JavaScript Object Notation (.json)

RFC Standard

JavaScript Object Notation (JSON) is a lightweight, human-readable text format for data interchange, completely language-independent and universally used for web APIs.

Convertir JSON en HTML

Convertisseur gratuit de JSON vers HTML dans le navigateur. Convertissez des fichiers instantanément sur votre appareil.

Compresser des fichiers JSON en ligne

Compression 100% privée dans le navigateur – les fichiers ne quittent jamais votre appareil

Inspecter et métadonnées

Les systèmes d'exploitation et les analyseurs de fichiers identifient les fichiers JSON en inspectant la séquence d'octets binaires de tête :

Sélectionnez ou faites glisser des fichiers

Sélectionnez ou déposez des fichiers ici

Conversion 100 % privée dans le navigateur - les fichiers ne quittent jamais votre appareil

ou coller Ctrl+V
Garantie de confidentialité sans transmission réseau : 0 octet téléchargé vers des serveurs externes. Tout le traitement a lieu localement dans le bac à sable de votre navigateur.

Signature d'en-tête au niveau des octets (Magic Bytes)

Les systèmes d'exploitation et les analyseurs de fichiers identifient les fichiers JSON en inspectant la séquence d'octets binaires de tête :

SIGNATURE HEXADÉCIMALE (DÉCALAGE 0) :

7B or 5B

REPRÉSENTATION ASCII : { or [

Normalisation : RFC 8259 / ECMA-404 / ISO/IEC 21778

Spécifications techniques

Architecture de conteneurLightweight, text-based, language-independent data interchange format
CompressionGzip / Brotli / Zstandard text compression (typically achieves 80%-90% ratio)
Boutisme des octetsUTF-8 encoded Unicode (no Byte Order Mark / BOM recommended)
Espaces colorimétriquesNot applicable
Canaux et structureSix basic data types: object, array, string, number, boolean, null
Dimensions maximalesUnbounded; limited only by parser memory and maximum string length
TransparenceNot applicable
Streaming et progressifNDJSON (Newline Delimited JSON) / JSON Lines enables progressive stream processing

Matrice de comparaison technique : JSON vs Concurrents

Attribut techniqueJSON (Actuel)YAMLXMLProtocol Buffers
Syntax ComplexityMinimal (6 types, strict syntax)High (indentation-based, complex spec)High (verbose closing tags, namespaces)Schema-defined binary wire format
Parsing PerformanceExtremely fast in all modern languagesSlow (complex indentation parsing)Moderate to slow (heavy DOM construction)Ultra-fast (zero-copy binary deserialization)
Comments SupportedNo (deliberately excluded to prevent metadata creep)Yes (# comments)Yes (<!-- comments -->)Yes in .proto files
Network Payload SizeCompact text (very high gzip ratio)Compact textVerbose text (heavy tag repetition)Ultra-compact binary

Modes de corruption courants et guide de récupération hexadécimale

⚠️ SyntaxError: Unexpected token , in JSON at position X.

Cause racine: Trailing comma after the last item in an array or object, which is strictly illegal in RFC 8259 JSON.

Récupération: Remove trailing commas from object keys and array entries before passing to JSON.parse().

⚠️ SyntaxError: Unexpected token ' in JSON.

Cause racine: Strings or keys enclosed in single quotes ('') instead of double quotes ("").

Récupération: Replace all single-quoted strings and keys with standard double-quoted strings.

Analyse de sécurité et vecteurs d'attaque de l'analyseur

JSON is text-only and safe from direct code execution, but parsing untrusted JSON can lead to Prototype Pollution, ReDoS, or memory exhaustion.

Vecteurs d'attaque connus

  • Prototype Pollution: Keys named '__proto__' or 'constructor' modifying Object.prototype in JavaScript applications.
  • Stack overflow denial of service via deeply nested JSON structures (e.g. 10,000 opening brackets).
  • Loss of numeric precision: JavaScript numbers larger than 2^53 - 1 (9,007,199,254,740,991) silently lose precision.

Bonnes pratiques de défense: Never evaluate JSON with eval(). Use JSON.parse() and sanitize '__proto__' properties in recursive object merge functions.

Origines historiques et jalons

2017RFC 8259 standardizes UTF-8 as the sole mandatory character encoding for JSON.
2013ECMA-404 defines the universal JSON syntax standard.
2001Douglas Crockford specifies JSON to enable stateless browser-to-server data communication.

Principaux avantages

  • Human-readable, self-describing, and concise text structure.
  • Native parsing support built into JavaScript engines (JSON.parse) and every major programming language.
  • Strict specification prevents arbitrary code execution.

Limites techniques

  • No support for comments, trailing commas, or circular object references.
  • No native binary types (binary data must be base64-encoded, inflating size by 33%).
  • Inefficient serialization compared to binary formats like Protocol Buffers or MessagePack.

Anecdotes techniques

  • Douglas Crockford added the software license clause 'The Software shall be used for Good, not Evil' to the original JSMin JSON tools.
  • JSON is a strict subset of JavaScript syntax, but until ES2019, raw unescaped U+2028 and U+2029 characters were valid in JSON but invalid in JavaScript strings.

Foire aux questions techniques

Why doesn't JSON allow comments?

Douglas Crockford deliberately excluded comments from the JSON specification to prevent developers from putting parsing instructions or environment-dependent configuration pragmas into data feeds, preserving universal interoperability.

How do you store 64-bit integers in JSON without losing precision?

JavaScript's native Number type is an IEEE 754 double-precision float, which only supports integers up to 2^53 - 1 precisely. 64-bit integers (like database IDs or timestamps) must be serialized as strings (e.g. '1234567890123456789') in JSON.