What Is XML (Extensible Markup Language)?

Related problems: Older ERP or partner integrations that only exchange XML files; A new vendor's API uses JSON but our existing systems expect XML; Integration errors because a file doesn't match the agreed schema; Not sure whether XML-based identity or network tools are still current

Extensible Markup Language (XML) is a text format for structuring data and documents with named tags. Each piece of information sits between an opening tag and a closing tag, such as <invoiceNumber>1042</invoiceNumber>, and tags can be nested to show how values relate. “Extensible” means each application defines its own tags rather than using a fixed set. XML is a W3C standard and has been widely used since the late 1990s for business integrations, web services, identity standards, office file formats and network management.

At a glance

  • XML marks up data with opening and closing tags that each application defines for itself.
  • Documents can be validated against a schema that sets which elements are required and what types they hold.
  • It supports attributes, namespaces and mixed text, which suits documents as well as data.
  • It is more verbose than JSON and less readable by hand than YAML.
  • It is still common in enterprise integrations, SAML and NETCONF.

What problem it solves

Businesses exchange structured information constantly: orders, invoices, shipping notices, user identities, device configurations. Each exchange needs a format both sides can read and both sides can check. XML gave organizations a single, vendor-neutral way to define such formats, with tools in every major language to create, parse, validate and transform them.

Its schema tools are the main strength. Two companies can agree on a schema for a purchase order, and either side can reject a document that is missing a required field or has the wrong data type before it causes a problem downstream. Industry groups and standards bodies used this to define shared formats, which is why XML runs through many long-lived enterprise, financial, healthcare and government systems.

How it works

Elements and attributes. Data lives in elements, written as tags, and elements can contain other elements. Attributes add extra details inside the opening tag, such as <price currency="USD">.

Well-formed and valid. A well-formed document follows XML’s syntax rules: one root element, every tag closed and correctly nested. A valid document also matches a schema, usually written in XML Schema (XSD) or an older format called a DTD.

Namespaces. Because anyone can define tags, two vocabularies might both use <address>. Namespaces attach a unique identifier to each vocabulary so tags from different sources can be mixed without confusion.

Querying and transforming. Companion standards let software find values in a document (XPath) and convert one XML format into another or into HTML (XSLT). Integration platforms and ETL tools use these to map partner formats onto internal systems.

Where it shows up. SOAP web services, many ERP and supply-chain integrations, SAML single sign-on assertions, Microsoft Office and other document formats, RSS feeds and the NETCONF network management protocol.

When it matters for buyers

  • ERP and partner integrations. Older systems and trading partners may only exchange XML. A new platform needs to handle those formats or sit behind an integration layer that converts them. See our enterprise resource planning page for help evaluating platforms.
  • Mixed formats. Many projects involve translating between XML from legacy systems and JSON from newer APIs. That mapping work should be scoped and priced up front.
  • Identity. SAML-based single sign-on still relies on signed XML, so XML handling and parser security matter to identity providers and applications.
  • Network management. Devices that support NETCONF exchange configuration as XML, so automation tooling needs to handle it.

Questions to ask vendors

  • Which integrations in your product use XML, and which use JSON or other formats?
  • Do you publish schemas (XSD) for your XML formats, and how do you version them?
  • Can your platform transform between our partners’ XML formats and your data model, or do we need a separate integration tool?
  • How do you validate incoming XML, and what happens to a document that fails validation?
  • Are your XML parsers configured to block external entity and similar attacks?
  • How much notice do you give before changing an XML format we depend on?

How it differs from JSON

JSON and XML carry the same kinds of structured data, but XML was designed for documents as well as data. XML wraps values in named opening and closing tags, supports attributes, namespaces and text mixed with markup, and has mature schema and transformation standards. JSON uses braces and brackets, has fewer concepts and maps directly onto the objects and lists in most programming languages, so documents are shorter and quicker to write by hand or in code. That is why JSON is common in newer web APIs, while XML persists where strict validation, document structure or established standards matter. YAML, the third common format, is built for human-edited configuration rather than data exchange. Many platforms support more than one, and some network interfaces, such as RESTCONF, accept either XML or JSON.

Frequently Asked Questions

Is XML still used?
Yes. Newer web APIs mostly use JSON, but XML remains common in enterprise and partner integrations, SOAP web services, identity standards such as SAML, office document formats, RSS feeds and network management protocols such as NETCONF.
Is XML the same as HTML?
No. Both use tags, but HTML has a fixed set of tags for displaying web pages. XML lets each application define its own tags to describe data, and it has stricter rules, such as every opening tag needing a matching closing tag.
What is an XML schema?
A schema defines which elements and attributes a document may contain, in what order and with what types. The most common schema language is XML Schema (XSD). Parsing catches malformed XML; validating a well-formed document against a schema can catch missing, misplaced or incorrectly typed content.
Are there security risks with XML?
Some XML parsers, if left at permissive settings, can be tricked by malicious documents into reading local files or consuming excessive resources, a class of attack known as XML external entity (XXE) injection. Many current parsers disable the risky features by default, but systems that accept XML from outside should be checked.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.