What is the YAML file format?
.yaml is a text file format used for exchanging data between various applications. YAML - short for *YAML Ain't Markup Language* - is a standard for organizing information in a human-readable, platform-independent format using indentation-based key: value pairs encoded in UTF-8. Parsing .yaml files requires a YAML library to be installed; popular libraries include PyYAML (Python), js-yaml (JavaScript), and SnakeYAML (Java). .yaml files are sometimes saved with the .yml extension, which is functionally identical. Beyond data interchange, .yaml files are typically used for serializing data and for writing configuration files in tools such as Docker Compose, Kubernetes, and GitHub Actions.
Serialization
Serialization is a term used in computer science. Serialization is a process of translating data or objects into a format that can be stored, transmitted, and reconstructed later. For example, two institutions exchanging some data in a standardized format using different applications must serialize that data before sending it. Serialized data can also be stored in a file - .yaml, .xml, .json, .toml, etc. - and then sent to the recipients.
A .yaml document may optionally begin with the --- document-start marker and end with ...; this also allows multiple documents inside a single file. Since YAML 1.2 (2009, revised 2021), every valid JSON file is also valid YAML.
Security & safety
RISK: MEDIUMA YAML file is plain text and doesn't execute on its own, so reading one is safe. Two real risks: (1) config YAML (CI pipelines, Compose, K8s, Ansible) frequently contains secrets - tokens, passwords, keys - so don't paste it into untrusted online validators or commit it publicly. (2) Programmatic danger: loading untrusted YAML with an unsafe parser (e.g. PyYAML's yaml.load instead of yaml.safe_load) can execute arbitrary objects/code - always use the safe loader for files you don't trust. Editing risk: a tab or a misaligned space silently changes meaning, so validate after editing.
Format details
in a nutshellPrograms that open YAML files
Technical details
deep spec| File extension | .yaml (also .yml) |
| MIME type | application/yaml |
| Encoding | UTF-8 plain text; no binary header or magic bytes |
| Structure | Indentation-based key: value pairs; indentation uses spaces only - tabs are forbidden by the spec |
| Document markers | --- marks document start, ... marks document end; multiple documents can coexist in one file |
| Native data types | Strings, integers, floats, booleans, null, sequences (lists), mappings (dictionaries), timestamps |
| Spec version | YAML 1.2 (2009, revised 2021); supersedes YAML 1.1 (2005) and YAML 1.0 (2001) |
| JSON compatibility | Since YAML 1.2, every valid JSON document is also valid YAML - JSON is a strict subset |
| Comments | Single-line comments introduced by # ; may appear on their own line or inline after a value |
| Multiline strings | Literal block scalar (|) preserves newlines; folded scalar (>) converts newlines to spaces |
| Anchors and aliases | & defines a named anchor and * references (aliases) it, enabling value reuse without duplication |
| Developers | Clark Evans, Ingy döt Net, Oren Ben-Kiki |
| Common use cases | Configuration files (Kubernetes, Docker Compose, GitHub Actions, Ansible), data serialization, OpenAPI definitions |
| Quoting | Unquoted, single-quoted ('...'), and double-quoted ("...") strings all supported; double-quoted allows escape sequences |
| Released | 2001 (YAML 1.0); YAML 1.1 (2005); current YAML 1.2 (2009, revised 2021) |
| Open standard | Yes · royalty-free |
| Specification | yaml.org |