惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
V
V2EX
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Recent Announcements
Recent Announcements
博客园 - 司徒正美
Microsoft Security Blog
Microsoft Security Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Latest news
Latest news
Vercel News
Vercel News
The Register - Security
The Register - Security
T
The Exploit Database - CXSecurity.com
S
Schneier on Security
N
Netflix TechBlog - Medium
WordPress大学
WordPress大学
小众软件
小众软件
L
Lohrmann on Cybersecurity
GbyAI
GbyAI
P
Privacy & Cybersecurity Law Blog
T
Tor Project blog
AWS News Blog
AWS News Blog
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
K
Kaspersky official blog
B
Blog RSS Feed
G
Google Developers Blog
量子位
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
Scott Helme
Scott Helme
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
I
Intezer
雷峰网
雷峰网
Martin Fowler
Martin Fowler
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Blog — PlanetScale
Blog — PlanetScale
IT之家
IT之家
F
Full Disclosure
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 【当耐特】
The Hacker News
The Hacker News
U
Unit 42
S
SegmentFault 最新的问题
I
InfoQ
aimingoo的专栏
aimingoo的专栏
Y
Y Combinator Blog
宝玉的分享
宝玉的分享
罗磊的独立博客
Spread Privacy
Spread Privacy
C
CERT Recently Published Vulnerability Notes

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
The Data Refinery: How JSON Quietly Became the Language AI Agents Speak
blense blog · 2026-06-17 · via DEV Community

Every tool call, every structured output, every agent decision travels as JSON. Here is the serialization knowledge that separates the amateur from the architect — now that the stakes have never been higher.


A developer ships an AI agent on a Friday. In the demo it's flawless: the model reads a request, calls a tool, returns a clean answer the app renders perfectly.

A week later, production dashboards are full of garbage. A date is showing up as raw text. A field that was definitely there is silently gone. Under one big payload, the whole server froze for two seconds. And here's the maddening part — nothing threw an error. The model returned JSON. The code parsed it. Everything "worked."

The bug wasn't in the model, and it wasn't in the parser. It lived in the narrow gap between text and data — the place every JSON value has to cross twice. That gap is serialization, and in 2026 it has quietly become one of the most important things a JavaScript engineer can actually understand.

Why now? Because the most important conversations in modern software aren't between humans anymore. They're between models and machines — an LLM deciding which tool to call, a server answering, an agent chaining ten steps together. And every one of those conversations happens in the same format: JSON.

So let's open up the refinery and see how raw structure becomes a clean stream of bytes — and back again — without losing anything precious on the way.

JSON is not a JavaScript object

This is the misunderstanding that creates most JSON bugs, so it's worth saying plainly: JSON only looks like a JavaScript object. It isn't one.

JSON is a transport format — flat, inert text meant to travel across a network or sit on a disk. A JavaScript object is a live structure in memory that your application can read, mutate, and call methods on. They resemble each other the way a flat-packed cardboard box resembles assembled furniture: same thing in spirit, completely different states.

const user = { name: "Joao" };   // a live object in memory
typeof user;                     // "object"

const text = JSON.stringify(user); // '{"name":"Joao"}' — just characters
typeof text;                       // "string"

The V8 engine has to do active work to move between these two worlds. Until you parse it, {"name":"Joao"} is no more "an object" than the word cake is something you can eat. Hold on to that mental model — everything below is just the two machines that cross the gap: one that packs, one that unpacks.

Packing the container: JSON.stringify and the serialization funnel

JSON.stringify walks the enumerable properties of a value and compresses them into a single JSON string for travel over the network or to disk. But it is not a neutral photocopier. Think of it as a funnel with three filters, and knowing what each filter does is what saves you at 2am.

Filter 1 — types that pass through cleanly: strings, numbers, booleans, arrays, and plain objects survive untouched.

Filter 2 — types that get quietly transformed: a Date is converted to an ISO 8601 string; NaN and Infinity are turned into null.

Filter 3 — types that are dropped entirely: functions, undefined, and symbols simply vanish from the output.

const data = {
  name: "Ana",
  createdAt: new Date(), // becomes an ISO string
  balance: Infinity,     // becomes null
  greet: () => "hi",     // dropped (function)
  nickname: undefined    // dropped (undefined)
};

JSON.stringify(data);
// '{"name":"Ana","createdAt":"2026-06-16T...Z","balance":null}'

Read that output again. Three of the five fields changed or disappeared, and the engine didn't say a word. That silence is the whole danger.

The one rule JSON refuses to break: no cycles

A JSON structure can nest as deeply as you like, but it must be strictly acyclic. The engine tracks the stack of objects it's walking; the moment it meets the same object twice, it aborts hard.

const a = {};
a.self = a;            // a points back at itself
JSON.stringify(a);
// TypeError: Converting circular structure to JSON

This is one of the rare cases where JSON fails loudly instead of silently — and you should be grateful for it.

