<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Koh Yee Huei</title>
    <description>The latest articles on DEV Community by Koh Yee Huei (@yeehuei).</description>
    <link>https://dev.to/yeehuei</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4171483%2F5c63fe53-162a-458a-828f-c59beda8b228.jpg</url>
      <title>DEV Community: Koh Yee Huei</title>
      <link>https://dev.to/yeehuei</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/yeehuei"/>
    <language>en</language>
    <item>
      <title>I built a JSON formatter that never uploads your data</title>
      <dc:creator>Koh Yee Huei</dc:creator>
      <pubDate>Thu, 08 Oct 2026 14:02:16 +0000</pubDate>
      <link>https://dev.to/yeehuei/i-built-a-json-formatter-that-never-uploads-your-data-4mbl</link>
      <guid>https://dev.to/yeehuei/i-built-a-json-formatter-that-never-uploads-your-data-4mbl</guid>
      <description>&lt;p&gt;Every developer I know pastes things into online formatters. An API response that came back as one long line. A Kubernetes YAML file that won't parse. A SQL query someone wrote in a single breath. A JWT you need to peek inside.&lt;/p&gt;

&lt;p&gt;It's such a reflexive habit that we rarely ask where that text goes.&lt;/p&gt;

&lt;p&gt;In November 2025, security researchers found more than 80,000 saved pastes from two of the most popular formatter sites, publicly reachable, and full of what you'd expect people to paste into a formatter: credentials, cloud keys, private keys, internal configuration. Nobody meant to publish them. They just wanted their JSON indented.&lt;/p&gt;

&lt;p&gt;That's why I built &lt;strong&gt;&lt;a href="https://pastekit.dev" rel="noopener noreferrer"&gt;PasteKit&lt;/a&gt;&lt;/strong&gt;: a formatter, validator and converter where your input never leaves your browser.&lt;/p&gt;

&lt;h3&gt;
  
  
  "Runs in the browser" should be checkable, not a promise
&lt;/h3&gt;

&lt;p&gt;Lots of tools say "we don't store your data". I wanted something you can verify:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;All processing happens client-side&lt;/strong&gt;, in a Web Worker. There is no server endpoint that receives your input.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A strict Content Security Policy&lt;/strong&gt; is sent with every page, and it only allows network requests back to the site itself (plus the ad and analytics hosts listed on the security page, which never receive the editor contents). The browser itself enforces it. You can read the policy at &lt;a href="https://pastekit.dev/security" rel="noopener noreferrer"&gt;pastekit.dev/security&lt;/a&gt; and check it in DevTools.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Share links put the content after the &lt;code&gt;#&lt;/code&gt;&lt;/strong&gt;. Browsers never send the fragment to a server, so a share link doesn't upload anything either.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It works offline&lt;/strong&gt; after the first visit. Turn off your Wi-Fi and keep formatting.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Real formatters, not regex tricks
&lt;/h3&gt;

&lt;p&gt;The formatters are the same ones you run locally, compiled to WebAssembly where needed: Prettier, Ruff (Black-style Python), gofmt, rustfmt, clang-format, sql-formatter, taplo and others. JSON is handled by a lossless parser, so big numbers keep every digit (&lt;code&gt;12345678901234567890&lt;/code&gt; stays exactly that) and duplicate keys are reported instead of silently dropped.&lt;/p&gt;

&lt;p&gt;When something is wrong, you get the line and column and a plain-English explanation, for example why YAML 1.1 tools read &lt;code&gt;country: NO&lt;/code&gt; as &lt;code&gt;false&lt;/code&gt; (the "Norway problem").&lt;/p&gt;

&lt;h3&gt;
  
  
  What's in it
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;58 formats&lt;/strong&gt;: JSON, JSON5, NDJSON, YAML, TOML, XML, CSV, SQL dialects, HTML, CSS, JS/TS, Python, Go, Rust, Java, GraphQL, Markdown, Dockerfile, nginx…&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;48 converters&lt;/strong&gt;: JSON ⇄ YAML / CSV / XML / TOML / Excel, JSON → TypeScript types, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;JSON tools&lt;/strong&gt;: diff, JSON Patch, schema validation, repair (for that almost-JSON an LLM gave you), JSONPath/jq path finder, tree and table views, size analyzer, token counter&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;JWT&lt;/strong&gt; decoder and encoder, validators and minifiers for every format&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It's free, there's no sign-up, and it's available in 9 languages.&lt;/p&gt;

&lt;h3&gt;
  
  
  Try it
&lt;/h3&gt;

&lt;p&gt;Paste anything at &lt;strong&gt;&lt;a href="https://pastekit.dev" rel="noopener noreferrer"&gt;pastekit.dev&lt;/a&gt;&lt;/strong&gt;: it detects the format for you. I'd love feedback, especially on formats or tools you wish it had. What's the worst thing you've ever caught yourself pasting into an online formatter?&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>json</category>
      <category>privacy</category>
      <category>showdev</category>
    </item>
  </channel>
</rss>
