Favicon of safetensors

safetensors

An open-source tensor format and library for storing model weights safely, with Rust and Python support, partial loading, and an Apache 2.0 license.

Screenshot of safetensors website

Safetensors is a file format and library for developers who store, share, or load AI model weights on their own hardware or servers. It avoids the arbitrary code execution risk of PyTorch's pickle-based files while supporting fast access to tensor data. The project is open source under Apache 2.0, with a Rust implementation and Python support.

Its focus is tensor storage. You can load individual tensors or slices without reading every weight into memory, which is useful when splitting a model across multiple GPUs. The format supports bfloat16 and FP8 data and doesn't impose a file size limit.

CPU loading can use cached file data without an extra copy of the tensor contents. GPU loading still requires a copy, but it can avoid holding all tensors in CPU memory at once. These distinctions matter for developers comparing formats for large models: the benefit depends on where the weights are loaded and whether the file is already cached.

Safetensors fits into existing local AI software. Projects using it include Transformers, MLX, Diffusers, ComfyUI, and text-generation-webui, so it serves both language model and image generation workflows.

The format stores tensor names, shapes, and data types in a readable JSON header alongside the tensor data. It limits header size and checks that tensor data regions don't overlap to reduce risks from malicious files. It also supports string metadata, while requiring tensors to be packed before saving.

Similar to safetensors