rfc8785
A pure-Python implementation of RFC 8785 (JSON Canonicalization Scheme)
Decision gist · record as of 2026-08-14
Yes. The package solves a specific, well-defined problem (RFC 8785 compliance) with zero dependencies, active maintenance, no known vulnerabilities, and permissive licensing. Install it if you need deterministic JSON serialization for cryptography, signatures, or any use case where byte-for-byte reproducibility matters.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.8 or later; non-string dictionary keys must be explicitly converted to strings before serialization.
- Low friction: pure Python with no runtime dependencies, distributed as a wheel.
- Actively maintained with a recent commit history and no known vulnerabilities.
License · maintenance · safety
permissive license (permissive) — Permissive Apache License 2.0 allows commercial and private use with minimal restrictions; suitable for most projects.
last release 2024-09-27 (686 days) · last repo commit 2026-08-10 · 12 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 2,479,670 downloads/mo, #3,045 on PyPI
Alternatives
Verify before relying
import rfc8785
data = {"key": "value", "another": [1, 2, 3]}
canonical_bytes = rfc8785.dumps(data)
# Returns: b'{"another":[1,2,3],"key":"value"}'- Whether the package handles very large JSON structures efficiently or has memory/performance constraints.
- Compatibility with Python 3.13+ beyond the stated 'current' support window.
What it is and what it does
rfc8785 is a pure-Python implementation of RFC 8785, the JSON Canonicalization Scheme (JCS), which produces a single canonical byte representation of JSON data. It takes any JSON-serializable Python object and outputs UTF-8-encoded bytes in a deterministic form: keys are sorted alphabetically, whitespace is minimized, and the output is always identical for logically equivalent inputs. This is essential for cryptographic operations, digital signatures, and any scenario where you need byte-for-byte reproducible JSON.
The package has zero runtime dependencies and works with Python 3.8 or later. It provides two main APIs: `dumps()` for in-memory serialization and `dump()` for writing directly to a file-like object. All serialization failures raise `CanonicalizationError`. The implementation differs from Andrew Rundgren's reference implementation in three ways: it requires explicit string conversion for non-string dictionary keys, provides no pretty-printing options, and always outputs minimally encoded UTF-8 bytes.
Use it for
- Sign JSON data cryptographically by canonicalizing it first to ensure signatures remain valid across systems.
- Deduplicate JSON objects in a database or cache by comparing their canonical forms.
- Verify that two JSON structures are logically identical despite differences in formatting or key order.
- Build deterministic content hashes for JSON payloads in APIs or distributed systems.
- Implement JWS (JSON Web Signature) or other standards that require canonical JSON representation.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package solves a specific, well-defined problem (RFC 8785 compliance) with zero dependencies, active maintenance, no known vulnerabilities, and permissive licensing. Install it if you need deterministic JSON serialization for cryptography, signatures, or any use case where byte-for-byte reproducibility matters.
Install
rfc8785 on PyPI
Before you install
Low friction: pure Python with no runtime dependencies, distributed as a wheel. Actively maintained with a recent commit history and no known vulnerabilities.
Requires Python 3.8 or later; non-string dictionary keys must be explicitly converted to strings before serialization.
License in practice
Permissive Apache License 2.0 allows commercial and private use with minimal restrictions; suitable for most projects.
Quickstart
import rfc8785
data = {"key": "value", "another": [1, 2, 3]}
canonical_bytes = rfc8785.dumps(data)
# Returns: b'{"another":[1,2,3],"key":"value"}'
Verify before relying
- Whether the package handles very large JSON structures efficiently or has memory/performance constraints.
- Compatibility with Python 3.13+ beyond the stated 'current' support window.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 686 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 2,479,670 / month, #3,045 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Topic :: File Formats :: JSONTopic :: Security :: Cryptography |
Evidence: rfc8785-0.1.4-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “json canonicalization”
- rfc8785Implements RFC 8785 (JSON Canonicalization Scheme) to produce…
- jcsCanonicalizes JSON according to RFC 8785, producing a deterministic…
- canonicaljsonEncodes Python objects to canonical JSON with sorted keys, minimal…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also jcs · canonicaljson · urlcanon · cbor · canoser · cbor2 · slip10 · python-jsonpath · jsonpatch