Skip to content
Tool4SaaS
HomeAboutContactBlog
Tool4SaaS

185 fast, local utilities for developers and creators. No sign-ups — most tools run in your browser (see /privacy).

hello@tool4saas.com

Categories

  • Text & Documents

  • Business & Writing

  • Developer Tools

  • Converters

  • Generators

  • Images & Design

  • PDF Tools

  • Calculators

  • Finance & Money

  • Health & Fitness

  • SEO & Marketing

  • Time & Date

Popular Tools

  • Invoice Generator

  • QR Code Generator

  • Word Counter

  • Password Generator

  • JSON Formatter

  • Mortgage Calculator

  • EMI Calculator

  • SIP Calculator

  • View all tools →

Company

  • All Tools

  • About Us

  • Author

  • Methodology

  • Blog

  • Contact Us

Guides

  • Invoice Generator Guide

  • QR Code Generator Guide

  • Resume Builder Guide

  • Mortgage Calculator Guide

  • Password Generator Guide

  • Word Counter Guide

  • llms.txt (for AI)

© 2026 Tool4SaaS. All rights reserved.

  • Privacy Policy

  • ·
  • Terms of Service

  • ·
  • ·
  1. Home
  2. /
  3. Blog
  4. /
  5. Debug API Responses Locally: JSON, Base64, JWT, Regex Guide

Debug API Responses Locally: JSON, Base64, JWT, Regex Guide

Debug APIs without uploading secrets: JSON errors at line:col, Base64 modes, SHA-256 vs MD5, UUID seeding, regex flags, JWT expiry + URL encoding. Free tools.

By Tool4SaaS Editorial Team · Published 2026-10-07 · Updated 2026-10-07 · 6 min read

Try it now — JSON Formatter, free in your browser

Format, validate & minify JSON · No signup · No watermark · Free forever.

Open JSON Formatter →
On this page
  • Local-first loop
  • JSON.parse failures
  • Base64 modes
  • SHA-256 vs MD5
  • UUID seeding
  • Regex flags + groups
  • JWT expiry
  • URL encoding
  • Limits

A production API returned a 500KB JSON error blob at 2 AM, and the on-call engineer pasted it — credentials and all — into a random online formatter. The formatting worked. So did the credential leak, into a stranger's server logs. I have seen this movie too many times: debugging with tools that upload your secrets. This guide is the alternative: format JSON, decode Base64 and JWTs, test regex, hash and mint UUIDs — everything locally, nothing uploaded, secrets stay in your tab.

Here is the promise: you will learn a local-first debugging workflow covering the seven operations developers repeat daily, with exact behaviors (trailing commas, padding, exp skew, bulk UUID counts) and the security boundaries that matter. I ran every example below in October 2026 against real payloads. Work alongside me starting at our free JSON formatter.

Part of the blog guides. Format in JSON formatter; decode in Base64 and JWT decoder; test in regex tester.

The local-first debugging loop (paste → inspect → fix → verify)

  1. Paste into the local tool, never a cloud box: API replies, tokens, hashes and patterns stay in your browser tab. Close the tab and they are gone — no retention policy to read.
  2. Let the tool point at line:column: a missing comma at 1:18 beats staring at 10,000 lines. Fix, re-paste, confirm green.
  3. Decode one layer at a time: JWT → Base64 segments → JSON claims. Each layer gets its own tool and its own verification.
  4. Verify, don't trust: decoding is not verifying — a decoded signature proves nothing. Expiry, audience and algorithm checks are separate steps below.

Why JSON.parse fails: trailing commas, comments, single quotes

Strict JSON accepts exactly one grammar — JavaScript object literals are not it. The three killers I see weekly:

CauseExampleFix
Trailing comma{"a": 1,}Delete the comma; minifiers flag it
Comments{// note "a": 1}Strip comments (JSONC is not JSON)
Single quotes{'a': 1}Double-quote all keys and strings
Duplicate keys{"a": 1, "a": 2}Last wins silently — dedupe

Paste the payload into the JSON formatter — it pinpoints line and column, pretty-prints 500KB replies instantly, and minifies ~20% smaller for transport. Split payloads over 10MB before pasting; oversized dumps hang tabs regardless of tool. Errors guide: JSON.parse error fixes. Tree-view large responses in the JSON tree viewer, and convert configs with the JSON to YAML tool.

Base64 standard vs URL-safe: padding, +/ vs -_

Standard Base64 (A–Z a–z 0–9 + / with = padding) breaks in URLs — + becomes a space, / splits paths. URL-safe mode swaps +/ for -_ and drops padding. Rule: standard for MIME/email/data-URLs, URL-safe for tokens, query params and filenames. Costs to remember: ~33% size overhead, UTF-8 emoji encode as 4 bytes first (café → Y2Fmw6k=), and 76-char mail wrapping is a transport concern, not storage. JWT segments are Base64URL without padding by spec — decode them in the Base64 tool, then inspect claims in the JWT decoder. Modes: URL-safe vs standard.

SHA-256 vs MD5: digest lengths and when legacy is acceptable

hello → SHA-256 2cf24dba… (64 hex chars), MD5 5d41402a… (32). Lengths identify algorithms at a glance: 40 SHA-1, 64 SHA-256, 128 SHA-512. Use SHA-256 for integrity checks and fingerprints; MD5 only for legacy manifest compatibility — never for passwords (use bcrypt/argon2 server-side). Flip one letter (hallo) and the avalanche effect rewrites the whole digest. Compare side by side in the hash generator, step up to keyed HMAC in the HMAC tool, and encrypt (not just hash) secrets with the AES encryptor. Guide: hash comparison.

