A JSON object can repeat a name:
{"role": "viewer", "role": "admin"}
The JSON specification says object names should be unique. Its grammar still admits the example above. A receiver is left to decide what the repeated name means. That decision can change the value an application sees.
The same bytes, different answers
The specification describes three observed behaviors. Many implementations keep the last pair. Others reject the object. Some expose every pair. Python’s JSON decoder uses the last value by default, so its ordinary object for this example contains role: admin. The Go encoding/json/v2 documentation says its decoder rejects duplicate names by default. Those are different answers to identical input.
The difference matters when software passes JSON through more than one component. Imagine a validator rejecting this object while a separate consumer accepts it and keeps admin. The rejection only protects the consumer if it prevents the consumer from processing that input. More generally, a check performed on one interpretation cannot establish what another parser will see. This follows from the parser differences; it is not a claim about any particular service.
Repetition can hide behind escapes
These names look different in the source text:
{"role": "viewer", "\u0072ole": "admin"}
After JSON string escapes are decoded, both names are role. The specification’s string comparison guidance warns that comparing undecoded spellings can give the wrong answer. A duplicate check must compare decoded names within each object, including nested objects. Looking only for repeated character sequences in raw text misses this case.
What to do
Reject duplicate decoded names when JSON first enters your system. Do this before converting the object into a map that retains one value per name. In Python, object_pairs_hook receives each object’s ordered pairs and can reject a name it has already seen, as the decoder documentation explains.
Add test inputs with an ordinary duplicate and an escaped spelling of the same name. Check the actual parser used at every boundary that accepts untrusted JSON. Keep one clear rule across the path: a repeated object name is an error. That gives later code a single mapping to work with.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.