bbpb
Library for working with protobuf messages without a protobuf type definition.
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has no known vulnerabilities, installs with minimal friction, and fills a genuine gap in protobuf tooling for scenarios where the schema is unavailable. MIT licensing removes legal friction. Install it if you work with protobuf-based systems in security, testing, or reverse-engineering contexts.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction: pure Python wheel with a single dependency (six).
- Actively maintained with recent commits and no known vulnerabilities.
License · maintenance · safety
MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
last release 2025-03-14 (518 days) · last repo commit 2026-04-13 · 731 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 188,177 downloads/mo, #9,950 on PyPI
Alternatives
Verify before relying
pip install bbpb
import base64
data = base64.b64decode('KglNb2RpZnkgTWU=')
message, typedef = bbpb.decode_message(data)
message[5] = 'Modified Me'
encoded = bbpb.encode_message(message, typedef)- Accuracy of type inference for complex or ambiguous wire-type scenarios
- Performance characteristics when handling large or deeply nested messages
- Completeness of .proto file round-trip conversion (documentation notes limitations)
What it is and what it does
bbpb is a Python library for working with Protocol Buffer messages when you don't have the original .proto schema file. It decodes binary protobuf data by inferring field types from wire-type metadata and field content, then returns both the decoded message as a Python dictionary and a generated type definition. You can modify the decoded message and re-encode it back to binary using the type definition.
The library is designed for penetration testing and security research scenarios where protobuf messages need to be inspected and modified without access to the schema. It provides both a Python API and a command-line tool. The type inference is best-effort—most common fields parse correctly, but you can also supply custom type definitions to override guesses or name fields for readability. It includes convenience functions for JSON encoding/decoding and .proto file import/export, though the latter has known limitations with certain proto syntax.
Use it for
- Penetration testing: intercept and modify protobuf messages in transit when schema is unavailable
- Reverse engineering: decode and understand protobuf message structure from binary samples alone
- Security research: analyze and fuzz protobuf-based protocols without access to source definitions
- Message inspection: examine and transform protobuf payloads in debugging or forensic workflows
- Protocol analysis: extract and manipulate protobuf fields for API testing or integration work
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has no known vulnerabilities, installs with minimal friction, and fills a genuine gap in protobuf tooling for scenarios where the schema is unavailable. MIT licensing removes legal friction. Install it if you work with protobuf-based systems in security, testing, or reverse-engineering contexts.
Install
bbpb on PyPI
Before you install
Low friction: pure Python wheel with a single dependency (six). Actively maintained with recent commits and no known vulnerabilities.
License in practice
MIT license permits unrestricted use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
Quickstart
pip install bbpb
import base64
data = base64.b64decode('KglNb2RpZnkgTWU=')
message, typedef = bbpb.decode_message(data)
message[5] = 'Modified Me'
encoded = bbpb.encode_message(message, typedef)
Verify before relying
- Accuracy of type inference for complex or ambiguous wire-type scenarios
- Performance characteristics when handling large or deeply nested messages
- Completeness of .proto file round-trip conversion (documentation notes limitations)
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release <4.0,>=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagesix |
| Maintenance | Actively maintained 518 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 188,177 / month, #9,950 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: bbpb-1.4.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “protobuf decode without schema”
- bbpbDecode and re-encode Protocol Buffer messages without access to the…
- protobuf-decoderDecodes protobuf binary messages without requiring proto schema…
- pbtoolsGenerates C source code from Protocol Buffer proto3 definitions and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also ldfparser · protobuf-decoder · proto-plus · pure-protobuf · discord-protos · pbtools · cobs · geobuf · pbspark · baml-bridge