Every day, developers paste production API responses, JWTs and config files into online JSON formatters. It's so routine that we rarely ask: where does that data go?
What many online tools do
Many popular formatters send your input to their server to process it. That means your JSON — customer records, emails, internal IDs, sometimes API keys — ends up in someone else's request logs.
You can check this yourself: open DevTools → Network, paste some JSON into a formatter, and watch for a POST request carrying your data.
JSON.parse silently changes your numbers
There's a second, subtler problem. Most browser-based formatters use JSON.parse, which converts numbers to JavaScript doubles:
JSON.parse('{"id": 9007199254740993}')
// → { id: 9007199254740992 } ← off by one!
JSON.stringify(JSON.parse('{"price": 1.0}'))
// → {"price":1} ← "1.0" became "1"
If your IDs are 64-bit integers (Twitter/X IDs, database keys, Snowflake IDs), a formatter built on JSON.parse can show you a different number than the one your API actually sent.
What a safe formatter should do
- Process everything locally. No server round-trip at all.
- Keep numbers exact. Use a parser that preserves the original text of each number.
- Explain errors precisely. "Unexpected token" isn't enough — show the line, column and how to fix it.
What I built
I built JSON Formatter Kit with these rules in mind:
- Everything runs in your browser — the site is static files, so there's no backend that could receive your data, and it works offline
- A custom lossless parser, so
9007199254740993and1.0stay exactly as written - Errors with line/column, a plain-English hint and one-click repair (trailing commas, single quotes, comments…)
It grew into 482 tools — converters, class generators, code formatters, hash generators, a JWT decoder and more — all following the same privacy rule.
Quick checklist for any online tool
- Open DevTools → Network before pasting anything sensitive
- Prefer tools that work offline (a good sign they don't need a server)
- Never paste production secrets into a tool you can't verify
What tools do you trust with sensitive data? I'd love to hear in the comments.
Top comments (0)