DEV Community

Koh Yee Huei
Koh Yee Huei

Posted on AI-assisted

I built a JSON formatter that never uploads your data

Every developer I know pastes things into online formatters. An API response that came back as one long line. A Kubernetes YAML file that won't parse. A SQL query someone wrote in a single breath. A JWT you need to peek inside.

It's such a reflexive habit that we rarely ask where that text goes.

In November 2025, security researchers found more than 80,000 saved pastes from two of the most popular formatter sites, publicly reachable, and full of what you'd expect people to paste into a formatter: credentials, cloud keys, private keys, internal configuration. Nobody meant to publish them. They just wanted their JSON indented.

That's why I built PasteKit: a formatter, validator and converter where your input never leaves your browser.

"Runs in the browser" should be checkable, not a promise

Lots of tools say "we don't store your data". I wanted something you can verify:

  • All processing happens client-side, in a Web Worker. There is no server endpoint that receives your input.
  • A strict Content Security Policy is sent with every page, and it only allows network requests back to the site itself (plus the ad and analytics hosts listed on the security page, which never receive the editor contents). The browser itself enforces it. You can read the policy at pastekit.dev/security and check it in DevTools.
  • Share links put the content after the #. Browsers never send the fragment to a server, so a share link doesn't upload anything either.
  • It works offline after the first visit. Turn off your Wi-Fi and keep formatting.

Real formatters, not regex tricks

The formatters are the same ones you run locally, compiled to WebAssembly where needed: Prettier, Ruff (Black-style Python), gofmt, rustfmt, clang-format, sql-formatter, taplo and others. JSON is handled by a lossless parser, so big numbers keep every digit (12345678901234567890 stays exactly that) and duplicate keys are reported instead of silently dropped.

When something is wrong, you get the line and column and a plain-English explanation, for example why YAML 1.1 tools read country: NO as false (the "Norway problem").

What's in it

  • 58 formats: JSON, JSON5, NDJSON, YAML, TOML, XML, CSV, SQL dialects, HTML, CSS, JS/TS, Python, Go, Rust, Java, GraphQL, Markdown, Dockerfile, nginx…
  • 48 converters: JSON ⇄ YAML / CSV / XML / TOML / Excel, JSON → TypeScript types, and more
  • JSON tools: diff, JSON Patch, schema validation, repair (for that almost-JSON an LLM gave you), JSONPath/jq path finder, tree and table views, size analyzer, token counter
  • JWT decoder and encoder, validators and minifiers for every format

It's free, there's no sign-up, and it's available in 9 languages.

Try it

Paste anything at pastekit.dev: it detects the format for you. I'd love feedback, especially on formats or tools you wish it had. What's the worst thing you've ever caught yourself pasting into an online formatter?

Top comments (0)