at https://app.chat2db.ai) runs it against MySQL, PostgreSQL, Oracle, SQL Server and 20+ other databases, shows the execution plan, and its AI assistant can explain why the query is slow or rewrite it. Keep in mind that the inlined query may get a different plan from the prepared statement, and never paste inlined SQL back into application code.

More free SQL tools

SQL Formatter & Beautifier
Format and beautify SQL queries online with dialect-aware indentation and keyword casing.
SQL Validator & Syntax Checker
Check SQL syntax online for MySQL, PostgreSQL and more, with clear error messages.
SQL Minifier
Minify SQL by stripping comments and collapsing whitespace into a single line.
MySQL to PostgreSQL Converter
Convert MySQL DDL and queries to PostgreSQL syntax with a best-effort dialect translator.
CSV to SQL Converter
Turn CSV, TSV or pasted Excel data into SQL INSERT statements.
JSON to SQL Converter
Convert a JSON array of objects into SQL INSERT statements.
SQL IN Clause Generator
Paste a list of values and get a ready-to-use SQL IN (...) clause.
SQL Escape & Unescape
Escape single quotes and special characters for safe SQL string literals.
JDBC Connection String Builder
Build JDBC URLs for MySQL, PostgreSQL, SQL Server, Oracle, MariaDB and ClickHouse.
SQL Cheat Sheet
A practical SQL reference: joins, aggregation, window functions, DDL and dialect differences.
UUID Generator (v4 & v7)
Generate UUID v4 and time-ordered UUID v7 in bulk, as plain text, JSON, CSV or SQL.
Cron Expression Generator & Validator
Build and validate cron expressions with plain-English explanations and next run times.
PostgreSQL EXPLAIN Plan Visualizer
Turn EXPLAIN ANALYZE output into a readable plan tree with timings and tuning warnings.
PgBouncer Config Generator
Generate pgbouncer.ini and size connection pools from your app instances and CPU cores.
PostgreSQL Partition Table Generator
Generate RANGE, LIST and HASH partitioning DDL with child partitions and maintenance SQL.
pg_dump Command Generator
Build pg_dump and pg_restore commands with format, filter and parallel job options.
mysqldump Command Generator
Build mysqldump backup commands with scope, options and a matching restore command.
SQL Test Data Generator
Generate realistic fake rows as SQL INSERT statements, CSV or JSON, right in your browser.
PostgreSQL Config Calculator
Calculate tuned postgresql.conf settings from your RAM, CPU cores, connections and workload.
SQL DDL to Code Generator
Convert CREATE TABLE statements into TypeScript, Prisma, Drizzle, Go, JPA or SQLAlchemy models.
SQL Window Function Generator
Build ROW_NUMBER, RANK, LAG, LEAD and running-total OVER() clauses with PARTITION BY and frames.
Docker Compose PostgreSQL Generator
Generate a docker-compose.yml for PostgreSQL with volumes, healthchecks, init scripts and pgAdmin.
PostgreSQL Replication Config Generator
Generate streaming and logical replication config: postgresql.conf, pg_hba.conf, slots and pg_basebackup.
SQL Injection Checker
Scan code for SQL injection risks and rewrite unsafe queries with bound parameters.
SQL to ER Diagram Generator
Paste CREATE TABLE DDL and get an entity relationship diagram plus Mermaid erDiagram code.
Postgres Connection String Generator
Build PostgreSQL connection strings: libpq URI, DSN, JDBC, psycopg, SQLAlchemy, Npgsql and .env.
Postgres GRANT Statement Generator
Generate PostgreSQL GRANT, ALTER DEFAULT PRIVILEGES and REVOKE scripts for read-only or read-write roles.
Postgres COPY Command Generator
Build PostgreSQL COPY and psql \copy commands to import or export CSV with HEADER, DELIMITER, NULL and WHERE options.
Postgres CREATE INDEX Generator
Generate PostgreSQL CREATE INDEX statements: B-tree, GIN, GiST, BRIN, UNIQUE, CONCURRENTLY, partial WHERE, INCLUDE and expression indexes.
Postgres TO_CHAR Date Format Builder
Build PostgreSQL TO_CHAR date format patterns with live preview, presets and generated TO_CHAR / TO_TIMESTAMP statements.
Postgres FDW Setup Generator
Generate postgres_fdw CREATE SERVER, USER MAPPING and IMPORT FOREIGN SCHEMA SQL for querying a remote Postgres database.
Postgres EXCLUDE Constraint Generator
Generate PostgreSQL EXCLUDE constraint SQL: GiST/SP-GiST operators, btree_gist columns, partial WHERE and overlap-check verification.
pgvector Index & Schema Generator
Generate pgvector SQL: vector/halfvec columns, HNSW or IVFFlat indexes, tuned parameters and the matching nearest-neighbour query.
