Kafka Protobuf Binary Decoder

Decode a protobuf payload, with a .proto or without one. The wire format carries field numbers and wire types, so the structure is always readable. Where a field could be a string, bytes, an embedded message or a packed array, every reading is listed rather than one being guessed.

Leave the schema empty for a structural decode, which is the useful case when you have bytes off a topic and cannot find the .proto. The payload accepts base64, hex or a decimal byte array.

Paste below, or drop a file anywhere on this panel

Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.

The answer appears here

Paste on the left and press Decode. Nothing leaves this tab.

Examples

Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.

Schemaless decode

Every reading the wire format admits for these bytes, because a field tag alone does not fix the type

089601120548656c6c6f

A nested message

A length-delimited field that could be a string, bytes or a sub-message

0a0508961612 03616263

Common mistakes

These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

  1. Assuming a field tag identifies the type

    The wire type distinguishes varint from length-delimited and nothing more. A length-delimited field could be a string, bytes, a packed array or a nested message.

    Instead:Decode with the .proto, or read every possible interpretation, which is what this page shows.

  2. Expecting an unknown field to be an error

    Protobuf ignores unknown fields by design, which is what makes it forward compatible. A typo in a field number is silently dropped.

    Instead:Check the field numbers against the schema.

  3. Reading a negative int32 as a small number

    A negative value encoded as int32 uses ten bytes, because it is sign-extended. sint32 uses zigzag and is much smaller.

    Instead:Use sint32 or sint64 for values that are often negative.

Protobuf bytes are partially self-describing, which is why this works with no schema

Every field is prefixed with a tag holding its field number and one of five wire types, so a payload can be walked with no .proto at all. What the tag does not say is the declared type, and that is where the honesty has to come in.

One wire type, four possible readings, and the bytes do not choose

Wire type 2 is shared by string, bytes, every embedded message and every packed repeated field. The three bytes 08 96 01 are both the message {1: 150} and a perfectly ordinary byte string, and nothing in the encoding distinguishes them. This page lists every reading a field admits instead of picking one, because picking one is what produces the confident nonsense that other decoders are known for. Wire type 0 has the same problem more mildly: int32, int64, uint32, uint64, sint32, sint64, bool and every enum share it, so the value is shown read every way at once.

The five bytes in front, and the array after them

A value from Confluent's serialiser starts with a zero magic byte and a four-byte big-endian schema id. For protobuf, and only for protobuf, a message-index array follows that, so the payload begins at byte 5 plus the array rather than at byte 5. Reading from byte 5 leaves the array in front of the payload, which is exactly the decode that comes out garbage by a few bytes. This page detects both and reports the id so the registry can be asked for the schema.

curl -s http://registry:8081\
  /schemas/ids/42 | jq -r .schema

Sign extension is where hand-decoding goes wrong

An int32 holding -1 is widened to 64 bits before encoding, so it occupies ten bytes rather than the five somebody counting bits expects. A buffer truncated inside one of those runs is the usual cause of a last field that reads as nonsense. Values are decoded as arbitrary-precision integers rather than as JavaScript numbers, because a uint64 runs to 18446744073709551615 and a double stops being exact at 2^53.

Stopping early is the diagnosis, not a crash

When the walk cannot read a byte it reports what it read, where it stopped and how much was left, because that is usually the answer: a length that runs past the end of the buffer means either the payload is truncated or the offset it was read from is wrong. Fields decoded before the fault are kept rather than discarded.

What this cannot see

Which message these bytes are. Protobuf payloads are not self-describing at the message level, so with several messages in a .proto nothing in the buffer says which one applies. It also cannot tell an absent field from one set to its default: proto3 does not write defaults, so they are the same bytes. There is no checksum here either, because a protobuf message has none.

