# Safetensors.mojo 0.7.0 — Safetensors in pure Mojo

**URL:** <https://forum.modular.com/t/safetensors-mojo-0-7-0-safetensors-in-pure-mojo/3479>\
**Category:** Community Showcase\
**Created:** [September 9, 2026, 12:38pm UTC](https://forum.modular.com/t/safetensors-mojo-0-7-0-safetensors-in-pure-mojo/3479 "2026-09-09T12:38:21Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![egor\_fyodorov](https://sea1.discourse-cdn.com/flex001/user_avatar/forum.modular.com/egor_fyodorov/32/1254_2.png) [@egor\_fyodorov](https://forum.modular.com/u/egor_fyodorov)\
**Post date:** [September 9, 2026, 12:38pm UTC](https://forum.modular.com/t/safetensors-mojo-0-7-0-safetensors-in-pure-mojo/3479/1 "2026-09-09T12:38:21Z")

</div>

Hi all,

I’ve been working on [safetensors.mojo](https://github.com/egor-fedorov/safetensors.mojo), a library for reading and writing Safetensors entirely in Mojo.

I wanted a way to work with model weights from native Mojo code without bringing in Python or a tensor runtime. The package’s only dependency is mojo-compiler.

Highlights:

- Single-file and sharded checkpoint readers, with support for standard .safetensors.index.json files or an explicit list of shard paths.
- Zero-copy memory-mapped access, including typed views whose lifetimes are tied to the mapping owner through Mojo’s origins.
- A deterministic single-file writer with atomic replacement.
- Linux x86-64, Linux ARM64 and macOS ARM64 support, built and tested in CI with Mojo 1.0.0.

A lot of the work has gone into validation and compatibility: checked arithmetic, duplicate-key detection, shard-index consistency and path handling. Tests include differential checks against the official Safetensors implementation, byte-for-byte writer comparisons, fuzzing, and programs that must fail to compile when borrowed views outlive their owner.

The [README](https://github.com/egor-fedorov/safetensors.mojo#performance) has examples and reproducible Mojo/Rust/Python benchmarks. Rust leads the measured workload; the practical benefit here is native Mojo access without CPython startup or imports.

Available as [safetensors-mojo in modular-community](https://prefix.dev/channels/modular-community/packages/safetensors-mojo), under Apache 2.0.

I’d love feedback from anyone working with checkpoints in Mojo. If a file fails to open, please open an issue with a reproducer. Slicing and tensor-runtime adapters aren’t implemented yet — which would be useful in your projects?

Independent community project, not affiliated with or endorsed by Hugging Face.
