Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Go
  3. cbor

cbor

MITGov2.9.4

A secure, fast, and feature-rich CBOR codec for Go, fully compliant with RFC 8949 and RFC 8742.

GitHubGitHub
1.1k stars86 forks0 contributors

What is cbor?

fxamacker/cbor is a comprehensive CBOR (Concise Binary Object Representation) encoding and decoding library for Go. It provides a robust, high-performance alternative to JSON and other binary formats, designed with a strong emphasis on security, speed, and standards compliance. The library is trusted by major organizations and used in critical systems.

Target Audience

Go developers working on systems that require secure, efficient binary data interchange, such as IoT, blockchain, authentication protocols (e.g., WebAuthn), and distributed systems. It is also suitable for projects needing standards-compliant CBOR handling with configurable security limits.

Value Proposition

Developers choose fxamacker/cbor for its security-first design with configurable decoding limits and fast rejection of malformed data, high performance without using Go's unsafe package, and comprehensive standards compliance including CBOR, CBOR Sequences, and Extended Diagnostic Notation. Its API is familiar to users of encoding/json, and it offers struct tag optimizations to automatically reduce encoded size.

Overview

CBOR codec (RFC 8949, RFC 8742) with CBOR tags, Go struct tag options (toarray, keyasint, omitempty, omitzero), float64/32/16, big.Int, and fuzz tested.

Use Cases

Best For

  • Building secure systems that need to defend against adversarial inputs, as it provides configurable decoding limits and fast rejection of malformed CBOR data.
  • Implementing CBOR-based protocols like WebAuthn (CTAP2) or COSE, which require specific encodings such as CTAP2 Canonical CBOR available as presets.
  • Reducing network payload sizes in Go applications, thanks to struct tag options like toarray, keyasint, omitempty, and omitzero that automatically shrink encoded data.
  • High-performance concurrent applications, because its encoding and decoding modes are immutable and safe for reuse across goroutines.
  • Systems requiring interoperability with CBOR Sequences (RFC 8742) or Extended Diagnostic Notation, as the library fully supports these standards.
  • Projects that need extensible CBOR tag handling, as it supports built-in and user-defined tags via customizable TagSets and Marshaler/Unmarshaler interfaces.

Not Ideal For

  • TinyGo projects requiring production-ready CBOR support, as compatibility is experimental and not fully fuzzed.
  • Teams that prioritize human-readable data formats for debugging and have no binary size or performance constraints.
  • Applications deeply integrated with Go's encoding/gob or other serialization libraries where switching costs outweigh benefits.
  • Prototypes or simple tools where the overhead of configuring CBOR settings and struct tags isn't justified.

Pros & Cons

Pros

Security-First Design

Configurable decoding limits and fast rejection of malformed data defend against adversarial inputs, with benchmarks showing it rejects malicious CBOR in 47 ns/op compared to millions for other libraries.

High Performance Without Unsafe

Optimized for speed and memory efficiency without relying on Go's unsafe package, making it safe for concurrent use in production systems.

Standards Compliance

Full support for CBOR RFC 8949, CBOR Sequences RFC 8742, and Extended Diagnostic Notation, ensuring interoperability with other CBOR implementations.

Struct Tag Optimizations

Tags like toarray, keyasint, omitempty, and omitzero automatically reduce encoded size, as shown where a nested struct encodes to 1 byte versus 18 bytes for JSON.

Familiar API

API mirrors encoding/json with functions like Marshal and Unmarshal, reducing the learning curve for Go developers.

Cons

Configuration Complexity

Advanced features require understanding DecOptions and EncOptions, and setting up custom modes or tag sets can be non-trivial, especially for users new to CBOR.

CBOR-Specific Knowledge Needed

Effective use demands familiarity with CBOR standards, tags, and struct tags, which may be a barrier compared to ubiquitous formats like JSON.

Experimental TinyGo Support

TinyGo compatibility is in a beta branch, not fully fuzzed, and has reduced default limits, making it risky for critical TinyGo applications.

Limited Ecosystem

As a CBOR library, it has a smaller community and tooling than JSON, which can affect finding resources or third-party integrations for niche use cases.

Frequently Asked Questions

Quick Stats

Stars1,093
Forks86
Contributors0
Open Issues29
Last commit1 day ago
CreatedSince 2019

Tags

#json-alternative#go-library#binary-encoding#cbor#security#data-interchange#golang#codec#serialization#go#cwt#struct-tags#performance

Built With

G
Go

Included in

Go169.1k
Auto-fetched 1 day ago

Related Projects

jsoniterjsoniter

A high-performance 100% compatible drop-in replacement of "encoding/json"

Stars13,865
Forks1,054
Last commit2 years ago
goprotobufgoprotobuf

Go support for Google's protocol buffers

Stars10,077
Forks1,569
Last commit21 days ago
go-codecgo-codec

idiomatic codec and rpc lib for msgpack, cbor, json, etc. msgpack.org[Go]

Stars1,967
Forks315
Last commit1 month ago
csvutilcsvutil

csvutil provides fast and idiomatic mapping between CSV and Go (golang) values.

Stars1,036
Forks70
Last commit1 year ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub