English

Developer tools · JSON formatter & validator

Check the network tab before pasting a config file into a formatter

· Why it matters

json developer-workflow validation

Check the network tab before pasting a config file into a formatter illustrated with JSON tokens and a precise validation boundary
Original ToolAcre vector illustration

Config files and API responses are full of tokens, connection strings and personal data. This post shows how to verify in your browser's network panel whether a formatter uploads your text, and why ToolAcre's design makes that check pass.

The paste that leaks a production secret

The paste that leaks a production secret — a connection string in appsettings.json, a bearer token in a captured response, and a formatter that posts to a server. A polished interface does not reveal where processing occurs. Once the document becomes an HTTP request body, copies may exist in transport logs, diagnostics, queues or backups even if the visible result appears immediately.

The privacy claim must be precise. Formatting and validation run locally and the pasted text is not posted to a ToolAcre application server. Production pages can still fetch disclosed site assets and Google loaders under the site-wide policy, so an absolutely empty Network panel is not the test; the test is that no request carries the pasted document. Inspect payloads, not merely request count.

What a JSON document usually contains

What a JSON document usually contains — credentials, session tokens, e-mail addresses and IDs that fall under data-protection rules. Configuration also exposes internal hostnames, tenant names, storage buckets and feature flags that help map a system. An API response can combine personal records with authorization metadata, making a harmless-looking formatting task a genuine data-handling decision.

Classify the document before choosing a tool. Replace live values with representative placeholders when the syntax issue survives redaction, and preserve length or escape patterns only when they matter to reproduction. Removing one password is insufficient if a signed URL, private key, cookie or database username remains elsewhere. Search the entire candidate rather than trusting the field that first attracted attention.

How to watch a tool with the network panel

How to watch a tool with the network panel — opening developer tools, filtering requests, formatting a document and confirming nothing leaves the tab. Clear the request list after the page settles, enable preserve-log if navigation is possible, then paste a distinctive redacted marker and trigger validation, formatting, copying and any download action you intend to use.

Review Fetch/XHR, document, beacon and WebSocket activity, but do not stop at resource names. Open request bodies, query strings and headers and search for the marker or recognizable fragments. Repeat the operation once so timing is clear. Existing asset and loader traffic may continue; the relevant observation is whether an action creates a request containing all or part of the supplied JSON.

Why 'we delete it after processing' is not the same as never sending it

Why 'we delete it after processing' is not the same as never sending it — transit, logs, error reports and third-party analytics as the leak paths. Server-side processing creates a recipient and a retention question before deletion policy matters. TLS protects transport from many observers, but the endpoint still receives plaintext and may duplicate it through normal operations.

A crash reporter could capture an input excerpt, an access layer could record a query parameter, or support tooling could retain failed jobs. Deletion after a successful response does not automatically remove those derivative copies. Local processing narrows this exposure because the transformation does not require submitting the document, although browser extensions, device monitoring and other page traffic remain separate surfaces to assess.

How ToolAcre removes the question

How ToolAcre removes the question — formatting in the browser without sending the supplied document to a ToolAcre application server. The repository path parses and serializes the text in client-side JavaScript, so the operation itself has no payload-request step. That architecture can be inspected in code and tested from the browser rather than inferred from a marketing label.

Keep the claim at that boundary. Eligible production pages may fetch disclosed Google loaders and ordinary site assets, so “the page makes no requests” would be inaccurate. Content Security Policy constrains categories of connections but is not a substitute for observing behavior. The defensible result is narrower and useful: formatting or validation does not place the pasted JSON into an application request.

Worked example: verifying the JSON formatter

Worked example: verifying the JSON formatter — use `{"ConnectionStrings":{"Main":"VERIFY_MARKER"}}` rather than a live secret. Load the page, let initial resources finish, clear Network, paste the sample and run both validation and formatting. The output should become indented JSON while the marker remains visible only in the input and generated output surfaces.

Search the captured requests for `VERIFY_MARKER`, inspect any action-time entries and confirm no body, URL or header contains it. A nonempty list can still pass this test if entries are unrelated page resources or disclosed loaders. Conversely, an endpoint named “format” fails the privacy check if its request carries the marker even when the service promises immediate deletion or returns no stored identifier.

What this does not cover

What this does not cover — clipboard managers, browser extensions and screen sharing, which can expose the same text outside the page. Managed endpoint software may also record window contents or keystrokes, and browser synchronization can preserve form state depending on environment. The Network panel tests page-originated transfer; it cannot prove that the operating system has no other observer.

It also does not authorize handling restricted data in an unapproved tool. Organizational policy may require an offline editor, dedicated workstation or local command-line parser even when browser processing is technically local. Redaction remains preferable, and incident material may need a documented evidence workflow. Treat the payload-request check as one concrete privacy verification, not a universal certification of the surrounding device.

Takeaway: verify, do not trust

Takeaway: verify, do not trust — inspect what happens when the exact operation runs. Use a unique harmless marker, clear prior traffic, trigger every relevant action and examine request payloads and URLs. That procedure distinguishes client-side formatting from a remote service more reliably than a badge, privacy slogan or empty-looking interface ever can.

For ToolAcre, state the result precisely: the pasted JSON is parsed and formatted in the browser and is not included in a request to a ToolAcre application server. Do not broaden that to “nothing leaves the device,” because production pages can fetch disclosed assets and loaders. Minimize sensitive input anyway, and choose an approved offline surface when policy or threat model demands it.