Postgres ALTER COLUMN TYPE Generator
Generate ALTER TABLE ALTER COLUMN TYPE SQL with the right USING cast, a table-rewrite verdict and a batched zero-downtime migration.
Postgres UPSERT Generator
Build INSERT ... ON CONFLICT DO UPDATE/DO NOTHING statements, the MERGE equivalent and the unique index they need.
pg_hba.conf Generator
Generate PostgreSQL client authentication rules with the right connection type, CIDR and auth method.
Postgres Trigger Generator
Generate CREATE TRIGGER SQL and plpgsql trigger functions: updated_at touch, JSONB audit log, operation guards and TG_OP skeletons.
Postgres VACUUM Command Generator
Build VACUUM / VACUUM FULL / ANALYZE commands with the right options, plus monitoring SQL and per-table autovacuum tuning.
SQL Pivot Generator (Rows to Columns)
Generate pivot queries with FILTER or CASE WHEN aggregates, the PostgreSQL crosstab() version and the reverse unpivot.
Epoch & Unix Timestamp Converter
Convert epoch to date and back with auto unit detection, plus to_timestamp and extract(epoch) SQL snippets.
pg_restore Command Generator
Build pg_restore or psql restore commands from a Postgres dump: archive format, parallel jobs, clean, no-owner and single-transaction options.
Postgres JSONB Query Builder
Generate JSONB queries from a nested path and operator, with the matching GIN or expression index and a JSONB cookbook.
SQL Schema Diff & Migration Generator
Compare two SQL schemas and generate the ALTER TABLE up and down migration, with lock and rewrite warnings.
Postgres Table Size Estimator
Estimate table and index size from your columns and row count, including tuple header, alignment padding and column-order savings.
Postgres Full Text Search Generator
Generate tsvector columns, GIN indexes, weighted ranking and ts_headline queries for PostgreSQL full text search.
Levenshtein Distance Calculator
Compute edit distance between two strings with the full DP matrix, edit path and matching Postgres fuzzy search SQL.
SQL Linter & Style Checker
Lint SQL for correctness traps, non-sargable predicates and style issues in your browser.
Database Normalization Analyzer
Find candidate keys and 1NF/2NF/3NF/BCNF violations, then get a lossless decomposition.
Connection Pool Size Calculator
Size your database connection pool from cores, latency and instances, with HikariCP, pgxpool, node-pg, SQLAlchemy and PgBouncer config.
PostgreSQL Error Code Lookup
Look up any SQLSTATE code or paste an error message to get the cause, the fix and how to catch it in your driver.
Postgres Autovacuum Calculator
Work out when autovacuum fires on a table, how much bloat builds up first, and generate per-table ALTER TABLE tuning.
SQL to MongoDB Query Converter
Convert a SQL SELECT into a MongoDB find() call or aggregation pipeline, with $lookup, $group, $match and $sort mapping.
pgloader Config Generator
Build a pgloader .load file to migrate MySQL, SQL Server, SQLite or CSV into PostgreSQL, with cast rules, table filters and verification SQL.
Postgres Upgrade Planner
Compare pg_upgrade, dump/restore and logical replication for a major version upgrade, with downtime estimates, commands and breaking changes.
SQL Join Visualizer
See INNER, LEFT, RIGHT, FULL, CROSS and anti joins run on real sample rows, with the SQL.
SCD Type 2 SQL Generator
Generate slowly changing dimension Type 2 DDL and load SQL for Postgres, Snowflake and BigQuery.
Postgres RLS Policy Generator
Generate PostgreSQL row level security policies for multi-tenant, per-user or role-based access.
Postgres Data Masking Generator
Build masked views, anonymization UPDATEs or PostgreSQL Anonymizer labels for sensitive columns.
Online SQL Playground
Run SQL in your browser against a sample SQLite database, with 10 checked practice exercises.
SQL CASE WHEN Generator
Build searched or simple CASE expressions with full queries and IF/IIF/DECODE equivalents per dialect.
SQL Set Operations Visualizer
See UNION, UNION ALL, INTERSECT and EXCEPT run on real rows, with counts and SQL per dialect.
Postgres Enum Type Generator
Generate CREATE TYPE, ADD VALUE, RENAME VALUE, safe value removal and enum-to-CHECK or lookup migrations.
Postgres Lock Conflict Checker
Check whether two PostgreSQL statements or LOCK TABLE modes block each other, with the conflict matrix and pg_locks queries.
Postgres Timezone Converter
Convert timestamps between IANA zones and generate AT TIME ZONE, SET timezone and date_trunc SQL with DST warnings.
