[Developer Tools]•6 min read
Five Reasons JSON Fails to Parse, and the Large-Number Trap
1. JSON is stricter than it looks
JSON resembles a JavaScript object literal but permits far less. It is defined by RFC 8259 and ECMA-404, and plenty of things valid in JavaScript are invalid in JSON.
2. Five reasons parsing fails
① Trailing comma
{"a": 1, "b": 2,} — a comma after the final member is an error. JavaScript allows it; JSON does not.② Unquoted keys
{a: 1} — keys must be double-quoted strings.③ Single quotes
{'a': 'b'} — JSON recognises double quotes only.④ Comments
Neither
// note nor /* */ exists in standard JSON. Configuration files that need comments must use an extension such as JSONC or JSON5.⑤ Special values
NaN, Infinity, and undefined are not JSON. Represent a missing number as null or as a string.A further common error is a raw newline inside a string; it must be escaped as
\n.3. Reading the error position
Parsers usually report something like "position 42", but the real cause is often earlier. A single missing quote makes the parser swallow the rest of the document as part of a string until it fails much later.
Running the document through a formatter to expand the structure makes the mismatched nesting easy to spot.
4. The large-number trap
This is not a syntax error but a silent value change, which makes it more dangerous.
JavaScript numbers are double-precision floats, so integers are exactly representable only up to:
Number.MAX_SAFE_INTEGER = 9007199254740991Parsing a larger integer with
JSON.parse silently alters it. For example 12345678901234567890 becomes 12345678901234567000, with no error and no warning.When this bites
The fix
The standard remedy is for the server to serialise such values as strings:
{"id": "12345678901234567890"}. If the client must treat them as numbers, use BigInt with a custom reviver.5. JSON variants
| Format | Difference | Used for |
|---|---|---|
| JSON | The standard | API responses, data interchange |
| JSONC | Comments allowed | VS Code settings and similar |
| JSON5 | Comments, trailing commas, single quotes | Hand-written config files |
| NDJSON / JSON Lines | One JSON value per line | Logs, streaming, bulk processing |
Do not return JSONC from an API just because it works in a config file; standard parsers will reject it.
6. A security note
Code that runs a JSON string through
eval() still turns up occasionally. Never do this. Untrusted input containing code executes as code. JSON.parse is safe.7. Tool
The EVEDAYS JSON Formatter validates and pretty-prints inside your browser. API responses frequently contain personal data or tokens, so a tool that never transmits them is the safer choice.