Stop pasting production JSON into random formatter sites
A webhook fails, an API returns one enormous line, and you need to inspect it quickly. The usual reaction is to search for a JSON formatter and paste the entire payload into the first result. That is convenient, but pro
A webhook fails, an API returns one enormous line, and you need to inspect it quickly. The usual reaction is to search for a JSON formatter and paste the entire payload into the first result.
That is convenient, but production JSON often contains much more than the field you are debugging.
It may include:
- access tokens
- email addresses
- internal IDs
- session data
- customer names
- private URLs
- infrastructure details
- feature flags
The risk is not JSON formatting itself. Formatting is a local string operation. The risk is sending sensitive input to a service when the task does not require a server at all.
What a formatter actually does
A JSON formatter normally performs two operations:
- Parse the input to confirm that it is valid JSON.
- Serialize the parsed value again with indentation.
In JavaScript, the core operation is only one line:
const formatted = JSON.stringify(JSON.parse(rawJson), null, 2);
The third argument controls indentation. Use 2 for two spaces, 4 for four spaces, or "\t" for tabs.
Minifying reverses the presentation step:
const minified = JSON.stringify(JSON.parse(rawJson));
Neither operation needs a database, an account, or a remote processing service.
The production payload problem
Consider a payload like this:
{
"user": {
"id": 42,
"email": "[email protected]"
},
"access_token": "REDACTED",
"internal_api": "https://internal.example.test/v1"
}
The object is small enough to inspect, but real responses can contain hundreds of nested properties.
The fastest route to the bug is often to format the response and search for the relevant key. But before pasting it anywhere, treat the payload as potentially sensitive.
A useful rule is:
If the data came from production, assume it contains something you should not share until you have checked it.
This applies even when the visible part looks harmless. Secrets and personal data are often buried several levels deep.
Three safer ways to format JSON
1. Use your browser console
If the string is already available in a development environment, the browser console can format it:
const raw = '{"user":{"id":42,"role":"admin"},"active":true}';
console.log(JSON.stringify(JSON.parse(raw), null, 2));
This is quick and requires no extra site.
Be careful when manually wrapping a large JSON string in quotes because existing quotes and escape characters can make the JavaScript invalid. Assigning an existing response value is easier than copying it into a new string literal.
2. Use a local command-line tool
If you have jq installed:
jq . response.json
To create a compact version:
jq -c . response.json
This is ideal for files, scripts, and repeatable workflows.
3. Use a formatter that processes input in the browser
A browser-based formatter can still be convenient, especially on a machine where you do not want to install anything. The important distinction is where the input is processed.
I tested the JSON Formatter and Validator on All Tools Verse with this minified value:
{"user":{"id":42,"role":"admin"},"active":true}
It returned an indented object with two spaces. I also tested malformed input containing a trailing comma, and the page reported the parser position instead of producing output.
On this page, the formatting logic runs in the browser. That is the correct architecture for this type of task.
Validation is more useful than pretty printing
Readable indentation is helpful, but validation often saves more time.
These are common reasons a JSON document fails to parse:
- trailing commas
- single quotes instead of double quotes
- unquoted property names
- JavaScript comments
- incomplete strings
- missing closing braces or brackets
- values that JSON does not support, including NaN and Infinity
For example, this is not valid JSON:
{
"user": {
"id": 42,
}
}
The comma after 42 is legal in some JavaScript contexts, but not in JSON.
A useful validator should refuse to format malformed data and show enough location information to help you find the problem.
Formatting does not sanitize data
Pretty printing changes whitespace. It does not remove secrets.
Before sharing a formatted payload in a ticket, chat, issue, or pull request, redact fields such as:
- authorization
- access_token
- refresh_token
- api_key
- password
- cookie
- phone
- internal hostnames and IP addresses
Also check arrays and nested objects. Replacing one visible token is not enough if another copy appears deeper in the document.
For recurring workflows, automate redaction rather than relying on memory.
How to evaluate an online formatter
A privacy statement is useful, but you can also inspect behavior yourself.
Try these checks:
- Open the browser developer tools.
- Select the Network panel.
- Clear the request history.
- Paste a non-sensitive test payload.
- Format it and watch for network requests.
- Reload the page, disconnect from the network, and test again if the page supports offline operation.
These checks provide evidence about the current behavior of the page. They are not a substitute for reviewing code or organizational security requirements, but they are better than assuming every formatter works the same way.
For real secrets, the safest choice is still a trusted local workflow.
A practical team policy
Teams do not need a long document for this. A short policy is enough:
- Do not paste unreviewed production payloads into third-party services.
- Prefer local tools for formatting, validation, conversion, and diffing.
- Redact data before adding it to tickets or chat.
- Use synthetic examples in documentation.
- Rotate a credential immediately if it was exposed.
The goal is not to make debugging slower. It is to remove an unnecessary data transfer from a task that can happen locally.
The takeaway
Formatting JSON is simple. Production data handling is not.
Use the browser console, jq, your editor, or a browser-based tool whose processing model you have checked. Validate the structure, remove sensitive fields, and only then share the smallest payload needed to explain the bug.
For related workflows, see JSON and CSV Tools and the JSON Formatter and Validator.
I build All Tools Verse, a directory of 1,000+ browser-based tools. This is original DEV content, and I tested the linked formatter with both valid and invalid JSON before publishing.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.