Seeding test DBs: how many UUIDs without collisions

v4 UUIDs carry 122 random bits — you can mint millions per second for fixtures with effectively zero collision risk (birthday math needs ~2.7 quintillion for 50% odds). Practical flow: generate 10,000 in bulk, bulk-copy into seed scripts, dedupe on insert as belt-and-braces. Prefer UUIDs over auto-increment IDs in test data to avoid order-dependent flakes; prefer random-string only for human-readable codes, never for unguessable tokens. Bulk mint in the UUID generator. Seeding guide: UUID seeding.

Regex flags g/i/m/s and capture groups that actually capture

Two thirds of regex pain is flags, not patterns. g finds all matches (d+ pulls 42 from “Order 42”), i ignores case, m makes ^/$ per-line for 4000-line logs, s lets . cross newlines. Named groups ((?<year>d{4})-(?<month>d{2})) beat numbered ones for 2024-05-01 extraction; non-capturing (?:…) keeps indexes stable. Greedy .* backtracks catastrophically on large inputs — prefer lazy .*? or explicit classes. Our regex tester highlights matches with per-flag control and runs catastrophic patterns in a worker with timeouts instead of freezing your tab. Flags lab: capture groups guide.

JWT expiry without trust: exp, skew and alg:none

Decoding shows claims; verification proves them — do both, in that order. Check exp against now (allow ~30s clock skew, sync NTP), confirm aud is your service and iss your IdP, and reject alg:none unconditionally — unsigned tokens must never authorize. exp: 1717252800 two hours past means expired, full stop, regardless of a valid-looking signature from the wrong key. Paste into the JWT decoder (redact emails before screenshotting), convert timestamps in the timestamp converter. Expiry guide: JWT checks.

Why café becomes caf%C3%A9 (and spaces become %20)

URLs allow a small ASCII set; everything else percent-encodes as UTF-8 bytes — é is two bytes, hence %C3%A9. Spaces encode as %20 in paths but + in form bodies (application/x-www-form-urlencoded) — the #1 encoding bug I review. Encode &, = and # inside values or they split your query; never double-encode (%2520). URLs over ~2000 chars risk proxy truncation — POST the payload instead. Encode and parse safely with the URL encoder and URL parser. Encoding guide: URL encoding.

Try it now: paste a broken API reply into the free JSON formatter — line errors, offline, nothing uploads and fix it in seconds.

Limits and honest notes

Local tools inspect; they do not execute. Decoded JWTs are unverified until your backend checks signatures against the IdP keys. Hash comparisons catch corruption, not malice without a trusted channel. Regex testers validate patterns, not intent — a matching pattern can still be the wrong pattern. And no formatter fixes a 500 status: client-side validation narrows the suspect list, server logs close the case.

General guidance only. Never paste production secrets into any web tool you have not audited — ours runs locally, but verify in DevTools Network tab.

Related free tools

Base64 Encode / Decode →JWT Decoder →Regex Tester →

Frequently asked questions

Paste the payload into a local formatter for line:column errors — a missing comma at 1:18 beats staring at 10,000 lines. Fix trailing commas, quotes and comments, decode nested Base64/JWT layers one at a time, and verify token expiry and audience separately.

For tokens, query params, filenames and slugs, where it uses -_ without padding. Standard Base64 (+/ with =) belongs in MIME, email and data URLs. Mixing modes across a boundary is the classic midnight outage — standardize per side.

Only for legacy checksum compatibility, never for passwords or security. Use SHA-256 for integrity fingerprints, keyed HMAC for origin proof, and slow bcrypt/argon2 for password storage server-side.

No. Decoding displays claims; your backend must verify the signature against IdP keys plus exp, aud and algorithm checks on every request. Reject alg:none unconditionally — unsigned tokens authorize nothing.

Catastrophic backtracking: nested quantifiers like (a+)+$ explode exponentially on non-matches. Prefer lazy quantifiers and explicit classes, anchor patterns, and test in runners that isolate execution in workers with timeouts.

Not with local tools: everything runs in your tab and vanishes on close, with no retention policy to read. Verify any web tool yourself in DevTools Network — ours fires zero requests, even with Wi-Fi off after load.

Done reading — open the JSON Formatter

Format, validate & minify JSON — free in your browser, no signup.

Open JSON Formatter →

Keep reading in this guide

In this silo

Why JSON.parse Fails: Trailing Commas and Quotes

In this silo

Base64 URL-Safe vs Standard: Padding and Modes

In this silo

Check JWT Expiry Without Trusting the Token

In this silo

SHA-256 vs MD5: When to Use Which Hash

All 7 tutorials in this silo

Each tutorial solves one job — pick yours. Every page links back here and to the free json formatter.

PART 01

Why JSON.parse Fails: Trailing Commas and Quotes

3 min read

PART 02

Base64 URL-Safe vs Standard: Padding and Modes

3 min read

PART 03

SHA-256 vs MD5: When to Use Which Hash

3 min read

PART 04

Seed Test Databases With UUIDs (No Collisions)

3 min read

PART 05

Regex Flags and Capture Groups That Work

3 min read

PART 06

Check JWT Expiry Without Trusting the Token

3 min read

PART 07

URL Encoding: Spaces, Symbols and Double-Escape Bugs

3 min read

Canonical: https://tool4saas.com/blog/json-formatter-guide · Pillar targets “how to debug api json responses locally”; clusters target one long-tail each — no cannibalization.