CBOR viewer
Decode CBOR (RFC 8949) binary data in your browser: major types 0–7, indefinite-length arrays, maps and strings, half-precision floats and tags (dates, big integers, nested CBOR) shown as a collapsible tree with type, byte length and offset.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Decoded value
Paste hex bytes to decode them
Selected node
JSON view
Byte strings are shown as h'…', tags are wrapped as { tag, value } and integers outside the safe range stay strings.
What this tool does
- Decode CBOR from an IoT device, a COSE message or WebAuthn data and turn a blob of hex back into a readable tree.
- Debug “the device is reporting something I cannot read”: locate each item by type, byte length and offset and check whether you misread the nesting level.
- Convert CBOR to JSON for further scripting while keeping tag information (a tag 1 timestamp becomes `{ tag, value }`).
- Verify your own encoder: indefinite-length containers, half-precision floats and the tag 2/3 big integers all decode correctly here.
Example
Input
a2 61 61 01 61 62 82 02 03
Output
{
"a": 1,
"b": [
2,
3
]
}This is the real decoded value: a2 starts a two-entry map, 61 61 is the one-byte text string "a", 01 is the integer 1, 61 62 is "b", 82 starts a two-item array and 02 03 are the integers 2 and 3 — 9 bytes and 5 nodes in total.
Frequently asked questions
Why does my data report “not valid CBOR”?
Three common causes: additional information set to the reserved values 28–30; a text string whose bytes are not valid UTF-8 (CBOR text must be UTF-8 — binary data belongs in a byte string); or truncated input. Also note that 0xFF (break) is only legal inside an indefinite-length container and is an error on its own.
What is the difference between a byte string and a text string?
In CBOR major type 2 is a byte string and major type 3 is a text string; the former holds arbitrary bytes, the latter must be valid UTF-8. The JSON view writes byte strings as `h'…'` hex because a JSON string cannot carry arbitrary bytes. Seeing h'…' means that item genuinely is binary, not that decoding failed.
How are tags shown?
A tag gets its own tree level showing the tag number, and in JSON it is wrapped as `{ tag: number, value: content }`. Well-known tags get a readable name: 0 is an RFC 3339 date string, 1 an epoch-based timestamp, 2 and 3 positive and negative bignums, and 24 nested CBOR data.
How does this compare with JSON parsing or the bencode decoder?
CBOR is a binary format that is more compact than JSON for the same data and supports types JSON lacks — byte strings, floats, tags — so it can express more. bencode is BitTorrent-specific with only four types and sorted dictionary keys. Use this for IoT, COSE or WebAuthn data and the bencode decoder for torrent files.
Does decoding touch the network?
No. The decoder runs entirely in your browser, the hex you paste never leaves the page, and no network requests are made.
Keywords:cborrfc 8949binarydecodehextagbignumCBOR 解码二进制解析序列化十六进制物联网