// the find
devinus/poison
An incredibly fast, pure Elixir JSON library
Poison is a pure-Elixir JSON encoder/decoder built around a hand-rolled, single-pass parser tuned for BEAM's JIT. It's for Elixir developers who want a fast, dependency-free JSON library with protocol-based struct encoding, but it's an older, long-running project rather than something newly emerging.
The parser uses sub-binary matching and techniques specifically chosen to benefit from BeamAsm JIT compilation, which is a real, measured performance approach rather than a marketing claim. It fully conforms to RFC 8259/ECMA 404 and passes the JSONTestSuite, so correctness on edge cases (surrogate pairs, number formats, etc.) isn't just asserted. The Encoder protocol lets you implement custom encoding per struct, with `@derive` plus `:only`/`:except` for selective field serialization without writing a full `defimpl`. Parser, decoder, and encoder are decoupled, so you can use just the parser if you don't need struct decoding.
Jason has effectively become the ecosystem default for Elixir JSON — it's usually faster in benchmarks and is what most libraries (Phoenix, Ecto adapters, etc.) assume you're using, so picking Poison today means swimming against the grain for library interop. The `keys: :atoms` decode option dynamically creates atoms from arbitrary input data; atoms are never garbage collected, so decoding untrusted JSON with this option is a real DoS vector, and the README's warning reads more like a footnote than the severity deserves. There's no streaming/incremental decode API — you need the entire document as a binary in memory before you can decode anything, which rules out large-payload or line-delimited JSON use cases. Elixir 1.18 shipped a built-in `JSON` module in the standard library, which covers a lot of what third-party libraries like this exist for, and the last push here was over a year ago (2024-08-12), so it's unclear how actively this is still being pushed forward.