JSON XML Converter: Convert Between JSON and XML
Bidirectional JSON ↔ XML mapping in this browser. Attributes use an @ prefix, arrays become repeated elements, and mixed content is flattened into #text. This is a converter, not a schema checker: output is not XSD-valid just because it is well-formed. Document type declarations and external entities are refused so nothing is fetched. Nothing is uploaded.
Root and item names must be XML 1.0 Names. The wrapper is used when JSON is an array, a primitive, or a multi-key object. Named arrays repeat the key; a root array uses the item name.
Drop a .json, .xml, or .txt file here. Client-only FileReader, UTF-8.
Output is a mapping, not a canonical or schema-valid document.
Mapping notes
How the mapping works
There is no standard bijection between RFC 8259 JSON and W3C XML 1.0. This page uses one explicit convention so both directions stay predictable. It does not invent BadgerFish, Parker, or SOAP encodings, and it does not claim the result is valid against an XSD.
| JSON | XML | Honest limit |
|---|---|---|
| {"@id":"a"} | attribute named id with value a | Attribute values must be primitives. Objects and arrays cannot become attributes. |
| {"#text":"hi"} | element text hi | Mixed content concatenates every text node into one #text string. Interleaving order with child elements is lost. |
| {"item":[1,2]} | repeated <item> siblings | A single sibling becomes a value, not a one-element array. Round-trip can change [x] into x. |
| null | empty element | XML has no null. With type inference, an empty element reads back as null; otherwise it is "". |
| [1,2] or multi-key object | wrapped in the Root element | XML 1.0 allows exactly one document element. A wrapper is required when JSON has no single usable root key. |
Privacy, DTD, and XXE
- JSON is parsed with JSON.parse (RFC 8259 / ECMA-404). XML is parsed with DOMParser and application/xml.
- A document type declaration is refused before parse. External subsets, SYSTEM / PUBLIC identifiers, and entity declarations are never fetched. That blocks classic XXE on this page.
- Well-formed is not valid. No XSD, DTD, Relax NG, or Schematron check is performed.
- Comments and processing instructions are dropped. CDATA is treated as text. Namespace prefixes are kept as part of the name; URIs are not resolved.
- Illegal JSON keys are rewritten to XML 1.0 Names. The rewrite is listed in Mapping notes.
- Input is capped at 1.5 MB, about 40,000 nodes, and 256 levels of nesting.
- There is no network call for conversion and no persistent client storage.