The filtering agent: the replacer

The second argument to JSON.stringify is a replacer — a surgical interception that runs during packing. It lets you mutate values or strip sensitive data before it ever reaches the wire. The classic use is redacting secrets:

const user = { name: "Joao", password: "123", admin: true };

JSON.stringify(user, (key, value) =>
  key === "password" ? undefined : value
);
// '{"name":"Joao","admin":true}'

Return undefined from the replacer and the key is deleted from the payload. It's the cleanest place to make sure a password never leaves the building.

Formatting and delegation: space and toJSON

Two more levers are worth knowing. The third argument, space, injects whitespace — trading network efficiency for human readability when you're debugging. And any object can define a toJSON() method to dictate its own serialization; the engine always delegates to it when present.

const account = {
  id: 42,
  secret: "s3cr3t",
  toJSON() { return { id: this.id }; } // dictate your own shape
};

JSON.stringify(account); // '{"id":42}' — secret never serialized

Unpacking the container: JSON.parse and rehydration

On the way back, JSON.parse reconstructs ECMAScript values from the text, rebuilding the hierarchy strictly from the syntax in the string. But remember Filter 2: serialization erased types. That Date you sent is now just a string, and parsing alone won't bring it back to life.

That's what the reviver — the second argument to parse — is for. It intercepts parsing node by node, letting you rehydrate flat strings back into rich instances.

const text = '{"event":"deploy","when":"2026-06-16T10:30:00Z"}';

const obj = JSON.parse(text, (key, value) =>
  key === "when" ? new Date(value) : value
);

obj.when instanceof Date; // true — revived

Serialization is lossy by design; the reviver is how you choose what to restore on the other side.

Two agents, one job: replacer vs. reviver

These two hooks are mirror images, and confusing them is a common source of bugs. Here's the clean comparison:

replacer reviver
Runs during Serialization (stringify) After parsing (parse)
Receives The original in-memory value The freshly parsed string/literal
Main use Omit secrets, filter payloads Restore classes (e.g. Date)
Delete a value by Returning undefined Returning undefined

The modern twist: stop cloning with JSON

Here's a trick almost every JavaScript developer has reached for: deep-cloning an object with JSON.parse(JSON.stringify(obj)). It's clever, it's one line — and it's a silent killer, because it runs your data through the entire funnel above.

const original = {
  date: new Date(),
  tags: new Set(["a", "b"]),
  meta: { level: 42 }
};

// The "classic" hack — loses the Date, destroys the Set
const bad = JSON.parse(JSON.stringify(original));
bad.date;  // "2026-..." (a string!)
bad.tags;  // {} (empty object!)

Dates become strings, undefined disappears, Map and Set collapse into empty objects, functions are gone, and a circular reference throws. The fix has been native since 2022: structuredClone(), built on the same Structured Clone Algorithm the platform already uses internally for postMessage and IndexedDB.

const good = structuredClone(original);
good.date; // a real Date
good.tags; // Set(2) { "a", "b" }

structuredClone preserves circular references, Map, Set, typed arrays, and Date; it keeps undefined; it's roughly 20–30% slower but trades that for data integrity; and it adds zero bytes to your bundle (goodbye, Lodash's cloneDeep). It throws on functions and DOM nodes — which, honestly, is a feature. If you're cloning a function, your data model is trying to tell you something.

JSON as the blueprint of the architecture

Step back from the two functions and you'll notice something: JSON isn't just data flowing through your app. In the Node ecosystem, it's the declarative blueprint the whole architecture is built on.

Open any package.json and you're reading a JSON object that controls everything: main is the entry point, scripts are your automation triggers (start, test, build), dependencies define the module tree npm assembles, and private: true is a safety lock against accidental publishing. Configuration follows the same instinct — critical values like passwords and URLs don't live in source code; the common pattern is to unify process.env into centralized config objects that switch behavior between development and production.

And this is where a genuinely modern upgrade lands. For years, importing a JSON config meant a bundler or a fetch(). As of ES2025 (baseline across modern runtimes since April 2025), you can import JSON natively with an import attribute:

// Native JSON import — no bundler, no fetch
import config from "./config.json" with { type: "json" };

console.log(config.apiUrl);

That with { type: "json" } is not decoration — it's a security contract. It forces the runtime to verify the file is genuinely JSON (via its MIME type) before processing it, which prevents a server from sneaking executable JavaScript in through a file that merely looks like data. JSON modules can't run code; they're pure data, and only ever expose a default export. The platform turned a workaround into a guarantee.

The HTTP frontier: where naïve parsing breaks the event loop

Now the hard part. Real-time applications don't receive tidy, complete JSON documents — they receive data flowing in streams over HTTP, arriving in fragments. Call the native JSON.parse naïvely on a half-arrived network buffer and you get one of two bad outcomes: a syntax error on incomplete data, or — worse — a blocked single-threaded event loop while a huge payload is parsed synchronously, freezing the entire server for every other user.

