The API Wars: How a Simple Bracket Killed the Tag | ZenixTools
Published: June 2, 2026Updated: Aug 23, 202612 min readDev Tools
The API Wars: How a Simple Bracket Killed the Tag
A developer's story of the battle between JSON and XML. Discover why JSON became the king of the web and when (if ever) you should still use XML in 2026.
JSON’s minimal syntax maps directly to native language types, cutting payload size and parse time. Coupled with mobile constraints, REST’s rise, and built-in support across languages and browsers, JSON became the lowest-friction default for APIs—while XML stayed strong where document fidelity, canonicalization, and strict signatures matter.
In the early 2000s, developers lived inside angle brackets. XML ruled enterprise systems: verbose, meticulous, and verifiable, with specs for everything—schemas, namespaces, transformations, signatures.
Then came a simple idea: data could be represented with lightweight structures that looked like native programming types. JSON emerged as a minimal data interchange format centered on objects and arrays—no tags, just {} and []. Browsers parsed it fast. Developers could glance and grok.
By 2026, the winner in mainstream APIs is clear. Simplicity wins at web scale. But the story isn’t about one format replacing the other; it’s about picking the right tool for the job and knowing how to migrate without breaking trust.
XML: The Era of Strictness
XML was designed for universal structure—corporate-first and feature-rich. Its strengths made it ideal for documents, publishing, and complex, rule-heavy data flows.
What XML brings to the table:
Namespaces and schema enforcement (XSD)
Transformations (XSLT) and canonicalization (C14N)
Mixed content support (text plus markup) for documents
Digital signatures (XMLDSig) and encryption (XML-Enc)
Mature tooling in enterprise, finance, identity, and publishing
Where it can hurt for web APIs:
Verbosity: a simple hello world often needs envelopes, headers, and namespaces.
Parsing overhead: DOM/SAX pipelines, validation steps, and more ceremony.
Developer ergonomics: reading, diffing, and patching payloads takes effort.
Example contrast:
XML
<user>
<id>1</id>
<name>Zenix</name>
</user>
JSON
{"id": 1, "name": "Zenix"}
With XML, you gain descriptive power and strictness. With JSON, you gain speed and clarity for everyday API work.
JSON: The Rise of Minimalism
JSON doesn’t try to be a document language. It models data—objects, arrays, strings, numbers, booleans, null—matching how developers think in code.
Why developers flocked to JSON:
Native mapping: Built-ins in JavaScript, Python, Go, Rust, Swift, Java, C#, PHP, Ruby, and more.
Lightweight parsing: Fast to decode; fewer moving parts than a full XML stack.
Decide on time formats (RFC 3339) and money (decimal string + currency).
Choose canonical IDs; avoid semantic or auto-increment IDs if possible.
Phase 4: Security equivalence
Replace XMLDSig with JWS where appropriate; clarify non-repudiation requirements.
Migrate WS-Security authZ to OAuth 2.0/OIDC with scopes; pin TLS/mTLS posture.
Reassess threat models; re-run pentests.
Phase 5: Testing and shadow traffic
Contract tests from OpenAPI; sample payloads from prod traffic.
Golden test data and idempotent replays; ensure invariants across systems.
Shadow requests through both stacks; compare responses with tolerance.
Phase 6: Gradual rollout
Canary by endpoint, then by tenant; use feature flags.
Monitor P50/P90/P99 latency, error rates, and payload sizes.
Communicate deprecations with timelines and migration guides.
Phase 7: Decommission
Freeze SOAP endpoints; keep adapters read-only if audits require.
Archive schemas, WSDLs, and mappings; document lessons learned.
Anti-break checklist
Preserve business IDs and error codes.
Keep pagination semantics equivalent or clearly documented.
Provide SDKs and sample clients; publish a test sandbox.
Offer a bulk migration endpoint or export for large data movers.
Common Pitfalls and How to Avoid Them
Silent type changes
Don’t change a string to a number in-place; add a new field and deprecate the old.
Big integer loss in JavaScript
Transmit as strings or use libraries that support BigInt; validate ranges.
Timezone and DST bugs
Store UTC; transmit RFC 3339 with Z; never rely on client local time.
Over-nesting and bloated payloads
Normalize relationships; use includes/expansions with explicit field masks.
