JSON Canonicalizer

Canonicalize JSON per RFC 8785 — sort keys lexicographically and remove whitespace. Compute SHA-256 hash for digital signatures and payload verification.

Input JSON
Canonical Output

Features

📐 RFC 8785 Compliant

  • Recursive key sorting (lexicographic)
  • Whitespace removal
  • Deterministic output
  • Handles nested objects and arrays

🔐 SHA-256 Hash

  • Web Crypto API (native browser)
  • Hex-encoded digest output
  • Suitable for payload signing
  • Repeatable across platforms

🔍 Key Sort Diff

  • Shows keys that were reordered
  • Count of total keys processed
  • Detects already-sorted payloads
  • Useful for debugging JWS/JWK

RFC 8785 Guide

What is JSON Canonicalization?

RFC 8785 (JSON Canonicalization Scheme, JCS) defines a deterministic serialization format for JSON. It enables consistent hashing and signing of JSON payloads regardless of how the original JSON was formatted.

// Input (any order, any whitespace)
{
  "zebra": "last",
  "apple": "first"
}

// Canonical form (RFC 8785)
{"apple":"first","zebra":"last"}

Where JSON canonicalization matters

Two JSON documents can hold the same data but differ in key order, spacing and number formatting. Canonicalization gives them one exact byte representation, which is required whenever you hash or sign JSON.

Tips and common pitfalls

  • Canonicalize on both sides: the signer and the verifier must apply the same RFC 8785 rules before hashing.
  • Numbers are written the way JavaScript prints them, so 1.0 becomes 1 and 1e2 becomes 100.
  • Keys are sorted by UTF-16 code units, which can differ from a simple alphabetical sort for non-ASCII keys.
  • Use it for content-addressed caching: a hash of canonical JSON gives the same cache key for equivalent requests.

More questions

Does canonicalization remove duplicate keys?

Input with duplicate keys is not valid I-JSON, which RFC 8785 requires. Parsers typically keep the last value, so fix duplicates at the source.

Is canonical JSON still normal JSON?

Yes. It is valid JSON that any parser can read; it just has no extra whitespace and a fixed key order.