XML Formatter & Validator
Pretty-print XML and catch a mismatched or unclosed tag, without ever expanding a DOCTYPE.
Paste XML on the left.
How it works
Checks well-formedness — every tag closes, closes in the right order, there is exactly one root element, attribute
values are quoted and not repeated, every & starts a valid reference, comments and CDATA sections
are terminated — and pretty-prints the result with two-space indentation per nesting level. The first error is
reported with its line and column.
Parsed as text, never as a document
This does not use the browser's XML parser. A small tokenizer reads the input as a string and the output is written back as plain text, so nothing you paste is ever loaded, rendered or executed by this page.
DOCTYPE is refused, not parsed
A DOCTYPE declaration can define external entities, which is the mechanism behind XXE (XML External Entity)
injection — a crafted entity that reads a local file or triggers a request when a real parser expands it. The same
declaration is where the "billion laughs" bomb lives: ten entities that each expand to ten of the previous one
reach a billion copies from a few hundred bytes. This tool exists to let you inspect untrusted XML safely, so it
refuses any document with a DOCTYPE outright rather than trying to parse one without expanding anything. Without a
DOCTYPE, only the five predefined references (<, >,&,
', ") and numeric references exist, so anything else, such as
, is reported as undefined.
Example
Well-formedness is not the same as validity against a specific format — this checks that
<a><b></a></b> is malformed (mismatched close order), but it has no opinion
on whether a document matches a particular RSS, SOAP or config-file schema.
Frequently asked questions
Why does it reject my document just because it has a DOCTYPE?
A DOCTYPE can declare external entities, which is the mechanism behind XXE injection — a crafted entity definition that reads a local file or triggers a server-side request when the parser expands it. This tool exists to let you inspect untrusted XML safely, and refusing a DOCTYPE entirely is simpler and safer than trying to parse one without expanding external entities.
Does this tell me if my XML matches a specific schema?
No — that needs an XSD or DTD for the specific format in question (an RSS feed, a SOAP envelope, a config file). This checks only that the document is well-formed XML: every tag closes, attributes are quoted, nesting is consistent.
Related tools
SAML Response Decoder
Decode a SAMLResponse and read its issuer, subject, conditions and attributes.
LocalJSON Formatter & Validator
Format, validate and measure JSON, with errors located by line and column.
LocalYAML to JSON Converter
Convert YAML to JSON and back, with what the conversion costs stated rather than dropped.
LocalUnicode Inspector
See the real code points, UTF-8 bytes and normalization forms behind any pasted text.
LocalBase64 Decoder
Decode Base64 and Base64URL back to text or raw bytes.
LocalBase64 Encoder
Encode text or bytes to Base64 or Base64URL.
Local