Binary-in-JSON bloat
Use presigned URLs; deliver media via CDN with integrity metadata.
Unbounded queries
Cap page size; enforce server-side max limits and timeouts; add rate limits.
Leaky error messages
Provide stable error catalogs; avoid stack traces; use correlation IDs.
Schema drift
Lock schemas; validate at ingress/egress; fail fast; run schema diff checks in CI.
XML entity attacks
Disable DTDs/XXE in every parser; unit-test parser configs.
Mini Scenario: A Safer, Faster Replatform
A payments vendor serves banks via SOAP with XMLDSig and WS-Security. Mobile partners want REST + JSON, lower latency, and simpler auth.
Approach
Built a JSON/REST facade with OpenAPI 3.1 and JSON Schema.
Introduced OAuth 2.0 with mTLS for institutional clients; replaced XMLDSig on transport-level secured calls with JWS for signed webhooks.
Ran shadow traffic for 60 days; compared XML vs JSON responses using a diff tool and business-level invariants.
Adopted cursor pagination and RFC 7807 errors; reduced mean payload size by 42%.
Outcomes
P99 latency dropped from 950ms to 420ms on mobile networks due to smaller payloads and HTTP/2 multiplexing.
Integration time for new partners fell from weeks to days, thanks to SDKs and interactive docs.
Audit teams approved equivalence based on signed event logs, JWS policies, and deterministic idempotency keys.
FAQs
Q: Should I use JSON for everything now?
A: No. Use JSON for data-centric APIs, especially on the web. Use XML when you need document fidelity, transformations, canonical signatures, or you’re embedded in ecosystems that standardize on XML (e.g., SAML, certain payments networks).
Q: Is XML more secure than JSON?
A: Neither format is inherently more secure. Security comes from parser settings, validation, authentication, encryption, and operational controls. XML has unique risks (XXE, Billion Laughs) and strengths (XMLDSig). JSON has simpler parsers but needs the same rigor (size caps, schema validation, authZ).
Q: How do I validate JSON?
A: Use JSON Schema for request/response validation and OpenAPI for endpoint and contract metadata. Validate both at the edge and in services.
Q: How do I sign JSON?
A: Use JWS (JSON Web Signature) from the JOSE family. For encryption, use JWE. For transport security, continue to use TLS/mTLS.
Q: What about gRPC, Protobuf, or CBOR?
A: For service-to-service, binary formats like Protobuf (via gRPC) or CBOR/MessagePack can outperform JSON. For public APIs and browser clients, JSON remains the most interoperable default.
Q: How should I version my API?
A: Prefer additive changes. If you must break, create /v2 or use media type versions. Publish deprecation notices, timelines, and migration steps. Keep old versions stable during migration windows.
Q: What’s the best way to handle money?
A: Use strings representing decimal values with explicit currency and scale, or integer minor units (e.g., cents). Avoid binary floating point for financial amounts.
Q: How do I stream large result sets?
A: Use NDJSON over chunked transfer encoding. Each line is a JSON object; clients can process incrementally.
Q: Can I keep XML internally and speak JSON externally?
A: Yes. Use adapters at the edge to translate. Maintain strong mapping docs and parity tests.
Q: How do I optimize for AI Overviews and agent integrations?
A: Publish accurate, concise “Quick Answer” sections, maintain up-to-date OpenAPI schemas, provide clear examples and error models, and keep rate limits and pagination predictable. Agents parse JSON and rely on consistent contracts.
XML Digital Signature (XMLDSig): W3C Recommendation
SOAP 1.2: W3C Recommendation
SAML 2.0: OASIS Standard
Conclusion
A simple bracket didn’t just “kill the tag”—it made the web’s default data shape fast, readable, and ubiquitous. JSON won mainstream APIs on pragmatism: minimal syntax, native types, and frictionless tooling. XML endures where structure, signatures, and documents rule. In 2026, the winning strategy isn’t format tribalism; it’s format fluency. Pick the right tool for the job, validate relentlessly, lock down your parsers, and ship contracts your customers can trust.
Before you ship your next change, sanity-check your payloads:
Writing Tip Google's search quality guidelines prioritize EEAT: Experience, Expertise, Authoritativeness, and Trustworthiness. Make sure your content reflects these!