In November 2025, researchers at watchTowr Labs published findings about two popular online formatters — JSONFormatter and CodeBeautify. According to that research, users who used those sites' Save features left shareable copies of their pastes on the services' servers. Both sites also exposed a "Recent Links" page that listed saved items.
watchTowr reported collecting 80,000+ saved JSON submissions — about five years of JSONFormatter history and one year of CodeBeautify data, described as 5GB+ of enriched content. After parsing that dataset, they said it included credentials, keys, configuration data, and personally identifiable information. They also planted canary credentials and later observed those canaries being tested, writing that someone else was already scraping the same sources.
That research is nearly a year old. Site features and exposure can change. This article does not claim either named site leaks data today. It explains the pattern watchTowr described, how to check any tool yourself, and how Tool Reign's JSON tools behave in our own code.
Why "Save" and "Share link" change the risk
Formatting JSON in the browser can stay local. The risk rises when a tool offers Save or a shareable link that stores your paste on a server. According to watchTowr, those shareable URLs followed predictable patterns, and Recent Links pages made saved entries browsable. Once text sits on someone else's server behind a guessable or listable URL, anyone who finds the link can read it — including automated scrapers.
The lesson is general: if a button uploads or persists your paste for later retrieval, treat that paste as public unless you have strong evidence otherwise.
How to check whether a tool sends your data
You can verify any site in a few minutes. Use harmless test data only — never real secrets.
- Open the tool in a private/incognito window.
- Open DevTools → Network. Enable Preserve log. Filter by Fetch/XHR.
- Paste a unique, harmless string (for example a fake key you invent for this test).
- Click Format, Beautify, Save, Share, or whatever actions the page offers.
- Inspect each request. Look for your test string in the request URL, query string, or request payload. If it appears, that action sent your paste somewhere.
A client-only formatter typically shows no Fetch/XHR that carries your paste when you format or view it. A Save/Share feature that stores content remotely usually posts your text (or an identifier that resolves to it) to an API. Results vary by site and by button — always re-check after UI changes.
Never paste real secrets into any online tool. If you already did, rotate those credentials and keys.
Safer habits
- Strip tokens, passwords, and PII before pasting sample JSON.
- Prefer editors and formatters that work offline or only in your browser.
- Treat every Save / Share / Permalink control as a potential upload until Network proves otherwise.
- For API debugging, send only redacted payloads.
What Tool Reign does
What you type, paste, or upload is never sent to our servers.
Our JSON Formatter (including Graph view) formats and renders in your browser, including a local Web Worker for larger documents. Share copies a URL with state in the hash fragment — it is not uploaded to Tool Reign. Draft preferences can stay in your browser's localStorage. You can confirm with the DevTools method above: formatting should not create Fetch/XHR requests that contain your paste.
The API Client is different by design: Direct mode calls the URL you enter from your browser; optional Proxy mode relays the request through a disclosed Tool Reign proxy so you can reach APIs that block browser CORS. That proxy logs only metadata (request id, status class, error code, duration) — never URLs, headers, or bodies. Analytics (GA4 and Clarity) load only after you Accept cookies; tool events carry slugs and similar metadata, not paste contents.
Do not take our word for it — run the Network check on JSON Formatter and the API Client yourself.
Related tools
- JSON Formatter & Validator — format, repair, tree/table/graph
- JSON graph view — interactive node graph inside the formatter
- API Client — Direct or disclosed Proxy mode
Top comments (1)
the devtools check is the best part. "trust us, it runs locally" becomes something anyone can verify in five minutes. most privacy claims live in marketing pages. this one lives in a network tab.
reminds me of the dns_failed fix on your other post. same instinct: keep the sensitive thing out of the request in the first place.