JavaScript Object Notation (.json)

RFC Standard

JavaScript Object Notation (JSON) is a lightweight, human-readable text format for data interchange, completely language-independent and universally used for web APIs.

Convert JSON to HTML

Free in-browser JSON to HTML converter. Convert files instantly on your device.

Compress JSON Online

100% private in-browser compression - files never leave your device

Inspect & Metadata

Operating systems and file analyzers identify JSON files by inspecting the leading binary byte sequence:

Select or drag files

Select or drop files here

100% private in-browser conversion - files never leave your device

or paste Ctrl+V
Zero-Network-Transmission Privacy Guarantee: 0 bytes uploaded to external servers. All processing occurred locally in your browser sandbox.

Byte-Level Header Signature (Magic Bytes)

Operating systems and file analyzers identify JSON files by inspecting the leading binary byte sequence:

HEX SIGNATURE (OFFSET 0):

7B or 5B

ASCII REPRESENTATION: { or [

Standardization: RFC 8259 / ECMA-404 / ISO/IEC 21778

Technical Specifications

Container ArchitectureLightweight, text-based, language-independent data interchange format
CompressionGzip / Brotli / Zstandard text compression (typically achieves 80%-90% ratio)
Byte EndiannessUTF-8 encoded Unicode (no Byte Order Mark / BOM recommended)
Color SpacesNot applicable
Channels & StructureSix basic data types: object, array, string, number, boolean, null
Max DimensionsUnbounded; limited only by parser memory and maximum string length
TransparencyNot applicable
Streaming & ProgressiveNDJSON (Newline Delimited JSON) / JSON Lines enables progressive stream processing

Technical Comparison Matrix: JSON vs Competitors

Technical AttributeJSON (Current)YAMLXMLProtocol Buffers
Syntax ComplexityMinimal (6 types, strict syntax)High (indentation-based, complex spec)High (verbose closing tags, namespaces)Schema-defined binary wire format
Parsing PerformanceExtremely fast in all modern languagesSlow (complex indentation parsing)Moderate to slow (heavy DOM construction)Ultra-fast (zero-copy binary deserialization)
Comments SupportedNo (deliberately excluded to prevent metadata creep)Yes (# comments)Yes (<!-- comments -->)Yes in .proto files
Network Payload SizeCompact text (very high gzip ratio)Compact textVerbose text (heavy tag repetition)Ultra-compact binary

Common Corruption Modes & Hex Recovery Guide

⚠️ SyntaxError: Unexpected token , in JSON at position X.

Root Cause: Trailing comma after the last item in an array or object, which is strictly illegal in RFC 8259 JSON.

Recovery: Remove trailing commas from object keys and array entries before passing to JSON.parse().

⚠️ SyntaxError: Unexpected token ' in JSON.

Root Cause: Strings or keys enclosed in single quotes ('') instead of double quotes ("").

Recovery: Replace all single-quoted strings and keys with standard double-quoted strings.

Security Analysis & Parser Attack Vectors

JSON is text-only and safe from direct code execution, but parsing untrusted JSON can lead to Prototype Pollution, ReDoS, or memory exhaustion.

Known Attack Vectors

  • Prototype Pollution: Keys named '__proto__' or 'constructor' modifying Object.prototype in JavaScript applications.
  • Stack overflow denial of service via deeply nested JSON structures (e.g. 10,000 opening brackets).
  • Loss of numeric precision: JavaScript numbers larger than 2^53 - 1 (9,007,199,254,740,991) silently lose precision.

Defensive Best Practices: Never evaluate JSON with eval(). Use JSON.parse() and sanitize '__proto__' properties in recursive object merge functions.

Historical Origins & Milestones

2017RFC 8259 standardizes UTF-8 as the sole mandatory character encoding for JSON.
2013ECMA-404 defines the universal JSON syntax standard.
2001Douglas Crockford specifies JSON to enable stateless browser-to-server data communication.

Key Advantages & Pros

  • Human-readable, self-describing, and concise text structure.
  • Native parsing support built into JavaScript engines (JSON.parse) and every major programming language.
  • Strict specification prevents arbitrary code execution.

Technical Limitations & Cons

  • No support for comments, trailing commas, or circular object references.
  • No native binary types (binary data must be base64-encoded, inflating size by 33%).
  • Inefficient serialization compared to binary formats like Protocol Buffers or MessagePack.

Interesting Technical Trivia

  • Douglas Crockford added the software license clause 'The Software shall be used for Good, not Evil' to the original JSMin JSON tools.
  • JSON is a strict subset of JavaScript syntax, but until ES2019, raw unescaped U+2028 and U+2029 characters were valid in JSON but invalid in JavaScript strings.

Frequently Asked Technical Questions

Why doesn't JSON allow comments?

Douglas Crockford deliberately excluded comments from the JSON specification to prevent developers from putting parsing instructions or environment-dependent configuration pragmas into data feeds, preserving universal interoperability.

How do you store 64-bit integers in JSON without losing precision?

JavaScript's native Number type is an IEEE 754 double-precision float, which only supports integers up to 2^53 - 1 precisely. 64-bit integers (like database IDs or timestamps) must be serialized as strings (e.g. '1234567890123456789') in JSON.