zcbor
Code generation and data validation using CDDL schemas
Decision gist · record as of 2026-08-14
Yes. zcbor fills a specific niche—CDDL-based CBOR validation and C code generation—with low install friction, active maintenance, no known vulnerabilities, and a permissive license. Install it if you need schema-driven CBOR handling in Python or C; skip it if you work exclusively with JSON or don't require CDDL's advanced schema features.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >= 3.8; generated C code depends on the bundled C library included in the package.
- Low friction install as a pure Python wheel.
- Actively maintained with recent commits and a stable release cadence; last release was 666 days ago with active repository status.
License · maintenance · safety
Apache (permissive) — Apache permissive license allows commercial and private use with minimal restrictions, suitable for most projects including those generating proprietary C code.
last release 2024-10-17 (666 days) · last repo commit 2026-08-03 · 165 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 383,063 downloads/mo, #7,082 on PyPI
Alternatives
Verify before relying
pip install zcbor
import zcbor
# Validate YAML/JSON/CBOR against a CDDL schema
zcbor.validate(data, schema_file)
# Or generate C code: zcbor code-gen schema.cddl --output-c- Whether the bundled C library requires compilation or system dependencies on target platforms
- Performance characteristics when validating large CBOR datasets
- Completeness of CDDL RFC 8610 feature coverage
What it is and what it does
zcbor is a CDDL schema processor that works in two modes: as a validator for YAML, JSON, and CBOR data, and as a code generator that produces C implementations for encoding and decoding CBOR according to a schema. The package includes a C library (also used standalone in Zephyr RTOS) that handles the low-level CBOR operations; when you generate C code, zcbor either references this library via CMake or copies its sources to your project.
The tool targets developers working with CBOR serialization who need either runtime validation in Python or embedded C implementations. CDDL (Concise Data Definition Language, RFC 8610) provides a powerful schema syntax for defining complex binary data structures, making zcbor useful for IoT, embedded systems, and any project where CBOR is the wire format.
Use it for
- Validate incoming CBOR messages against a schema before processing in a Python service.
- Generate C code for CBOR encoding/decoding in embedded or IoT firmware projects.
- Convert between YAML/JSON and CBOR formats with schema-enforced validation.
- Define and validate complex binary protocols using CDDL schemas.
- Integrate CBOR serialization into Zephyr RTOS or other embedded systems via the C library.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
zcbor fills a specific niche—CDDL-based CBOR validation and C code generation—with low install friction, active maintenance, no known vulnerabilities, and a permissive license. Install it if you need schema-driven CBOR handling in Python or C; skip it if you work exclusively with JSON or don't require CDDL's advanced schema features.
Install
zcbor on PyPI
Before you install
Low friction install as a pure Python wheel. Actively maintained with recent commits and a stable release cadence; last release was 666 days ago with active repository status.
Requires Python >= 3.8; generated C code depends on the bundled C library included in the package.
License in practice
Apache permissive license allows commercial and private use with minimal restrictions, suitable for most projects including those generating proprietary C code.
Quickstart
pip install zcbor
import zcbor
# Validate YAML/JSON/CBOR against a CDDL schema
zcbor.validate(data, schema_file)
# Or generate C code: zcbor code-gen schema.cddl --output-c
Verify before relying
- Whether the bundled C library requires compilation or system dependencies on target platforms
- Performance characteristics when validating large CBOR datasets
- Completeness of CDDL RFC 8610 feature coverage
Package facts
| License | Apache permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagescbor2pyyamlregex |
| Maintenance | Actively maintained 666 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 383,063 / month, #7,082 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: CProgramming Language :: Python :: 3Topic :: File Formats :: JSON :: JSON SchemaTopic :: Software Development :: Build ToolsTopic :: Software Development :: Code Generators |
Evidence: zcbor-0.9.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “CBOR schema validation”
- zcborzcbor validates and converts YAML/JSON/CBOR data against CDDL…
- cborSerializes and deserializes data in CBOR (Concise Binary Object…
- cbor2Encodes and decodes CBOR (Concise Binary Object Representation) data…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also cbor2 · cbor · kcidb-io · yamale · kubernetes-validate · avro-validator · annotatedyaml · check-jsonschema · pykwalify · msgspec