Slow Query Log Analyzer
Group a MySQL or PostgreSQL slow query log by normalized query shape and rank the shapes by total time.
Postgres generate_series Builder
Build generate_series SQL for calendar tables, time buckets, gap-filled reports and test data, with a row preview.
Postgres Index Type Advisor
Pick between B-tree, Hash, GIN, GiST, SP-GiST, BRIN and HNSW for a column and query pattern, with the CREATE INDEX statement and operator class.
Postgres SERIAL to IDENTITY Converter
Convert a SERIAL or BIGSERIAL column to GENERATED AS IDENTITY with the correct setval, rollback and optional bigint widening.
Postgres DROP ROLE Helper
Generate the audit queries, REASSIGN OWNED, DROP OWNED and DROP ROLE script that clears "role cannot be dropped" errors.
pg_stat_statements Query Builder
Build version-correct Top-N pg_stat_statements queries by total time, mean time, calls, cache misses, temp spills or WAL.
AWS DMS Table Mapping Generator
Build a valid AWS DMS table-mappings.json with selection rules, schema and table renames, column removal and source row filters.
ClickHouse MergeTree Table Generator
Generate ClickHouse CREATE TABLE DDL with MergeTree engines, sorting keys, partitioning, TTL and compression codecs.
SQL Server to PostgreSQL Converter
Translate T-SQL DDL and queries to PostgreSQL: brackets, IDENTITY, NVARCHAR, TOP, GETDATE and more.
Docker Compose MySQL & MariaDB Generator
Generate docker-compose.yml for MySQL or MariaDB with volumes, healthchecks, init scripts and phpMyAdmin.
Oracle to PostgreSQL Converter
Translate Oracle DDL and SQL to PostgreSQL: VARCHAR2, NUMBER, NVL, DECODE, SYSDATE, sequences and more.
SQL Server Backup & Restore Command Generator
Generate T-SQL BACKUP and RESTORE scripts with compression, checksum, WITH MOVE, STOPAT and sqlcmd.
pgbench Command Generator
Build pgbench init and benchmark command lines for PostgreSQL load testing.
dbt schema.yml Generator
Turn a CREATE TABLE statement into a dbt schema.yml with data tests and a unit test skeleton.
DBML to SQL Converter
Convert DBML schemas to PostgreSQL or MySQL DDL, and turn existing CREATE TABLE statements back into DBML.
Liquibase Changelog Generator
Turn SQL DDL into a Liquibase changelog in XML, YAML, JSON or formatted SQL, with constraints and rollbacks.
MySQL Config Calculator
Generate a tuned my.cnf from your RAM, cores and workload, with an InnoDB memory budget check.
Debezium Connector Config Generator
Build a Debezium CDC connector config for PostgreSQL, MySQL, SQL Server, Oracle or MongoDB.
MongoDB Connection String Builder
Build or parse mongodb:// and mongodb+srv:// URIs with encoded passwords, auth and replica set options.
MySQL GRANT Statement Generator
Generate MySQL 8 CREATE USER, GRANT, role and REVOKE scripts for read-only, read-write or replication users.
SQL Server Connection String Builder
Build or parse SQL Server connection strings for ADO.NET, ODBC, JDBC, sqlcmd and SQLAlchemy with Encrypt options.
MySQL DATE_FORMAT Builder
Build MySQL DATE_FORMAT and STR_TO_DATE patterns with a live preview and every % format specifier explained.
Oracle tnsnames.ora Generator
Build or parse Oracle tnsnames.ora entries with RAC failover and TCPS, plus EZConnect, JDBC thin URLs and sqlplus.
SQL Server Date Format Converter
Every CONVERT date style code (101, 103, 112, 120, 126…) rendered live, plus a FORMAT() builder and string-to-date help.
SQL INSERT to CSV / JSON Converter
Turn INSERT statements or a mysqldump / pg_dump file into CSV, TSV, JSON or Markdown, with correct quoting and NULLs.
Oracle Date Format Builder
Live TO_CHAR preview for any Oracle date format mask (FM, TH/SP, IW, J, FF), common masks and TO_DATE string parsing.
MySQL Error Code Lookup
Look up a MySQL error number, symbol or message and get the cause, a concrete fix and a code snippet to catch it in your driver.
Postgres Sequence Reset Generator
Fix "duplicate key value violates unique constraint" after imports: generate setval SQL that resets serial and identity sequences to MAX(id)+1.
SQL Data Dictionary Generator
Paste CREATE TABLE DDL and get a data dictionary with types, keys, defaults and comments as Markdown, HTML, CSV or JSON.
OtterMind
OtterMind