Glossary

XML

XML (Extensible Markup Language) is a tag-based markup format for representing structured, nested data, where every piece of content is wrapped in a named opening and closing tag. It's a W3C Recommendation, first published in 1998, and predates JSON as the dominant format for web APIs and configuration files.

How it works

An XML document is a tree of elements, each of which can have attributes and nested child elements:

<?xml version="1.0" encoding="UTF-8"?>
<book id="1">
  <title>Structure and Interpretation</title>
  <authors>
    <author>Abelson</author>
    <author>Sussman</author>
  </authors>
</book>

A document is well-formed if it follows XML's syntax rules (every tag closed, attributes quoted, a single root element); it's valid if it additionally conforms to a schema — a DTD or an XSD (XML Schema Definition) — that constrains which elements, attributes, and nesting are allowed. XML supports namespaces (xmlns) so element names from different vocabularies can mix in one document without colliding, a feature JSON has no equivalent for. XML is also the basis for several derived formats still in wide use: SVG (vector graphics), RSS/Atom (feeds), and the zipped-XML internals of .docx/.xlsx files.

Common pitfalls

  • XML is verbose — every value is wrapped in an opening and closing tag, roughly doubling the character overhead compared to JSON for the same data.
  • Parsing untrusted XML without disabling external entity resolution exposes an XXE (XML External Entity) vulnerability, letting an attacker read local files or trigger server-side requests.
  • Deciding whether a piece of data is an attribute (<book id="1">) or a child element (<book><id>1</id></book>) is a design choice XML doesn't enforce, and inconsistent APIs mix both.
  • Unlike JSON's implicit array/object distinction, XML has no native "list" type — repeated sibling elements are the convention, but nothing in the syntax marks them as a list versus separate fields.

Related terms

  • JSON — the lighter-weight format that has replaced XML for most new web APIs.
  • CSV — a flat, row-based alternative with none of XML's nesting or schema capability.
  • YAML — a whitespace-based format similarly used for configs, without XML's tag overhead.

See also

  • Tool: JSON to XML Converter — convert JSON objects and arrays to well-formed XML with configurable root and item element names.