pyasn1

Pure-Python implementation of ASN.1 types with BER, CER, and DER serialization codecs.

Library
PyPI
v0.6.4
53 stars
BSD-2-Clause

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
55 /100 Fair
Development Activity 48
Maintenance 44
Community 52
Maturity 56
Momentum 20

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
73 /100 Good
Architecture 85
Code Quality 82
Innovation 55
Learning Curve 70

pyasn1 gives Python programs a way to work with ASN.1 (X.208) data structures as native Python objects, then serialize and deserialize them using the BER, CER, and DER encoding rules. Rather than hand-rolling byte-level parsing for protocols and file formats that rely on ASN.1 — X.509 certificates, SNMP, LDAP, Kerberos, and many others — pyasn1 lets you declare typed classes (Sequence, Integer, OctetString, and so on) that mirror ASN.1 module definitions and handle the wire format underneath.

The library is a foundational, low-level dependency: it doesn’t ship protocol-specific modules itself, but higher-level packages like pyasn1-modules, pyOpenSSL, and rsa build directly on it to decode certificates and cryptographic structures. Its value is in doing the fiddly, standards-compliant encoding work once, correctly, so every downstream protocol implementation doesn’t have to.

What You Get

  • A full set of ASN.1 type classes (Integer, OctetString, Sequence, Set, Choice, Any, and more) that behave like their closest Python built-in equivalents
  • BER, CER, and DER encoder/decoder modules for turning typed objects into wire bytes and back
  • A native codec that converts pyasn1 objects to and from plain Python dicts/lists for interop with JSON-style tooling
  • Constraint and named-type machinery (NamedType, OptionalNamedType, DefaultedNamedType, ConstraintsIntersection) for expressing ASN.1 module semantics precisely in Python
  • Streaming-capable decoding so large substrates can be processed incrementally rather than loaded fully into memory

Common Use Cases

  • Parsing and validating X.509 certificates and certificate chains before handing them to a TLS/crypto library
  • Implementing or debugging SNMP agents and managers that exchange BER-encoded PDUs
  • Decoding LDAP or Kerberos protocol messages that are defined via ASN.1 modules
  • Building a custom protocol compiler or codec on top of a compliant, well-tested ASN.1 type system instead of writing one from scratch

Under The Hood

Architecture pyasn1 splits cleanly into a type system (pyasn1/type/: base.py, univ.py, char.py, useful.py, namedtype.py, tag.py, constraint.py, tagmap.py) and a set of codecs (pyasn1/codec/{ber,cer,der,native}/) that operate purely against that type system’s public interface. Every ASN.1 value — scalar or constructed — is an Asn1Type subclass carrying its own tagSet and subtypeSpec, so a codec never needs protocol-specific knowledge: encoding and decoding are dispatched generically off the type’s tag and constraints. CER and DER encoders subclass and override only the parts of the BER encoder where their encoding rules diverge, keeping the three codecs in a clear specialization hierarchy rather than three parallel implementations. codec/streaming.py lets decoding consume a file-like stream instead of a fully materialized buffer, so the core abstraction change that would ripple furthest is the Asn1Type/tagSet contract itself — everything else, including every codec, is built on top of it.

Tech Stack The library has zero runtime dependencies and targets Python 3.8+ (per pyproject.toml), built with a standard setuptools backend and dynamic versioning sourced from pyasn1/__init__.py. It ships wheels via a dedicated pypi.yml GitHub Actions workflow, is tested across CPython 3.8-3.14 and PyPy through tox.ini, and is scanned with bandit and GitHub’s CodeQL for security issues. There is no build-time compiled extension — the whole codec stack is pure Python, which is also why the README calls out MT-safety and portability across interpreters.

