CSV to SQL: Generate CREATE TABLE and INSERT Statements Safely
In this article
Importing a CSV into a database is a routine job that goes wrong in routine ways: a name like O’Neil breaks the SQL, a header with a space in it isn’t a valid column name, or phone numbers lose their leading zero. The free CSV to SQL converter generates a CREATE TABLE statement and batched INSERT statements for MySQL/MariaDB, PostgreSQL or SQLite, with every value escaped correctly. Here is how to use it and what to check before running the result.
How to convert CSV to SQL
- Open the CSV to SQL converter and choose your CSV file. The first row must contain column names.
- Enter a table name.
- Choose your database: MySQL/MariaDB, PostgreSQL or SQLite.
- Keep Include a CREATE TABLE statement ticked to create the table, or untick it to generate INSERT statements only for an existing table.
- Generate and download the .sql file, then run it in your database client.
What the output looks like
For a small CSV of customers, MySQL output looks like this:
-- Generated by FreeToolConvert CSV to SQL (mysql)
SET NAMES utf8mb4;
CREATE TABLE `customers` (
`name` TEXT,
`city` TEXT,
`orders` BIGINT
) DEFAULT CHARSET=utf8mb4;
INSERT INTO `customers` (`name`, `city`, `orders`) VALUES
('Priya Sharma', 'Delhi', 12),
('Sean O''Neil', 'Mumbai', 3);
How column types are chosen
The converter looks at the first 1,000 rows of each column:
- Only whole numbers →
BIGINT - Decimal numbers →
DECIMAL(20,6) - Anything else →
TEXT - Empty cells →
NULL
Review the types before production use. A column of phone numbers or PIN codes contains only digits, so it is typed as a number — but it should be text, or numbers like 011001 lose their leading zero. Change those columns to VARCHAR or TEXT in the CREATE TABLE statement before running it. You may also want to add a primary key and indexes.
Escaping: why it matters
Writing INSERT statements by hand or with a spreadsheet formula usually breaks on the first apostrophe. The converter escapes for each database:
- Single quotes inside values are doubled:
O''Neil. - For MySQL, backslashes are escaped too.
- Column and table names are quoted — backticks for MySQL, double quotes for PostgreSQL and SQLite — so headers like “Order Date” or reserved words like “order” still work.
Because every value is escaped, the content of the CSV can’t change the meaning of the SQL.
Hindi and other non-English text
The MySQL output starts with SET NAMES utf8mb4 and creates the table with DEFAULT CHARSET=utf8mb4, so Hindi, emoji and other characters are stored correctly. CSV files saved as UTF-8 (with or without a BOM) or UTF-16 are all read correctly. PostgreSQL and SQLite store UTF-8 by default.
Limits and privacy
- Up to 50,000 rows per file.
- This tool runs on our server. The file is uploaded over HTTPS and deleted automatically within an hour.
- Server tools include a free daily allowance; after that, each conversion uses 1 credit.
Running the SQL
- MySQL/MariaDB:
mysql -u user -p database < customers.sql, or Import in phpMyAdmin. - PostgreSQL:
psql -d database -f customers.sql. - SQLite:
sqlite3 data.db < customers.sql.
Need JSON instead? See converting CSV to JSON.