Pasting a config file into an online formatter feels harmless: you want indentation, not a data transfer. In November 2025, security researchers showed how badly that assumption can fail. This guide summarises what they reported and what to look for in any tool you paste into — including this one.
What the researchers found
In November 2025, watchTowr Labs published research into two popular formatting sites, JSONFormatter.org and CodeBeautify.org. Both offered a save feature that stored a pasted snippet on the site’s servers and produced a shareable link, and a “Recent Links” page that listed recently saved items. Because the saved items could be enumerated and retrieved, the researchers were able to collect more than 80,000 saved pastes, totalling over 5 GB, spanning several years of use.
According to the report, the pastes included:
- Active Directory credentials and other domain passwords
- database and cloud credentials, including AWS access keys
- private keys and code-repository tokens
- CI/CD secrets and payment-gateway API keys
- recordings of SSH sessions, and personal data including customer identity (KYC) records
The affected organisations reportedly spanned government, critical national infrastructure, banking and finance, technology and even cybersecurity companies.
To test whether anyone else was watching, the researchers saved pastes containing fake AWS credentials (canary tokens). They reported that someone attempted to use those credentials roughly 48 hours later — evidence that saved content was already being harvested by others. Coverage at the time reported that the save functionality had been disabled following the research.
It is worth being precise about what this was. It was not a break-in to the sites’ servers. Users had chosen to save content, and the sites’ own features made that content discoverable by strangers. Many of those users probably did not realise that “save” effectively meant “publish”.
Why formatters are a high-risk place to paste
People paste into formatters precisely the material that contains secrets: a JSON response with a bearer token, a Kubernetes manifest with a database password, a .env file, a JWT, a SAML assertion, a stack trace with a connection string. The act is quick and routine, and it usually happens while debugging under time pressure, when nobody stops to redact.
Any of these can expose a paste beyond your machine:
- Server-side processing. If the site sends the text to a server to be formatted, it can be logged, cached or retained, whatever the privacy policy intends.
- Save and share features that store content server-side, especially with guessable links or public listings.
- Third-party scripts on the page — analytics, advertising, session-replay tools — that may capture what is typed into a text area.
- Browser extensions with permission to read every page you visit.
A trustworthy tool should keep the first two from happening by design, keep third-party scripts off the page that handles your data, and let you check its behaviour yourself.
Three design choices that limit the damage
1. Client-side processing. When parsing and formatting run as JavaScript and WebAssembly in your browser, the pasted text never needs to leave the tab. PasteKit works this way for every formatter, validator and converter: the engine for a format is downloaded once as a static file, and from then on your input is processed locally.
2. Sharing through the URL fragment. A share link can carry the content itself instead of a pointer to a server-side copy. PasteKit compresses the input into the part of the URL after #. Browsers do not send the fragment to the server when they request the page, and it is not included in the Referer header, so there is no server-side store to leak or enumerate and no “recent links” list. Be clear about the limits, though: the link is the data. It is compressed, not encrypted, so anyone who receives the link can read it, and it is kept wherever the link is kept — your chat history, your browser history, a ticket.
3. A secret scanner before sharing. Before you copy a share link, PasteKit scans the input for common credential formats — private keys, AWS access keys and secret keys, GitHub, GitLab and Slack tokens, Slack webhooks, Stripe and Google API keys, AI-provider API keys, Azure storage keys, JWTs, passwords embedded in URLs and connection strings, password-like fields and bearer tokens — and highlights each finding with a masked preview so you can redact it first. A scanner cannot recognise every secret, but it catches the obvious ones at exactly the moment they are about to be sent somewhere.
How to verify in DevTools that nothing is uploaded
Do not take any site’s word for it, including ours. You can check in a few minutes with the browser’s developer tools:
- Open the tool’s page, then open DevTools (F12, or Cmd+Option+I on a Mac) and select the Network tab.
- Tick Preserve log and clear the existing entries.
- Paste a test string containing a unique marker, such as
canary-7f3a9c, and format, validate and convert it. - Look at every new request. Filter by Fetch/XHR and by WS (WebSockets), and check the request payload of anything that appears. Loading a format’s engine for the first time shows up as GET requests for
.jsor.wasmfiles with no request body — that is code coming in, not data going out. - Use the Network panel’s search (Ctrl+F or Cmd+F inside the panel) to look for your marker across all requests. It should not appear in any request.
- For a stronger test, set the throttling menu to Offline after the page and engine have loaded, and format again. A genuinely client-side tool keeps working.
Repeat the check occasionally; a site can change. The same method works for any web tool you are considering for sensitive data.
Habits that protect you anywhere
- Redact before you paste: replace tokens and passwords with placeholders when the structure is all you need.
- Treat any secret pasted into a third-party site as exposed. Rotate it; deleting the paste is not enough if it may already have been copied.
- Prefer local tools for sensitive material: your editor’s formatter,
jq,yq,terraform fmtorprettieron the command line. - Use secret scanning in your repositories and CI (GitHub push protection, gitleaks, trufflehog) so leaked keys are caught even when habits slip.
- Keep short-lived credentials where possible, so an exposed token stops working on its own.
Frequently asked questions
What happened with JSONFormatter and CodeBeautify?
In November 2025, watchTowr Labs reported that pastes saved with those sites’ save feature could be listed and retrieved, and collected more than 80,000 of them containing credentials, keys and personal data.
Does PasteKit send my data to a server?
No. Formatting, validation and conversion run in your browser, and share links keep the content in the URL fragment rather than on a server. You can confirm this with the DevTools steps above.
Is a URL-fragment share link private?
It is never sent to the website’s server, but anyone with the link can decode the content. Share it only with people who should see the data, and redact secrets first.
I pasted a secret into an online tool. What should I do?
Assume it is compromised: revoke or rotate the credential, check access logs for its use, and then remove it from wherever you pasted it.
Can a secret scanner find every secret?
No. It recognises well-known formats and suspicious field names. Custom tokens or plain passwords in unusual places can slip through, so it supports redaction rather than replacing it.