XML ↔ JSON Converter
Two-way XML ⇄ JSON with control over attributes, arrays and namespaces — XXE-safe.
Converted as you type. You can also drop a file here — it is read on your device; nothing is uploaded or fetched.
About the XML ↔ JSON Converter
Turn an XML document — a SOAP or REST response, an RSS feed, a sitemap, a config or a data export — into JSON, or build XML from JSON. The mapping is the one most libraries use: attributes become members with an @ prefix, repeated elements become arrays, an element that only holds text becomes a string, and text next to attributes or child elements goes into #text. Every part of it is a setting, including CDATA handling, namespace prefixes and which elements must always be arrays.
The XML is checked as it is read: errors show the line and column and how to fix them ("Closing tag </itm> does not match <item>…"). Nothing is ever fetched — external DTDs and external entities are never loaded, which also protects you from XXE attacks, and documents whose entities expand without limit are refused.
How to use it
- Choose XML → JSON or JSON → XML, then paste your data, open a file or press Load sample. The result updates as you type.
- For JSON output, set the attribute prefix (default
@), the text key (default#text), and whether CDATA is merged into the text. Tick Remove namespace prefixes to turnsoap:BodyintoBody. - List elements that must always be arrays under Always arrays — a name such as
itemor a path from the root such ascatalog.book— so that one-item lists keep the same shape. - For XML output, choose the root element name for JSON that has no single root, the indentation, and whether to write the
<?xml ?>declaration. - Copy or download the result, or press Use as input to convert it back.
Examples
<order id="A-1"><item sku="X">Pen</item><item sku="Y">Ink</item></order>
{"order":{"@id":"A-1","item":[{"@sku":"X","#text":"Pen"},{"@sku":"Y","#text":"Ink"}]}}Shown minified.
<catalog><book>Cosmos</book></catalog>
{"catalog":{"book":["Cosmos"]}}With Always arrays set to book. Without the setting, a single <book> becomes a string and two become an array — code that reads the JSON would have to handle both.
{"user": {"@id": 7, "name": "Asha", "roles": ["admin", "editor"]}}<user id="7"> <name>Asha</name> <roles>admin</roles> <roles>editor</roles> </user>
Array items become repeated elements with the array's name.
Common uses
- Reading SOAP, payment-gateway or government API responses in JavaScript, Python or
jq. - Turning RSS/Atom feeds, sitemaps and XML exports into JSON for scripts and spreadsheets.
- Building XML request bodies or config files from JSON data.
- Checking that an XML document is well-formed before sending it to another system.
How XML maps to JSON
- An element with only text becomes a string:
<name>Asha</name>→"name": "Asha". - Attributes become members with the prefix:
<price currency="INR">299</price>→"price": {"@currency": "INR", "#text": 299}. - An element that occurs more than once in the same parent becomes an array, in document order.
- An empty element
<flag/>becomes""(ornullif you choose). - With Convert numbers and true/false, text and attribute values that are valid JSON numbers (
42,-1.5,2e3) or exactlytrue/falsebecome numbers and booleans; anything else stays text, so007,+91and1,000are never changed. Numbers keep every digit. - Comments are dropped unless you keep them; the XML declaration, processing instructions and the DOCTYPE are not part of the JSON.
- Namespace prefixes are kept (
"soap:Body") unless you remove them, which also drops thexmlnsattributes.
Security: XXE and entity bombs
XML can declare entities that refer to files or URLs — <!ENTITY xxe SYSTEM "file:///etc/passwd"> — which careless parsers fetch and insert (an XXE attack). This converter never loads anything: a reference to an external entity is reported as an error, and an external DTD is ignored with a note. Internal entities declared in the document are expanded, with a limit of one million characters in total, so "billion laughs" documents are refused instead of freezing your browser.
Limitations
- Mixed content — text interleaved with elements, as in
<p>Hello <b>world</b>!</p>— keeps the elements and the text, but not where the text stood between them; the converter tells you when this happens. - Entities whose value contains markup, parameter entities and definitions in external DTDs are not expanded, and default attribute values declared with
<!ATTLIST>are not added (the converter says so). Schema validation (XSD, DTD) is not performed — only well-formedness. Spaces or blank lines before<?xml ?>, which strict XML forbids, are ignored with a note. - JSON → XML needs valid XML names: keys with spaces or starting with a digit are reported (or repaired with Fix invalid names), and text containing control characters that XML 1.0 forbids is rejected. Empty arrays have no XML form and are left out (with a note);
#commentmembers become XML comments. - Very large files (tens of megabytes) are converted in your browser and can take a few seconds.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Is my XML or JSON uploaded?
No. Parsing and conversion run in your browser, and the page works offline once loaded.
Why is a single element sometimes an object and sometimes an array?
Because XML does not say whether an element can repeat. One <item> becomes an object or string, two become an array. List the element under Always arrays (for example item or items.item) to get an array every time.
Can I avoid the @ and #text names?
Yes. Set the attribute prefix to _, $ or nothing, and the text key to any name such as value. With an empty prefix, an attribute and a child element of the same name would collide — the converter warns you if that happens.
Is this safe for XML from an unknown source?
Yes. External entities and DTDs are never fetched, entity expansion is limited, and all processing happens on your device. The converter does not run scripts, stylesheets (XSLT) or anything else inside the document.
How do I just pretty-print or validate XML?
Use the XML Formatter, which checks well-formedness and re-indents XML without converting it.