What is the JNLP file format?
Files with the .jnlp extension contain data stored using XML syntax. Such data describes a Java application or applet whose source code resides on a remote server, intended to be launched locally according to the Java Network Launch Protocol - originally implemented by Java Web Start.
A .jnlp file typically contains:
- Information about the application - title, vendor, description and homepage,
- Resources - the URL (
codebaseattribute) where the JAR archive packages are hosted, - Security settings - permissions that allow the application to perform certain actions,
- Target element - the main class and parameters of the application or web applet.
A .jnlp file may also contain many different details about JRE version requirements, icons, shortcut preferences and update policies. The full specification is defined by JSR-56 (Sun Microsystems / Oracle) and the <jnlp> root element's attributes point back to the application's server location. Java Web Start - the original javaws launcher bundled with JRE 1.4 through Java 8 - was deprecated in Java 9 (2017) and removed entirely in Java 11 (2018). Modern alternatives are OpenWebStart (a cross-platform open-source replacement) and IcedTea-Web on Linux. The content of a .jnlp file can be viewed and edited using any plain-text editor.
Security & safety
RISK: MEDIUMThe JNLP file itself is inert XML, but what it launches is a full desktop Java application, historically with <all-permissions/> - JNLP attachments were a documented phishing/malware vector in the 2010s precisely because javaws would fetch and execute remote code. Today the attack surface is small (modern Java cannot run them at all), but anyone with OpenWebStart or legacy Java 8 installed should only open JNLP files from servers they trust, and check the codebase URL in a text editor first. Unexpected .jnlp e-mail attachments should be deleted.
Format details
in a nutshellPrograms that open JNLP files
Technical details
deep spec| Format type | XML application-launch descriptor (plain text) |
| Root XML element | `<jnlp>` with required `codebase` attribute and optional `href` attribute |
| MIME type | `application/x-java-jnlp-file` |
| Character encoding | UTF-8 (standard XML; declared in the `<?xml?>` processing instruction) |
| Binary signature | None - plain-text XML; files begin with `<?xml` followed by a `<jnlp>` root element |
| Original developer | Sun Microsystems (later Oracle); standardized as JSR-56 |
| Legacy launcher | `javaws` (Java Web Start), bundled with JRE 1.4 through Java 8 |
| Current launchers | OpenWebStart (cross-platform, open-source); IcedTea-Web (Linux) |
| Lifecycle status | Java Web Start deprecated in Java 9 (2017); removed in Java 11 (2018) |
| JAR reference element | `<jar href="..."/>` inside `<resources>` block links the application's `.jar` packages |
| Security descriptor | `<security><all-permissions/></security>` grants full access; absence means sandboxed |
| JRE version targeting | `<java version="..."/>` or `<j2se version="..."/>` element specifies minimum runtime |
| Offline launch support | `<offline-allowed/>` element permits launch without network after initial JAR caching |
| Supported application types | Standard Java applications, applets, and installer extensions (nested `<extension>` JNLP) |
| JAR caching | Launcher downloads and caches JARs locally; `version` attribute on `<jar>` enables delta updates |
| Released | 2001 (Java Web Start, J2SE 1.3.1/1.4 era; standardized as JSR-56) |
| Open standard | Yes · royalty-free |
| Specification | jcp.org |
JNLP conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about JNLP files.