The architecture demands a specialized intermediary. In Express, that's the express.json() middleware — the inspection conveyor on the assembly line. It buffers the incoming stream safely, checks the Content-Type: application/json header, parses the result, and hands your route a ready-to-use req.body.

const express = require("express");
const app = express();

app.use(express.json()); // the inspection conveyor

app.post("/api/users", (req, res) => {
  // req.body is already an object: stream buffered, validated, parsed
  console.log(req.body.name);
  res.status(201).json({ ok: true });
});

The distinction between the native function and the middleware is the distinction between a script and a system:

JSON.parse() express.json()
Execution context Synchronous memory (data already in V8) HTTP network layer (buffers/streams)
Invalid data Throws SyntaxError, aborts execution Returns a clean HTTP 400, keeps running
Scalability Low — blocks the event loop on huge payloads High — manages payload limits and concurrency

The payoff: why all of this now runs the AI era

Everything above used to be "good Node hygiene." In 2026 it's something bigger, because of one structural fact: LLMs are text generators, and your systems need data structures. JSON is the bridge between them — and, as we've seen, the bridge is exactly where bugs live.

That gap is now formalized into three levels of reliability, and knowing which one you're on is the difference between a demo and production:

  • Level 1 — Prompt engineering. "Return JSON with these fields." Works 80–95% of the time, fails silently on edge cases, gives you zero type guarantees.
  • Level 2 — Function / tool calling. The model "calls" a function whose schema you defined. Works 95–99% of the time, but the schema is a hint, not a constraint — you can still get valid types with invalid values.
  • Level 3 — Native structured output. Constrained decoding against a JSON Schema, using a finite-state machine to mask invalid tokens at generation time. Schema-valid 100% of the time — types and values enforced as the text is produced.

This isn't fringe tooling. Native structured output now ships across OpenAI (since August 2024), Google Gemini (2024, expanded through 2026), Anthropic (beta in late 2025, GA in early 2026), Cohere, and xAI's Grok — plus local runtimes like Ollama, vLLM, and SGLang. The schema has become the contract between the model and the rest of your system, and the advice from teams running this in production is blunt: design the schema first, the same way you'd design a database schema before writing application code. Tools like Pydantic and Zod exist to make that contract executable, and the real prize is testability — once output is typed and schema-valid, you can write unit tests and regression suites against it and catch the day a model update quietly changes its behavior.

Go one layer deeper, to the wire itself, and JSON is there too. The Model Context Protocol — introduced by Anthropic in November 2024 and now supported across Claude, Cursor, Gemini, and the major clouds — runs on JSON-RPC 2.0. Every tool an agent invokes, every resource it reads, is a JSON-RPC message:

{
  "jsonrpc": "2.0",
  "id": 7,
  "method": "tools/call",
  "params": {
    "name": "get_order",
    "arguments": { "orderId": "A-1042" }
  }
}

JSON Schema tells the model what arguments a tool accepts before it calls; one-way notifications carry progress updates; and batching lets an agent fan out several tool calls at once. MCP exists to solve the N×M problem — connecting N models to M tools without writing N×M custom adapters — and it solves it by making JSON the universal language every agent and every tool already speaks.

Now connect the two halves of this article. Every serialization gotcha we covered — the silently dropped field, the Date flattened into a string, the circular reference, the event loop frozen by a fat payload — now happens inside agent pipelines, where a non-deterministic model's output becomes your system's input. The silent bug was always dangerous. With a model on one end of the pipe, it's more dangerous than ever. Understanding the refinery stopped being optional the moment your software started talking to itself.

The refinery is operational

From rigorous lexical validation in the ECMAScript spec, to stream orchestration at scale in Node, to the contract language of autonomous agents — JSON has quietly become the connective tissue of the entire stack. It is one of the simplest formats ever designed, and that simplicity is exactly why it won.

Mastering the transformation agents — replacer, reviver, structuredClone, the schema — and the network traffic that carries them is what separates the programmer who uses JSON from the architect who commands it. A technical article, after all, isn't made of words alone; it's made of the small, exact decisions that survive contact with production.

So the next time an agent calls a tool and an answer comes back clean, you'll know what really happened in that fraction of a second. The Data Refinery is operational — and now you know how to run it.


Follow me on Dev.to for practical content about software engineering, AI, architecture, frontend, and backend development.

For complete articles, developer cheat sheets, and access to CIEL, my AI-powered learning guide, visit: blense.fun/en

No hype. Just clear and practical tech content. 🚀


Written in June 2026. The platform features referenced — import attributes (with { type: "json" }), structuredClone, native LLM structured output via constrained decoding, and the Model Context Protocol over JSON-RPC 2.0 — reflect the state of JavaScript and the AI tooling ecosystem at that date.