28

Zstandard file signature

Magic number at the start of the file

28 B5 2F FD

Zstandard frames begin with the little-endian magic 28 B5 2F FD. Zstd is a fast modern compressor used for package archives, filesystem compression and .tar.zst bundles.

Hex signature
28 B5 2F FD
Offset
0 (start of file)
Length
4 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 28 B5 2F FD, it is a Zstandard file.

Formats that use the 28 B5 2F FD signature

These file types in our database carry this signature:

It is also seen in: TZST.

How to check a file's signature

You can read the first bytes of any file yourself. The magic bytes are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.zst
  • hexdump -C -n 16 example.zst
  • file example.zst

Windows (PowerShell)

  • Format-Hex -Path example.zst -Count 16

Python

  • open("example.zst","rb").read(4).hex()

In your browser

Frequently asked questions

What is the Zstandard file signature?

Zstandard files start with the hex bytes 28 B5 2F FD. This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.zst on Linux or macOS, or Format-Hex -Path example.zst -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the Zstandard signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine Zstandard file has these exact bytes; a file with the wrong bytes is not really Zstandard, whatever its name says.

Related signatures

Sources