Code Quality Tests live under tests/, mirroring the pyasn1/ package layout (tests/type/, tests/codec/{ber,cer,der,native}/) with 34 test modules built on unittest via a shared BaseTestCase, run with -Werror so warnings fail the suite, and gated at a minimum 80% coverage threshold in the cover tox environment. Exceptions are modeled as a real hierarchy (PyAsn1Error and its subclasses like ValueConstraintError, SubstrateUnderrunError, PyAsn1UnicodeDecodeError) rather than bare Exception or silently-swallowed errors, and each carries structured context for debugging. Naming favors explicit, descriptive method names (isSameTypeWith, isSuperTypeOf) over abbreviation, and CI runs the full matrix on every push.

What Makes It Unique pyasn1’s value isn’t a novel algorithm — ASN.1 and its encoding rules are a 40-year-old ITU standard — but it is the de facto reference implementation for doing that standard correctly in pure Python, with no native extension to compile or vendor. That reliability is precisely why it sits as a transitive dependency underneath much of the Python cryptography and networking ecosystem: correctness and standards compliance here get reused everywhere else rather than reimplemented per project.

Used by 9 apps in this directory

Python
100%
Apache 2.0

Agno

AI Development · Automation · Devops

42,358

Build, run, and manage agent platforms with a full production stack — SDK, runtime, and control plane included.

View details
93
Repo Health
87
Technical
66
Dependency
Built with
Python 100%
Updated 4 days ago
TypeScript
91%
Apache 2.0

Helicone

AI Development · Analytics · Monitoring

6,182

An open-source AI gateway and LLM observability platform that routes requests to 100+ models while logging cost, latency, and full traces for every call.

View details
70
Repo Health
81
Technical
65
Dependency
Built with
TypeScript 91%
Updated 2 weeks ago
Python
51%
AGPL 3.0

Khoj

AI Assistants · Knowledge Management · Productivity

37,526

A self-hostable AI second brain that chats with your documents, searches the web, builds custom agents, and runs entirely on your own LLM.

View details
63
Repo Health
82
Technical
66
Dependency
Built with
Python 51%
TypeScript 36%
Updated 2 months ago
Python
69%
MIT

Langflow

AI Agents · AI Development

155,319

Build, test, and deploy AI agents and RAG workflows visually with native API and MCP server export.

View details
90
Repo Health
85
Technical
65
Dependency
Built with
Python 69%
TypeScript 22%
Updated 4 days ago
TypeScript
51%
Other

Phase Console

Devops · Security

924

End-to-end encrypted secrets management for engineering teams — from local dev to Kubernetes production.

View details
84
Repo Health
73
Technical
63
Dependency
Built with
TypeScript 51%
Python 48%
Updated 5 days ago
Python
78%
AGPL 3.0

Skyvern

AI Agents · Automation

23,088

Skyvern (YC S2023) automates browser-based workflows by pairing LLMs with computer vision, letting agents click, fill, and extract data on sites they've never seen, without brittle XPath selectors that break on every layout change.

View details
89
Repo Health
82
Technical
70
Dependency
Built with
Python 78%
TypeScript 20%
Updated 4 days ago
Python
94%
Apache 2.0

SWIRL

Data Engineering · Databases · Search

3,047

Federated AI search and RAG across 100+ enterprise sources—no data extraction, no vector database required.

View details
62
Repo Health
83
Technical
65
Dependency
Built with
Python 94%
Updated 6 days ago
Python
91%
GPL 3.0

Weblate

Developer Tools

6,094

Continuous localization platform that commits translations directly into your version control system with full translator attribution.

View details
95
Repo Health
86
Technical
67
Dependency
Built with
Python 91%
Updated 4 days ago
Python
65%
Apache 2.0

WrenAI

AI Agents · Analytics · Data Engineering

17,763

Open-source GenBI engine that lets AI agents turn natural-language questions into governed SQL, charts, and shareable dashboards across 20+ data sources — no vendor lock-in, no black-box prompts.

View details
90
Repo Health
91
Technical
69
Dependency
Built with
Python 65%
Rust 32%
Updated 1 weeks ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers