marshmallow
A lightweight library for converting complex datatypes to and from native Python datatypes.
Decision gist · record as of 2026-08-14
Yes. Marshmallow is a mature, actively maintained library with low install friction, no known vulnerabilities, and permissive licensing. It solves a common problem (structured data conversion and validation) in a clean, declarative way. Install it if you're building APIs, handling external data, or need schema-based validation anywhere in your stack.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low install friction with only two runtime dependencies (backports-datetime-fromisoformat, typing-extensions).
- Active maintenance with a release 6 days ago and consistent commit activity; production-stable status since early releases.
License · maintenance · safety
MIT (permissive) — MIT license is permissive, allowing use in commercial and proprietary projects with minimal restrictions beyond attribution.
last release 2026-08-08 (6 days) · last repo commit 2026-08-09 · 7,241 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 125,436,071 downloads/mo, #296 on PyPI
Alternatives
Verify before relying
from marshmallow import Schema, fields
class ArtistSchema(Schema):
name = fields.Str()
schema = ArtistSchema()
result = schema.dump({"name": "David Bowie"})
print(result) # {'name': 'David Bowie'}- Whether the package handles circular references or deeply nested object graphs without performance degradation.
- Support for custom field types beyond the built-in set and extensibility patterns for domain-specific serialization.
What it is and what it does
Marshmallow is a schema-based library for converting between complex Python objects and primitive datatypes. It decouples serialization logic from your application's data models, making it useful across ORMs, ODMs, and frameworks. The core workflow involves defining a Schema class with typed fields, then calling dump() to serialize objects to dictionaries or load() to deserialize and validate incoming data.
The library handles nested objects, custom field types, and validation rules declaratively. It's commonly used to build HTTP APIs where you need to accept JSON input, validate it against a schema, convert it to application objects, and serialize responses back to JSON. Its framework-agnostic design means it works equally well with Flask, Django, FastAPI, or standalone scripts.
Use it for
- Build REST APIs that accept and return JSON with automatic validation and type conversion.
- Deserialize API responses or database records into application objects with schema-enforced structure.
- Validate user input against a schema before processing or storing in a database.
- Serialize application objects to JSON for HTTP responses or external integrations.
- Define reusable data contracts between frontend and backend or between microservices.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Marshmallow is a mature, actively maintained library with low install friction, no known vulnerabilities, and permissive licensing. It solves a common problem (structured data conversion and validation) in a clean, declarative way. Install it if you're building APIs, handling external data, or need schema-based validation anywhere in your stack.
Install
marshmallow on PyPI
Before you install
Low install friction with only two runtime dependencies (backports-datetime-fromisoformat, typing-extensions). Active maintenance with a release 6 days ago and consistent commit activity; production-stable status since early releases.
Requires Python 3.10 or later.
License in practice
MIT license is permissive, allowing use in commercial and proprietary projects with minimal restrictions beyond attribution.
Quickstart
from marshmallow import Schema, fields
class ArtistSchema(Schema):
name = fields.Str()
schema = ArtistSchema()
result = schema.dump({"name": "David Bowie"})
print(result) # {'name': 'David Bowie'}
Verify before relying
- Whether the package handles circular references or deeply nested object graphs without performance degradation.
- Support for custom field types beyond the built-in set and extensibility patterns for domain-specific serialization.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesbackports-datetime-fromisoformattyping-extensions |
| Maintenance | Actively maintained 6 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 125,436,071 / month, #296 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: marshmallow-4.3.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “convert objects to primitives”
- marshmallowMarshmallow converts complex Python objects to and from native Python…
- atomosAtomos provides thread-safe atomic primitives (integers, floats,…
- pyserdeSerialize and deserialize Python dataclasses to and from JSON, YAML,…
Give your agent the search over MCP, or paste the wish link into any chat.
Similar packages
Accelerates Marshmallow schema serialization and deserialization by generating optimized code at runtime, achieving 3-5x speedup over vanilla Marshmallow without changing the API.
However, the aging maintenance status (10 stars, last commit 2025-09-03) and modest adoption signal mean you should verify compatibility with your Marshmallow version…
Flask-Marshmallow integrates Flask and marshmallow to serialize/deserialize Python objects into JSON with built-in support for URL generation and HATEOAS hyperlinking in APIs.
Install it if you're building a Flask API and want declarative schemas with built-in HATEOAS support.
Produces JSON API 1.0-compliant output from Python objects using marshmallow schemas, with built-in support for relationships, resource linkage, and typed resources.
Generates marshmallow schemas from SQLAlchemy models to serialize and deserialize database objects to and from JSON or other formats.
Install it if you're building APIs or services that need to serialize SQLAlchemy models.
Extends Marshmallow with a PolyField class that handles serialization and deserialization of polymorphic types by selecting the appropriate schema based on the object's runtime type.
However, it has been dormant since 2022-10-26 with no active maintenance—install only if you can tolerate potential incompatibilities with future Marshmallow releases.
Adds union field support to marshmallow, allowing a single field to deserialize and serialize values that match any of several candidate field types.
See also marshmallow-oneofschema · marshmallow-mongoengine · amundsen-common · webargs