More kafka tools

Kafka Confluent Wire Format Decoder The five junk bytes in front of your payload Kafka Key to Partition Mapper Which partition does this key land on? Kafka Topic Name Validator Legal, risky, or 249 characters too long? Kafka Replication Safety Checker How many brokers can you lose Kafka Producer Config Linter Will it start, and will it lose a record? Kafka Message Payload Decoder The first five bytes are usually not data Kafka Connect Source Connector Generator tasks.max is a ceiling, not a count Kafka Connect Sink Connector Generator A dead letter queue with no context headers is a pile of records Kafka Connect SMT Chain Builder The order is the transforms list Kafka MirrorMaker 2 Config Generator It renames every topic by default Kafka Partition Reassignment Generator The throttle is not optional Strimzi Kafka Resource Generator Without the cluster label, nothing happens Kafka mTLS Config Generator The certificate is the identity Kafka Schema Registry Config Generator The compatibility direction is your deployment order Kafka Exactly-Once Config Generator Half of it is worse than none Kafka Broker and KRaft Config Generator The internal topics that break a one-broker cluster Kafka Quota Generator Byte rates are per broker, not per cluster Kafka Streams Config Generator application.id is four things at once Kafka Connect Worker Config Generator Security three times, or the tasks fail Kafka Retention and Unit Converter log.retention.hours does not take milliseconds Kafka Timestamp Converter Two sentinels and two meanings Kafka .properties to YAML Converter Dotted keys stay flat Kafka Streams Internal Topic Predictor Create them before Streams does Kafka ACL Generator The grant you forgot is on another resource type Kafka Topic Config Generator min.insync.replicas is the one that matters Kafka client.properties Generator The file every CLI tool asks for Kafka Producer Config Generator No password field, on purpose Kafka Consumer Config Generator The commit mode decides the semantics Kafka Disk and Retention Calculator retention.bytes is per partition Kafka Partition Count Calculator The number you can never reduce Kafka Cluster Sizing Calculator The traffic no client metric shows Kafka Consumer Lag Catch-Up Calculator Whether it ever clears, not just when Kafka Producer Batching Calculator linger.ms=0 still batches Kafka Segment and Index Sizing Why retention.ms is a lower bound Kafka Rebalance Duration Estimator What a rolling restart really costs Kafka Cost Estimator Your rates, so nothing goes stale Kafka Config Explorer by Version The answer depends on the release Kafka Default Config Reference What moved under a config you never edited Kafka OAuth Bearer Token Decoder Will Kafka accept it, and can it refresh Kafka Record Header Viewer Headers are a list, not a map Kafka Topic Regex Subscription Tester Kafka matches the whole name Kafka ACL Permission Matrix Viewer DENY beats every ALLOW Kafka Connect Config Validator The mistakes that raise no error Kafka Consumer Group Id Validator Which broker coordinates the group Kafka Partition Assignment Visualizer Leadership is the load, not replicas Kafka Consumer Assignment Visualizer The three assignors disagree Kafka ZooKeeper to KRaft Config Converter The authorizer class nobody changes Kafka Config to Strimzi Half of it belongs elsewhere Kafka Docker Compose Generator (KRaft) Reachable from inside and outside Kafka JAAS Config Decoder The line that stops SASL working Kafka CRC32C Calculator Which CRC, over which bytes Kafka Config Upgrade Checker What breaks when you upgrade Kafka Kafka Config Diff Which change actually changed something Kafka Consumer Config Linter Why the group rebalances, and where the records went Kafka Avro Schema Validator The defaults Avro accepts and rejects Kafka Schema Compatibility Checker What the registry will say, before you ask it Kafka Avro Schema Diff Which direction each change breaks Kafka Compression Comparison Measured on your bytes Kafka Delivery Semantics Exactly-once has a consumer half Kafka ksqlDB Query Builder It looks like SQL and the rules are not Kafka Connect SMT Predicate Tester negate reads backwards Kafka Streams Topology Viewer Count the repartitions Kafka Connect Pipeline Visualizer The order things really run in Kafka Protobuf JSON Converter Why your JSON does not round-trip Kafka Protobuf to Avro Schema What does not survive the conversion Kafka Avro Binary Decoder Wrong schema, no error Kafka Avro JSON Converter Why the console producer rejects your line Kafka Avro Sample Data Generator Records that actually serialize Kafka JSON to Avro Schema What JSON cannot tell you Kafka JSON Schema to Avro What does not survive the conversion Kafka SASL JAAS Generator One login module, four syntaxes Kafka CLI Command Builder kcat is librdkafka, not Kafka

Elsewhere on the site