Safetensors.mojo 0.7.0 — Safetensors in pure Mojo

Hi all,

I’ve been working on safetensors.mojo, a library for reading and writing Safetensors entirely in Mojo.

I wanted a way to work with model weights from native Mojo code without bringing in Python or a tensor runtime. The package’s only dependency is mojo-compiler.

Highlights:

  • Single-file and sharded checkpoint readers, with support for standard .safetensors.index.json files or an explicit list of shard paths.
  • Zero-copy memory-mapped access, including typed views whose lifetimes are tied to the mapping owner through Mojo’s origins.
  • A deterministic single-file writer with atomic replacement.
  • Linux x86-64, Linux ARM64 and macOS ARM64 support, built and tested in CI with Mojo 1.0.0.

A lot of the work has gone into validation and compatibility: checked arithmetic, duplicate-key detection, shard-index consistency and path handling. Tests include differential checks against the official Safetensors implementation, byte-for-byte writer comparisons, fuzzing, and programs that must fail to compile when borrowed views outlive their owner.

The README has examples and reproducible Mojo/Rust/Python benchmarks. Rust leads the measured workload; the practical benefit here is native Mojo access without CPython startup or imports.

Available as safetensors-mojo in modular-community, under Apache 2.0.

I’d love feedback from anyone working with checkpoints in Mojo. If a file fails to open, please open an issue with a reproducer. Slicing and tensor-runtime adapters aren’t implemented yet — which would be useful in your projects?

Independent community project, not affiliated with or endorsed by Hugging Face.

2 Likes