DEV Community

Chhatrapal Singh
Chhatrapal Singh

Posted on

Stop pasting API responses into random JSON formatters

Every day, developers paste production API responses, JWTs and config files into online JSON formatters. It's so routine that we rarely ask: where does that data go?

What many online tools do

Many popular formatters send your input to their server to process it. That means your JSON — customer records, emails, internal IDs, sometimes API keys — ends up in someone else's request logs.

You can check this yourself: open DevTools → Network, paste some JSON into a formatter, and watch for a POST request carrying your data.

JSON.parse silently changes your numbers

There's a second, subtler problem. Most browser-based formatters use JSON.parse, which converts numbers to JavaScript doubles:

JSON.parse('{"id": 9007199254740993}')
// → { id: 9007199254740992 }  ← off by one!

JSON.stringify(JSON.parse('{"price": 1.0}'))
// → {"price":1}               ← "1.0" became "1"
Enter fullscreen mode Exit fullscreen mode

If your IDs are 64-bit integers (Twitter/X IDs, database keys, Snowflake IDs), a formatter built on JSON.parse can show you a different number than the one your API actually sent.

What a safe formatter should do

  1. Process everything locally. No server round-trip at all.
  2. Keep numbers exact. Use a parser that preserves the original text of each number.
  3. Explain errors precisely. "Unexpected token" isn't enough — show the line, column and how to fix it.

What I built

I built JSON Formatter Kit with these rules in mind:

  • Everything runs in your browser — the site is static files, so there's no backend that could receive your data, and it works offline
  • A custom lossless parser, so 9007199254740993 and 1.0 stay exactly as written
  • Errors with line/column, a plain-English hint and one-click repair (trailing commas, single quotes, comments…)

It grew into 482 tools — converters, class generators, code formatters, hash generators, a JWT decoder and more — all following the same privacy rule.

Quick checklist for any online tool

  • Open DevTools → Network before pasting anything sensitive
  • Prefer tools that work offline (a good sign they don't need a server)
  • Never paste production secrets into a tool you can't verify

What tools do you trust with sensitive data? I'd love to hear in the comments.

Top comments (0)