JSON XML Converter: Convert Between JSON and XML

Bidirectional JSON ↔ XML mapping in this browser. Attributes use an @ prefix, arrays become repeated elements, and mixed content is flattened into #text. This is a converter, not a schema checker: output is not XSD-valid just because it is well-formed. Document type declarations and external entities are refused so nothing is fetched. Nothing is uploaded.

Conversion options

Root and item names must be XML 1.0 Names. The wrapper is used when JSON is an array, a primitive, or a multi-key object. Named arrays repeat the key; a root array uses the item name.

Load file

Drop a .json, .xml, or .txt file here. Client-only FileReader, UTF-8.

Output is a mapping, not a canonical or schema-valid document.

Paste JSON or XML and choose a direction. Results stay in this browser.

How the mapping works

There is no standard bijection between RFC 8259 JSON and W3C XML 1.0. This page uses one explicit convention so both directions stay predictable. It does not invent BadgerFish, Parker, or SOAP encodings, and it does not claim the result is valid against an XSD.

JSON XML Honest limit
{"@id":"a"} attribute named id with value a Attribute values must be primitives. Objects and arrays cannot become attributes.
{"#text":"hi"} element text hi Mixed content concatenates every text node into one #text string. Interleaving order with child elements is lost.
{"item":[1,2]} repeated <item> siblings A single sibling becomes a value, not a one-element array. Round-trip can change [x] into x.
null empty element XML has no null. With type inference, an empty element reads back as null; otherwise it is "".
[1,2] or multi-key object wrapped in the Root element XML 1.0 allows exactly one document element. A wrapper is required when JSON has no single usable root key.

Privacy, DTD, and XXE

  • JSON is parsed with JSON.parse (RFC 8259 / ECMA-404). XML is parsed with DOMParser and application/xml.
  • A document type declaration is refused before parse. External subsets, SYSTEM / PUBLIC identifiers, and entity declarations are never fetched. That blocks classic XXE on this page.
  • Well-formed is not valid. No XSD, DTD, Relax NG, or Schematron check is performed.
  • Comments and processing instructions are dropped. CDATA is treated as text. Namespace prefixes are kept as part of the name; URIs are not resolved.
  • Illegal JSON keys are rewritten to XML 1.0 Names. The rewrite is listed in Mapping notes.
  • Input is capped at 1.5 MB, about 40,000 nodes, and 256 levels of nesting.
  • There is no network call for conversion and no persistent client storage.