Neatbo.

Diagnose a SQL command with typed bindings

Prepare a complete typed binding list, inspect source spans and retain the diagnostic with both originals.

Prepare the command and binding list

Paste a command or select at most one strict UTF-8 file, up to 256 KiB. A selected file replaces only the command box; keep the secondary typed JSON, up to 1 MiB. Original filename labels allow 512 UTF-8 bytes, independent of operating-system basename limits.

Use a root object with a parameters array. Each entry has exactly name, type and value. Supported types are scalar Unicode string, signed 32-bit int as a JSON integer token, decimal as an exact canonical decimal string with precision and scale at most 38, strict JSON boolean and null. Unknown types or metadata are refused.

One supplied binding
SELECT subcatId FROM EnrollmentSubCategory WHERE catid = @catId
{"parameters":[{"name":"@catId","type":"int","value":1}]}
=> SELECT subcatId FROM EnrollmentSubCategory WHERE catid = 1

Match every actual occurrence

At most 1,000 unique bindings, 128 UTF-16 units per name including @, and 65,536 UTF-8 bytes per string value. Names must be complete mature LOCAL_ID tokens, without @@. Exact matching is default; optional case folding affects ASCII A–Z only.

Only complete code-region parameter tokens are expanded. Quoted strings, quoted/bracketed identifiers, line comments and valid nested block comments stay unchanged; @@ system references stay unchanged and are reported. Unfinished tokens, missing bindings and duplicate decoded metadata/names refuse the whole operation.

  • Paste the original command or select one local UTF-8 .sql file.
  • Paste the complete typed parameter JSON and choose the explicit name matching rule.
  • Run the preview; inspect repeated occurrences, missing-name errors and unused bindings.
  • Copy the complete diagnostic or save all four artifacts, then keep the originals with the real application log.

Keep a complete diagnosis

Allow 100,000 mature lexer tokens and 20,000 total parameter/system references. Complete diagnostic SQL allows 8 MiB and the complete report 4 MiB; no sampled or truncated result is returned. A pathological input can hit the 10-second disposable Worker deadline before reaching a numeric limit.

One leading BOM per input is removed for parsing, recorded and retained in unchanged originals. Reject malformed UTF-8 and unpaired Unicode surrogates. The screen previews 4,000 codepoints; copy and downloads keep every result byte.

The report preserves all typed values, literals, every occurrence span, system references, unused bindings, source names/SHA256/byte sizes and matching mode. There is no connection, statement validation, declaration scope analysis, database collation inference, driver size/precision coercion or execution. The diagnostic must not replace parameterized execution.

Correct every missing binding, duplicated name, type, encoding or unfinished token and rerun. Cancellation and the 10-second deadline discard unfinished output; retry with the same selected File and parameter values.

The four downloads have a separate 16 MiB cap. Downloads plus the complete copy text have a 32 MiB aggregate cap; the full text is counted again even though it also appears in the SQL download. The data panel contains only bounded counts; the complete matching report stays in its JSON download.

The same absolute 10-second deadline covers validation, reading, callbacks, Worker loading and final result publication. Blocking synchronous work cannot extend it; input is retained for retry.

Four complete downloads
FilePurpose
sql-diagnostic.sqlComplete diagnostic text with explicit header
sql-parameter-report.jsonAll typed bindings, occurrences and source identities
command-original.sqlExact effective source SQL bytes
parameters-original.jsonExact original parameter JSON bytes

References

  • SQL command and separate parameter logging

    Full original question, all seven answers and both author comments reviewed. The author accepts explanatory and separate-log approaches; browser intent and market scale are unknown.

  • Microsoft T-SQL constants

    Single-quote doubling, uppercase N for Unicode, strict bit and exact decimal values.

  • ANTLR T-SQL lexical grammar

    Pinned unmodified generated lexer plus validation of its COMMENT token nesting and unfinished token fallbacks. Lexical diagnostics do not validate SQL statements.

Tools in this category

Expand a tool to see its steps, options and supported formats, then open its workspace.

Preview bound SQL parametersExpand typed T-SQL parameter values for diagnosis and audit every binding.

Keep the original T-SQL command and typed parameter JSON, then read a complete diagnostic preview and matching report. SQL drivers send the command and parameters separately.

Steps

  1. Paste the original command or select one local UTF-8 .sql file.
  2. Paste the complete typed parameter JSON and choose the explicit name matching rule.
  3. Run the preview; inspect repeated occurrences, missing-name errors and unused bindings.
  4. Copy the complete diagnostic or save all four artifacts, then keep the originals with the real application log.

Available options

Name matching
Exact spelling · Ignore ASCII letter case

Choose exact matching or explicit ASCII case folding; database collation is unknown.

Capabilities and limits

  • Paste a command or select at most one strict UTF-8 file, up to 256 KiB. A selected file replaces only the command box; keep the secondary typed JSON, up to 1 MiB. Original filename labels allow 512 UTF-8 bytes, independent of operating-system basename limits.
  • Use a root object with a parameters array. Each entry has exactly name, type and value. Supported types are scalar Unicode string, signed 32-bit int as a JSON integer token, decimal as an exact canonical decimal string with precision and scale at most 38, strict JSON boolean and null. Unknown types or metadata are refused.
  • At most 1,000 unique bindings, 128 UTF-16 units per name including @, and 65,536 UTF-8 bytes per string value. Names must be complete mature LOCAL_ID tokens, without @@. Exact matching is default; optional case folding affects ASCII A–Z only.
  • Only complete code-region parameter tokens are expanded. Quoted strings, quoted/bracketed identifiers, line comments and valid nested block comments stay unchanged; @@ system references stay unchanged and are reported. Unfinished tokens, missing bindings and duplicate decoded metadata/names refuse the whole operation.
  • Allow 100,000 mature lexer tokens and 20,000 total parameter/system references. Complete diagnostic SQL allows 8 MiB and the complete report 4 MiB; no sampled or truncated result is returned. A pathological input can hit the 10-second disposable Worker deadline before reaching a numeric limit.
  • One leading BOM per input is removed for parsing, recorded and retained in unchanged originals. Reject malformed UTF-8 and unpaired Unicode surrogates. The screen previews 4,000 codepoints; copy and downloads keep every result byte.
  • The report preserves all typed values, literals, every occurrence span, system references, unused bindings, source names/SHA256/byte sizes and matching mode. There is no connection, statement validation, declaration scope analysis, database collation inference, driver size/precision coercion or execution. The diagnostic must not replace parameterized execution.
  • The four downloads have a separate 16 MiB cap. Downloads plus the complete copy text have a 32 MiB aggregate cap; the full text is counted again even though it also appears in the SQL download. The data panel contains only bounded counts; the complete matching report stays in its JSON download.
  • The same absolute 10-second deadline covers validation, reading, callbacks, Worker loading and final result publication. Blocking synchronous work cannot extend it; input is retained for retry.
Open Preview bound SQL parameters →