Skip to main content
QUIETLYTIC
Encoding & Data

XML Formatter & Validator

Pretty-print XML and catch a mismatched or unclosed tag, without ever expanding a DOCTYPE.

Local · nothing leaves this browser Waiting for XML
Esc Clear
Formatted

Paste XML on the left.

How it works

Checks well-formedness — every tag closes, closes in the right order, there is exactly one root element, attribute values are quoted and not repeated, every & starts a valid reference, comments and CDATA sections are terminated — and pretty-prints the result with two-space indentation per nesting level. The first error is reported with its line and column.

Parsed as text, never as a document

This does not use the browser's XML parser. A small tokenizer reads the input as a string and the output is written back as plain text, so nothing you paste is ever loaded, rendered or executed by this page.

DOCTYPE is refused, not parsed

A DOCTYPE declaration can define external entities, which is the mechanism behind XXE (XML External Entity) injection — a crafted entity that reads a local file or triggers a request when a real parser expands it. The same declaration is where the "billion laughs" bomb lives: ten entities that each expand to ten of the previous one reach a billion copies from a few hundred bytes. This tool exists to let you inspect untrusted XML safely, so it refuses any document with a DOCTYPE outright rather than trying to parse one without expanding anything. Without a DOCTYPE, only the five predefined references (<, >,&, ', ") and numeric references exist, so anything else, such as  , is reported as undefined.

Example

Well-formedness is not the same as validity against a specific format — this checks that <a><b></a></b> is malformed (mismatched close order), but it has no opinion on whether a document matches a particular RSS, SOAP or config-file schema.

Frequently asked questions

Why does it reject my document just because it has a DOCTYPE?

A DOCTYPE can declare external entities, which is the mechanism behind XXE injection — a crafted entity definition that reads a local file or triggers a server-side request when the parser expands it. This tool exists to let you inspect untrusted XML safely, and refusing a DOCTYPE entirely is simpler and safer than trying to parse one without expanding external entities.

Does this tell me if my XML matches a specific schema?

No — that needs an XSD or DTD for the specific format in question (an RSS feed, a SOAP envelope, a config file). This checks only that the document is well-formed XML: every tag closes, attributes are quoted, nesting is consistent.

Related tools

From the intelligence desk