October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

PATCH Done Right: JSON Merge Patch vs. JSON Patch for Partial Updates

JSON Merge Patch is concise for object updates but treats null as deletion and replaces arrays. JSON Patch offers ordered, explicit operations for path-level edits.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use application/merge-patch+json for concise, object-shaped updates when null should delete a member and replacing whole arrays is acceptable. Use application/json-patch+json when clients need explicit operations at individual paths—especially array edits, moves, copies, or a precondition expressed with test. Neither format is universally better: an API must document which one its endpoint accepts and how it applies it.

How the two patch formats differ

Decision JSON Merge Patch JSON Patch
Payload shape An object resembling the desired partial resource An ordered array of operation objects
Remove an object member Supply that member with a value of null Use a remove operation at its path
Meaning of null Within an object patch, it means remove the target member; it cannot express setting that member to JSON null Removal is separate from supplying a value, so a value can explicitly be JSON null
Arrays A supplied array replaces the existing array as a whole Operations can target individual array locations
Available operations Merge object members, replace values, and remove members through null semantics add, remove, replace, move, copy, and test
Practical trade-off Often concise for straightforward object updates More explicit and precise, but verbose and order-sensitive

The rules come from RFC 7396 and RFC 6902. They define different meanings for patch documents, not just different spellings for the same update.

How JSON Merge Patch works

A Merge Patch document is a JSON value. When it is an object, members are processed recursively: omitted members remain unchanged, non-null supplied values add or replace members, and null-valued members remove them. If the patch document itself is not an object, it replaces the entire target with that value.

For example, this request renames a profile, removes its phone member, and merges the nested preferences object:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
PATCH /profile HTTP/1.1
Content-Type: application/merge-patch+json

{
  "displayName": "Sam",
  "phone": null,
  "preferences": { "theme": "dark" }
}

If the patch also included "tags": ["api"], the new array would replace the existing tags array; Merge Patch has no instruction for changing only one element. The specification notes that the format suits documents that primarily use objects and do not make use of explicit null values. It says, “The merge patch format is not appropriate for all JSON syntaxes.”

How JSON Patch works

A JSON Patch document is an ordered array of operations. Each operation uses an op and a JSON Pointer path; operations that need a value or a source location also use value or from. The result of one operation becomes the input to the next. If an operation fails, evaluation stops.

This example changes a name, removes a phone member, and replaces the item at array index 1:

PATCH /profile HTTP/1.1
Content-Type: application/json-patch+json

[
  { "op": "replace", "path": "/displayName", "value": "Sam" },
  { "op": "remove", "path": "/phone" },
  { "op": "replace", "path": "/tags/1", "value": "api" }
]

The six standardized operation names serve distinct purposes:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • add adds a value at a path (and can insert an array element).
  • remove removes the value at a path.
  • replace replaces the value at a path.
  • move moves a value from one path to another.
  • copy copies a value from one path to another.
  • test checks that a value at a path matches the supplied value; a failed test stops the sequence.

Paths use JSON Pointer syntax. Array indexes are zero-based, so /tags/1 addresses the second item. Because operations run in order, earlier insertions or removals can change which item a later array index refers to. RFC 6902 describes JSON Patch as “a sequence of operations to apply to a target JSON document.”

Choose based on the resource and update

Choose Merge Patch for simple object-shaped changes

  • Most updates are partial objects, such as changing a profile name or nested preference.
  • A supplied null can naturally mean “remove this member.”
  • Replacing an entire array whenever it changes is acceptable.

Choose JSON Patch for precise path-level changes

  • A client needs to update one array element without resending the whole array.
  • Removal must be an explicit operation rather than encoded as a null member.
  • The update needs to move or copy values, or check a value with test before proceeding.

If JSON null is meaningful data for a field, Merge Patch’s object-member rule creates a limitation: its ordinary semantics cannot distinguish “set this field to null” from “remove it.” JSON Patch can represent those separately with a value-bearing operation and remove. These are choices inferred from the standards’ semantics; neither RFC mandates one format for a particular API.

Media types and endpoint support

The formats have distinct media types: application/merge-patch+json for Merge Patch and application/json-patch+json for JSON Patch. Send the media type that the endpoint documents. The fact that an endpoint accepts HTTP PATCH does not by itself establish which patch format it supports; check the API documentation rather than assuming either one will be accepted.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Concurrency, validation, and security

Patch syntax does not set an API’s concurrency policy. RFC 6902 includes an example using the HTTP If-Match header, but that does not mean every endpoint requires or enforces it. The endpoint should document whether clients need a conditional request, version field, or another mechanism to prevent an update based on stale data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Both formats request changes; neither authorizes them. RFC 7396 places responsibility on the server to decide whether requested modifications are appropriate and whether the requester is authorized. In practice, validate the caller’s permission for the affected fields and validate the resulting resource against the application’s rules. Follow the security controls of the application and HTTP stack; RFC 6902’s discussion of CSRF in older browsers concerns historical browser behavior, not a universal current vulnerability.

What the standards do—and do not—establish

RFC 7396, JSON Merge Patch, is an IETF Standards Track specification published in October 2014; it obsoletes RFC 7386. RFC 6902, JavaScript Object Notation (JSON) Patch, is an IETF Standards Track specification published in April 2013. For HTTP PATCH method behavior and its security context, see RFC 5789.

These specifications establish processing rules and examples, not comparative performance, adoption, or error-rate figures. They do not support a claim that one format is inherently faster, safer, or more widely used. API-specific implementation behavior must be confirmed in that API’s current documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.