Documentation
Wire XML validation into the place it breaks
Everything here exists so a broken document fails in CI, next to the change that broke it — rather than in production, next to nothing. The same API converts, queries, diffs and transforms, for the pipelines that need more than a verdict.
HTTP API
5 endpoints · 4 MB a request
Each endpoint runs the same module as the tool of the same name, so a result here and one in the browser are the same bytes. Validation answers in JSON or SARIF 2.1.0, and nothing is stored.
/validate/convert/xpath/diff/transform
MCP server
Model Context Protocol
The same operations as 5 tools an AI agent can call over the Model Context Protocol. Discovery needs no key; a call takes the same key and allowance as the API.
xml_validatexml_convertxml_xpathxml_diffxml_transform
CI and integrations
SARIF 2.1.0 · 6 rules
A copy-paste workflow, or a composite GitHub Action, that turns a malformed file into an annotation on the pull request that broke it — plus webhooks for the sources you monitor.
Validation policies
Account required
Save up to 2 MB of XSD, a vocabulary profile and per-rule severities as an immutable revision, then pass its id to the API or the action so every repository validates the same way.
API keys
1,000 requests an hour
Keys are issued per account and only a SHA-256 hash is stored, so a key is shown exactly once and cannot be recovered by anyone. Guests cannot issue them.
OpenAPI description
OpenAPI 3.1.0
Every endpoint in machine-readable form, built from the constants the endpoints enforce. Import it into a client generator or an HTTP client; reading it needs no key.
Limits
Stated here rather than discovered in a 413. The caps exist because parsing is the one thing a stranger can make expensive.
- Free tools
- 2 MB
- Per document, no account
- API request
- 4 MB
- Per request, schema and JSON escaping included
- API rate
- 1,000 / hour
- Per account, shared by its keys
- Schema
- 2 MB
- Per XSD, RELAX NG, DTD or Schematron schema
Nothing here fetches a URL on your behalf: an XSD that imports a remote schema will not fetch it, and neither will a stylesheet's xsl:import. Every limit, with the reason for it
Get started
Bring order to the XML your team can't afford to ignore.
Create a free account and get a private workspace to search, validate, diff, and monitor your XML feeds, sitemaps, schemas, and vendor integrations.