JSON Formatter & Validator
Format, validate and measure JSON, with errors located by line and column.
Paste JSON on the left.
How it works
Formatting is the easy half. The useful half is telling you precisely where a document stops being JSON, and what it contains once it parses.
Strict, deliberately
Trailing commas, unquoted keys, single quotes and comments are rejected. They are JavaScript object syntax or JSON5, not JSON, and a formatter that repairs them hands you back something the source never said — which matters when the source is evidence rather than a file you are editing.
Errors are located here, not read off the engine
V8 stopped putting an offset in its JSON error messages, so a tool built on parsing that message reports line 1 for every error — useless on a 400-line document. This page scans the text against the grammar in RFC 8259 and reports the line, the column and the line itself. The scan runs only after the native parse has already failed, so the ordinary path is still one fast parse.
Duplicate keys
A key repeated inside one object is legal JSON. JSON.parse keeps the last and discards the rest in
silence, so {"a":1,"a":2} becomes {a:2} and the 1 is simply gone. That is also
how a value gets smuggled past something that read the first occurrence — so the raw text is scanned for it,
because the parsed object no longer holds the evidence.
Nothing is executed
JSON.parse is a data parser, not an evaluator, and this page never calls eval or
new Function. A payload crafted to exploit a JSON consumer is inert text here — including a
__proto__ key, which JSON.parse stores as an ordinary property rather than following it
to a prototype.
Example
A malformed line reports as Line 3, column 10 — "o" does not start a JSON value, with the offending
line shown beneath it. A valid document reports its depth, node count and any repeated keys instead — the shape
information that tells you whether an API response changed.
Frequently asked questions
Why does it reject JSON that other formatters accept?
Because trailing commas, unquoted keys, single quotes and comments are not JSON — they are JavaScript object syntax or JSON5. A formatter that repairs them hands you back something the source never said, which matters when the source is evidence.
How is the error position worked out?
By scanning the text against the grammar in RFC 8259, not by reading the engine’s message. V8 stopped including an offset in its JSON errors, so a tool that parses that message reports line 1 for every error — useless on a 400-line document.
What is a duplicate key and why flag it?
A key repeated inside the same object. JSON.parse keeps the last one and discards the rest silently, so {"a":1,"a":2} becomes {a:2} and the 1 is gone. That is legal, and it is also how a value gets smuggled past something that read the first occurrence — so the raw text is scanned for it, since the parsed object no longer holds the evidence.
Can pasting hostile JSON here run anything?
No. JSON.parse cannot execute code — it is a data parser, not an evaluator — and this page never calls eval or new Function. A payload crafted to exploit a JSON consumer is inert text here.
Related tools
JWT Decoder
Decode a JSON Web Token and read its header, claims and expiry.
LocalBase64 Decoder
Decode Base64 and Base64URL back to text or raw bytes.
LocalURL Parser
Split a URL into scheme, host, path, query and fragment.
LocalHTTP Status Code Lookup
What a status code means, which RFC defines it, and what to do next.
LocalJWT Security Inspector
Check a decoded token against the weaknesses that show up in real audits.
LocalRegex Tester
Test a pattern against sample text with a hard execution timeout.
Local