XML
Extensible Markup Language
- Pronunciation
- eks-em-EL
In short
XML (Extensible Markup Language) is a text format for structured data that uses nested tags you define yourself, readable by both people and machines.
What is XML?
XML became a W3C Recommendation in 1998. Like HTML it uses tags in angle brackets, but the tags aren't fixed: a book list can use <book>, <title> and <author>, and an invoice its own vocabulary. Elements can have attributes and nested children, and every document has exactly one root element, which makes XML well suited to complex, hierarchical documents.
A family of standards grew around it. XML Schema (XSD) describes which elements and types a document may contain so it can be validated; XPath selects parts of a document; XSLT transforms one XML document into another; and namespaces let vocabularies from different sources be mixed without name clashes.
XML is everywhere even when it is not noticed: SOAP web services, RSS and Atom feeds, SVG images, Android layouts, Maven's pom.xml, sitemaps for search engines, and Office files such as .docx and .xlsx, which are ZIP archives full of XML. Many banking, government and healthcare integrations still exchange XML messages.
A common misconception is that JSON has made XML obsolete. JSON is lighter and maps directly to objects, so it won for web APIs, but XML still has strengths JSON lacks: mixed text and markup, comments, attributes, namespaces and mature validation. XML parsers should also be configured securely, since features such as external entities enable XXE attacks.
Key takeaways
- XML is a text format for structured data with self-defined tags.
- It became a W3C standard in 1998.
- XSD validates documents, XPath queries them and XSLT transforms them.
- SOAP, RSS, SVG, sitemaps and Office files all use XML.
- JSON dominates web APIs, but XML suits documents and strict validation.
Example
import xml.etree.ElementTree as ET
xml = """
<library>
<book id="1" lang="en">
<title>Dune</title>
<author>Frank Herbert</author>
</book>
<book id="2" lang="en">
<title>The Left Hand of Darkness</title>
<author>Ursula K. Le Guin</author>
</book>
</library>
"""
root = ET.fromstring(xml)
for book in root.findall("./book"): # an XPath-style path
print(book.get("id"), book.findtext("title"))Readers ask
What is the difference between XML and JSON?
Both store structured data as text. JSON is shorter and maps directly to objects and arrays, so most web APIs use it. XML is more verbose but supports attributes, namespaces, comments, mixed content and formal schemas.
What is the difference between XML and HTML?
HTML has a fixed set of tags for displaying web pages and is forgiving about errors. XML has no predefined tags, is used to describe data, and must be well-formed or parsers reject it.
What is an XXE attack?
XML External Entity injection: a malicious document uses an external entity to make the parser read local files or call internal URLs. Disabling external entities in the parser prevents it.
Often compared
See also
- JSONBackend & APIs, p. 25JSON is a lightweight, text-based format for storing and exchanging structured data as key-value pairs and lists, readable by both humans and machines.
- SOAPBackend & APIs, p. 44SOAP is an XML-based messaging protocol for web services that wraps each request and response in a strict envelope, usually defined by a formal WSDL contract.
- HTMLWeb Development, p. 18HTML is the markup language that defines the structure and content of web pages, such as headings, paragraphs, links, images, and forms.
- SerializationBackend & APIs, p. 41Serialization is the process of converting in-memory data structures into a format such as JSON or bytes, so they can be stored or sent over a network.
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- YAMLDevOps & Cloud, p. 54YAML is a human-readable data format that uses indentation instead of brackets, widely used for configuration files in DevOps tools and CI/CD pipelines.
Spotted a mistake or something missing on this page?Suggest an edit