safepaste json

JSON formatter

Paste some JSON on the left and a formatted copy will appear on the right. If it will not parse, the right side shows you the line where it went wrong, and the status line underneath explains what is wrong with it. All of this happens in this tab, and nothing is sent anywhere.

JSON

Formatted

Layout

What happens to what you paste

Nothing happens to it beyond what you asked for. It is read and formatted inside this browser tab, and it is gone as soon as you close the tab. SafePaste has no account, no database and no analytics, so there is nothing for it to be stored in.

How your browser enforces this

The page includes a Content Security Policy of connect-src 'none'. That makes fetch, XMLHttpRequest, WebSocket, EventSource and sendBeacon fail in the browser itself, whatever the code on this page tries to do. Images and fonts are restricted to data that is already inside the file, and form-action 'none' prevents all form submission.

You do not have to take our word for it. Open your browser's developer tools, watch the Network tab while you use the page, and confirm that it stays empty after the page itself has loaded.

What the host can see

This page is served by Cloudflare Pages. Like any web server, it sees the request for the page itself, which includes your IP address, the name and version of your browser, and the time of the request. That happens before any of this page's code runs, and it is the same for every website you visit. What it does not see is anything you paste, because nothing you paste is ever part of a request. That includes any addresses inside your JSON. They are shown as text, and none of them is visited, looked up or turned into a link.

Cookies, storage and tracking

Links to other sites

The footer links to Flytrap Industries and to a Stripe donation page. Neither is contacted unless you click it. They carry no query string and no referrer, so following one tells the destination nothing about what you were doing here. If you do donate, Stripe handles that payment under its own privacy policy and SafePaste never sees your card details.

Working offline

Save this page to disk and open it again. It is a single self-contained file, so it works with no network at all, including on a machine that has never been connected to one.

This policy describes the page you are reading. It is part of the same file, so the copy you save to disk carries it too.

How JSON works

JSON is a way of writing data down as text so that one program can hand it to another. It was taken from the way JavaScript writes objects, but it is stricter than JavaScript, and nearly every programming language can now read and write it. API responses, configuration files and log lines are very often JSON.

What it is made of

A JSON document is a single value, and there are six kinds of value. An object is a list of keys and values inside braces, where every key is a string. An array is a list of values inside square brackets. A string is text inside double quotes, a number is written in decimal, and the last three are the words true, false and null. Objects and arrays can hold any kind of value, including more objects and arrays, which is how JSON describes things that have parts.

On one line, which is called minified
{"name":"Ada","languages":["en","fr"],"active":true}
Formatted with two spaces of indentation
{
  "name": "Ada",
  "languages": [
    "en",
    "fr"
  ],
  "active": true
}

The spaces and line breaks between the parts mean nothing to a program reading JSON. The same document can be written on a single line to make it as small as possible, or spread over many lines with indentation so that a person can read it. Formatting only changes that whitespace, so the two versions above hold exactly the same data.

What JSON does not allow

Most JSON that will not parse has one of a handful of problems, usually because it was written by hand or copied out of JavaScript or Python, which are both more forgiving. This page recognizes each of these, and the status line names the one it found.

Comments and trailing commas

Some files that look like JSON are really JSONC, a variant that allows comments and trailing commas. The tsconfig.json file in a TypeScript project is one, and so are the settings files of several code editors. When the only problems in what you paste are comments and trailing commas, the status line offers to remove them, and it tells you how many of each it took out.

Numbers are kept exactly as they were written

JSON itself puts no limit on how large or how precise a number can be, but most programs that read it do. JavaScript, for example, keeps about 16 significant digits of any number, so its JSON.parse reads the ID 12345678901234567890 as 12345678901234567000. Large IDs from databases are the usual victims. This page never converts a number at all. It copies each one into the formatted version digit for digit, and when a number is one that JavaScript would change, the status line points it out.

Strings are treated the same way. An escape such as é stays an escape in the formatted copy instead of being turned into the character it stands for, so the only thing formatting changes is the whitespace, unless you ask for the keys to be sorted.

Duplicate keys

The JSON standard says the keys in an object should be unique, but it does not require it, and parsers disagree about what to do when a key appears twice. Most keep the last value without saying anything, a few keep the first, and some refuse the document. This page keeps both, in the order they were written, and the status line tells you where they are.

JSON inside a string

Sometimes a whole JSON document arrives inside a string, with every quote escaped, like "{\"id\":1}". That usually means something encoded it twice, which happens a lot in log files and message queues. When the string you paste contains JSON, the status line offers to format the JSON inside it.

JSON Lines

A log file often has one JSON value on each line, which is a format called JSON Lines or NDJSON. That is not a single JSON document, so it will not parse as one. When every line is valid on its own, the status line says so and offers to put the lines into an array, which is a single document that the page can format.