flask-marshmallow
Flask + marshmallow for beautiful APIs
Decision gist · record as of 2026-08-14
Yes. Flask-Marshmallow is a mature, actively maintained library with no known vulnerabilities, minimal dependencies, and low install friction. It solves a common Flask use case (API serialization with validation) cleanly and is widely used (top 5000 packages by downloads). Install it if you're building a Flask API and want declarative schemas with built-in HATEOAS support.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low friction: pure Python wheel with only two runtime dependencies (Flask and marshmallow).
- Active maintenance with a recent release and no known vulnerabilities.
License · maintenance · safety
MIT (permissive) — MIT license is permissive; you can use, modify, and distribute this package freely with minimal restrictions.
last release 2026-04-16 (120 days) · last repo commit 2026-08-03 · 887 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,535,427 downloads/mo, #3,800 on PyPI
Alternatives
Verify before relying
pip install flask-marshmallow
from flask import Flask
from flask_marshmallow import Marshmallow
app = Flask(__name__)
ma = Marshmallow(app)
class UserSchema(ma.Schema):
email = ma.Email()
_links = ma.Hyperlinks({"self": ma.URLFor("user_detail", values=dict(id=""))})
user_schema = UserSchema()
data = user_schema.dump({"email": "test@example.com"})- Whether Flask-SQLAlchemy integration is automatic or requires additional setup beyond what the excerpt shows.
- Performance characteristics when serializing large collections or deeply nested schemas.
What it is and what it does
Flask-Marshmallow is a lightweight bridge between Flask and marshmallow that simplifies building JSON APIs. It extends marshmallow with Flask-specific fields like URLFor and Hyperlinks, making it straightforward to generate HATEOAS-compliant responses where API resources include links to related endpoints. You define schemas as classes, then call dump() or load() on request/response data to serialize objects to JSON or deserialize incoming JSON back into Python objects with validation.
The package is designed for developers building REST APIs who want declarative, reusable schema definitions with automatic URL generation. It has no external system dependencies, installs quickly, and integrates cleanly into existing Flask applications. Optional integration with Flask-SQLAlchemy is available for ORM-backed schemas.
Use it for
- Serialize database models to JSON responses with automatic hyperlinking to related endpoints.
- Validate and deserialize incoming JSON request bodies against defined schemas before processing.
- Generate HATEOAS-compliant API responses that include self and collection links.
- Define reusable output formats for multiple Flask routes sharing the same data model.
- Add email, datetime, and custom field validation to Flask request handlers.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Flask-Marshmallow is a mature, actively maintained library with no known vulnerabilities, minimal dependencies, and low install friction. It solves a common Flask use case (API serialization with validation) cleanly and is widely used (top 5000 packages by downloads). Install it if you're building a Flask API and want declarative schemas with built-in HATEOAS support.
Install
flask-marshmallow on PyPI
Before you install
Low friction: pure Python wheel with only two runtime dependencies (Flask and marshmallow). Active maintenance with a recent release and no known vulnerabilities.
Requires Python 3.10 or later.
License in practice
MIT license is permissive; you can use, modify, and distribute this package freely with minimal restrictions.
Quickstart
pip install flask-marshmallow
from flask import Flask
from flask_marshmallow import Marshmallow
app = Flask(__name__)
ma = Marshmallow(app)
class UserSchema(ma.Schema):
email = ma.Email()
_links = ma.Hyperlinks({"self": ma.URLFor("user_detail", values=dict(id=""))})
user_schema = UserSchema()
data = user_schema.dump({"email": "test@example.com"})
Verify before relying
- Whether Flask-SQLAlchemy integration is automatic or requires additional setup beyond what the excerpt shows.
- Performance characteristics when serializing large collections or deeply nested schemas.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesFlaskmarshmallow |
| Maintenance | Actively maintained 120 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,535,427 / month, #3,800 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: Web EnvironmentIntended Audience :: DevelopersNatural Language :: EnglishProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Internet :: WWW/HTTP :: Dynamic Content |
Evidence: flask_marshmallow-1.5.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “flask api serialization”
- flask-marshmallowFlask-Marshmallow integrates Flask and marshmallow to…
- APIFlaskAPIFlask is a lightweight web API framework that extends Flask with…
- flask-apispecflask-apispec decorates Flask view functions and classes to…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also amundsen-common · Flask-JSON · marshmallow · marshmallow-jsonapi · marshmallow-union · APIFlask · marshmallow-jsonschema · marshmallow-sqlalchemy · marshmallow-oneofschema · webargs