cbor2
CBOR (de)serializer with extensive tag support
Decision gist · record as of 2026-08-14
Yes. cbor2 is actively maintained, production-stable, has no known vulnerabilities, and provides a straightforward implementation of RFC 8949 with broad platform support. Install friction is moderate but manageable; wheels cover common platforms. Choose it if you need CBOR serialization with tag support and don't mind the Rust build requirement on unsupported platforms.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >= 3.10.
- If wheels are unavailable for your platform, you need Rust toolchain v1.93.0 or later to compile from source.
- Medium install friction due to Rust compilation requirement when wheels are unavailable.
License · maintenance · safety
MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal restrictions, making it suitable for both open-source and commercial projects.
last release 2026-08-01 (13 days) · last repo commit 2026-08-01 · 304 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 69,771,135 downloads/mo, #470 on PyPI
Alternatives
Verify before relying
import cbor2
# Encode a dictionary to CBOR bytes
data = {'hello': 'world'}
encoded = cbor2.dumps(data)
# Decode CBOR bytes back to Python object
decoded = cbor2.loads(encoded)- Performance characteristics and throughput compared to other CBOR implementations or serialization formats
- Memory overhead for large or deeply nested data structures
- Specific CBOR tag support coverage and any unsupported tags
What it is and what it does
cbor2 is a Python library that implements CBOR serialization and deserialization per RFC 8949. It provides a simple API similar to the standard json and pickle modules, allowing you to convert Python objects to compact binary format and back. The library is implemented in Rust for performance and supports a wide range of CBOR tags that map to standard library objects, shared value references (including cyclic structures), and string compression through reference indices.
The package includes both a programmatic API for use in applications and a command-line tool for diagnostic conversion of CBOR to JSON. It requires Python 3.10 or later and has no runtime dependencies. The library is actively maintained, marked as production-stable, and has been thoroughly tested on different architectures.
Use it for
- Serialize structured data for efficient storage or network transmission where binary size matters
- Decode CBOR-formatted messages from IoT devices, APIs, or other systems using RFC 8949
- Convert CBOR files to JSON for inspection and debugging using the command-line tool
- Handle cyclic or shared data structures that need compact binary representation
- Integrate CBOR support into applications requiring interoperability with CBOR-based protocols
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
cbor2 is actively maintained, production-stable, has no known vulnerabilities, and provides a straightforward implementation of RFC 8949 with broad platform support. Install friction is moderate but manageable; wheels cover common platforms. Choose it if you need CBOR serialization with tag support and don't mind the Rust build requirement on unsupported platforms.
Install
cbor2 on PyPI
Before you install
Medium install friction due to Rust compilation requirement when wheels are unavailable. The package is actively maintained with recent releases, supports current Python versions (3.10+), and has no known vulnerabilities. Wheels are available for common platforms and architectures.
Requires Python >= 3.10. If wheels are unavailable for your platform, you need Rust toolchain v1.93.0 or later to compile from source.
License in practice
MIT license permits unrestricted use, modification, and distribution with minimal restrictions, making it suitable for both open-source and commercial projects.
Quickstart
import cbor2
# Encode a dictionary to CBOR bytes
data = {'hello': 'world'}
encoded = cbor2.dumps(data)
# Decode CBOR bytes back to Python object
decoded = cbor2.loads(encoded)
Verify before relying
- Performance characteristics and throughput compared to other CBOR implementations or serialization formats
- Memory overhead for large or deeply nested data structures
- Specific CBOR tag support coverage and any unsupported tags
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 13 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 69,771,135 / month, #470 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.15Programming Language :: Python :: Free Threading :: 2 - BetaProgramming Language :: RustTyping :: Typed |
Evidence: cbor2-6.1.4-cp310-cp310-macosx_11_0_arm64.whl; cbor2-6.1.4-cp310-cp310-manylinux_2_28_aarch64.whl; cbor2-6.1.4-cp310-cp310-manylinux_2_28_x86_64.whl; cbor2-6.1.4-cp310-cp310-musllinux_1_2_aarch64.whl; cbor2-6.1.4-cp310-cp310-musllinux_1_2_x86_64.whl; cbor2-6.1.4-cp310-cp310-win32.whl; cbor2-6.1.4-cp310-cp310-win_amd64.whl; cbor2-6.1.4-cp310-cp310-win_arm64.whl; cbor2-6.1.4-cp311-cp311-macosx_11_0_arm64.whl; cbor2-6.1.4-cp311-cp311-manylinux_2_28_aarch64.whl; cbor2-6.1.4-cp311-cp311-manylinux_2_28_x86_64.whl; cbor2-6.1.4-cp311-cp311-musllinux_1_2_aarch64.whl; cbor2-6.1.4-cp311-cp311-musllinux_1_2_x86_64.whl; cbor2-6.1.4-cp311-cp311-win32.whl; cbor2-6.1.4-cp311-cp311-win_amd64.whl; cbor2-6.1.4-cp311-cp311-win_arm64.whl; cbor2-6.1.4-cp312-cp312-macosx_11_0_arm64.whl; cbor2-6.1.4-cp312-cp312-manylinux_2_28_aarch64.whl; cbor2-6.1.4-cp312-cp312-manylinux_2_28_x86_64.whl; cbor2-6.1.4-cp312-cp312-musllinux_1_2_aarch64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “cbor serialization deserialization”
- cbor2Encodes and decodes CBOR (Concise Binary Object Representation) data…
- cborSerializes and deserializes data in CBOR (Concise Binary Object…
- smpSerializes and deserializes the Simple Management Protocol (SMP),…
Give your agent the search over MCP, or paste the wish link into any chat.
Similar packages
Implements the Borsh binary serialization format for Python, enabling secure and consistent serialization of data structures for hashing and cryptographic applications.
zcbor validates and converts YAML/JSON/CBOR data against CDDL schemas, and generates C code for encoding/decoding CBOR data with schema validation.
Install it if you need schema-driven CBOR handling in Python or C; skip it if you work exclusively with JSON or don't require CDDL's advanced schema features.
Encodes and decodes Base64 data without RFC 4648 padding characters, supporting protocols that omit the trailing "=" bytes.
However, for new projects, consider whether the standard library base64 module with manual padding removal would suffice, since this package will not receive updates.
Canoser implements canonical serialization for Libra network data structures, enabling byte-consistent encoding and decoding of Python objects that can be safely compared across independent implementations.
BinaPy wraps Python's binary-handling libraries (hashlib, base64, zlib, urllib.parse, json, pickle) into a fluent, chainable interface for encoding, decoding, compressing, and hashing data.
Encodes and decodes binary data using Base2048, a character encoding that fits up to 11 bits per Unicode character, reducing encoded size compared to Base64.
However, do not use it if you require active maintenance or security updates—it has not been updated since 2022 and the maintainer is no longer active.
See also cbor · xdrlib3 · py-multibase · mda-xdrlib