Add your SAFETENSORS file
Drop one or more .safetensors files onto the converter above, or browse for them. They load into browser memory only — nothing is uploaded, so there is no size-based pricing and no server queue.
Converting a .safetensors font to .zip repackages the same glyphs and metrics for a different delivery target. Free, private, and validated — the file never leaves your browser.
Batch files can each use a different output. Nothing uploads for local conversions.
Working inputs include camera RAW, browser-local audio/video, PDF, CBZ/CBR comics, office documents, ebooks, markup, 3D models, structured text, images, and archives.Converting a .safetensors font to .zip repackages the same glyphs and metrics for a different delivery target. A .safetensors file stores machine-learning model weights: a JSON header naming each tensor with its dtype, shape and byte range, then the tensor data laid end to end. Its defining property is negative — loading one cannot execute code, which is precisely what loading a PyTorch .bin or .pt checkpoint can do.
A .zip file bundles files and folders into a single archive, compressing each entry individually. It is the only compression format that every major operating system can open and create without extra software, which is why .zip remains the default way to send multiple files. For this route the practical draw is opens natively on Windows, macOS, Linux, iOS, and Android and random access: any single entry extracts without decompressing the archive — balanced against weaker ratios than 7z or xz, especially across many small similar files, which is worth knowing before you commit a large batch.
The practical trigger for this conversion is usually a mismatch: with .safetensors, stores tensors only — no optimizer state, no model architecture, no training code. Switching to .zip buys you opens natively on Windows, macOS, Linux, iOS, and Android, which is why it is the better fit for emailing or sharing a batch of files as one attachment. Because the conversion runs locally, trying it costs nothing but a few seconds of compute on your own machine.
| Aspect | Safetensors model data (.safetensors) | ZIP archive (.zip) |
|---|---|---|
| Format type | Lossless — every pixel or sample is preserved exactly | Container — quality depends on the codecs and settings inside |
| How it stores data | the file opens with a little-endian uint64 giving the length of the JSON header | every entry is compressed independently, usually with DEFLATE, so a single file can be extracted without touching the rest |
| Strongest at | distributing model weights where users must not have to trust the publisher | emailing or sharing a batch of files as one attachment |
| Weak spot | stores tensors only — no optimizer state, no model architecture, no training code | weaker ratios than 7z or xz, especially across many small similar files |
| Metadata | tensor names, dtypes, shapes and the __metadata__ string map are all read and preserved into the JSON export and into the exported NumPy filenames | stores modification times at DOS 2-second resolution and, through the Unix extra field, permission bits — though Windows-made ZIPs usually omit those bits, a classic cause of scripts arriving non-executable |
Drop one or more .safetensors files onto the converter above, or browse for them. They load into browser memory only — nothing is uploaded, so there is no size-based pricing and no server queue.
Select .zip in the output menu next to each file. The menu only offers targets this engine can genuinely produce, so if ZIP is selectable, the route is real and validated.
Press Convert. The font tables are parsed and rewritten locally with fonteditor-core; glyph outlines, hinting, and kerning survive the trip.
Each result is signature-checked before the download unlocks, so a failed encode can never masquerade as a valid ZIP file. Outputs keep the original filename with the .zip extension.
Since safetensors is lossless-oriented and zip is container-oriented, the conversion preserves the source content exactly as stored; no additional compression pass is applied beyond what .zip itself requires.
Yes — the .safetensors file is processed inside your browser tab and never uploaded. The font tables are parsed and rewritten locally with fonteditor-core; glyph outlines, hinting, and kerning survive the trip. Close the tab and the file is gone from memory.
File Explorer has handled ZIP since Windows XP, Finder and the GNOME/KDE file managers extract it with a double-click, and iOS and Android manage it through their Files apps. No mainstream platform requires any third-party install for basic ZIP work.
It depends on the content: every entry is compressed independently, usually with DEFLATE, so a single file can be extracted without touching the rest. Convert one representative file first and compare before batch-processing a large set.
In .safetensors, tensor names, dtypes, shapes and the __metadata__ string map are all read and preserved into the JSON export and into the exported NumPy filenames. Re-encoding through the browser pipeline does not carry embedded metadata into the output, which doubles as a privacy scrub — check the exported file if you specifically need tags preserved.