Hi all,
I’ve been working on safetensors.mojo, a library for reading and writing Safetensors entirely in Mojo.
I wanted a way to work with model weights from native Mojo code without bringing in Python or a tensor runtime. The package’s only dependency is mojo-compiler.
Highlights:
- Single-file and sharded checkpoint readers, with support for standard .safetensors.index.json files or an explicit list of shard paths.
- Zero-copy memory-mapped access, including typed views whose lifetimes are tied to the mapping owner through Mojo’s origins.
- A deterministic single-file writer with atomic replacement.
- Linux x86-64, Linux ARM64 and macOS ARM64 support, built and tested in CI with Mojo 1.0.0.
A lot of the work has gone into validation and compatibility: checked arithmetic, duplicate-key detection, shard-index consistency and path handling. Tests include differential checks against the official Safetensors implementation, byte-for-byte writer comparisons, fuzzing, and programs that must fail to compile when borrowed views outlive their owner.
The README has examples and reproducible Mojo/Rust/Python benchmarks. Rust leads the measured workload; the practical benefit here is native Mojo access without CPython startup or imports.
Available as safetensors-mojo in modular-community, under Apache 2.0.
I’d love feedback from anyone working with checkpoints in Mojo. If a file fails to open, please open an issue with a reproducer. Slicing and tensor-runtime adapters aren’t implemented yet — which would be useful in your projects?
Independent community project, not affiliated with or endorsed by Hugging Face.