Works
Viewing, inspecting and verifying. You get a byte-level hex and ASCII dump alongside the detected signature, exact size and type analysis. File details, exact byte size and the detected signature are always shown.
If double-clicking a CBOR file did nothing useful, that is normal: this extension carries no standard structure, so there is nothing for a generic viewer to hand off to. This page explains the format and gives you a way to read one immediately.
Concise Binary Object Representation is a binary & system format developed by IETF (RFC 8949), first appearing in 2013. It is normally produced by IoT devices, WebAuthn, COSE.
A binary encoding of the JSON data model designed for constrained devices. WebAuthn and passkey attestation objects are CBOR, which is why it shows up in browser security tooling.
| Full name | Concise Binary Object Representation |
|---|---|
| File category | Binary & system |
| MIME type | application/cbor |
| Magic bytes (file signature) | D9 D9 F7 (optional self-describe tag) |
| Developer | IETF (RFC 8949) |
| Introduced | 2013 |
| Usually created by | IoT devices, WebAuthn, COSE |
| OpenAnyFile engine | universal hex inspector |
| Opens without upload | Yes — parsed locally in your browser |
OpenAnyFile routes .cbor to its universal hex inspector, which inspects a byte-level hex and ASCII dump alongside the detected signature, exact size and type analysis.
Viewing, inspecting and verifying. You get a byte-level hex and ASCII dump alongside the detected signature, exact size and type analysis. File details, exact byte size and the detected signature are always shown.
Full-fidelity rendering. This extension has no standard structure, so you get a byte-level inspection rather than a rendered view.
It depends entirely on whether the website uploads it, and almost all of them do. That is a real problem when the binary & system file in question is a contract, a client deliverable or something under NDA. OpenAnyFile removes the question: the decoding happens inside your browser tab, so there is no transfer, no queue, no temporary storage and no retention window to read about in a privacy policy.
Yes. OpenAnyFile's universal hex inspector runs in your browser, so you can read a CBOR file with nothing installed. You get a byte-level hex and ASCII dump alongside the detected signature, exact size and type analysis. It will not replace the original application for editing, but it answers 'what is in this file' in seconds.
Look at the first bytes rather than the extension. A genuine CBOR begins with D9 D9 F7 (optional self-describe tag). Opening the file in OpenAnyFile shows that signature in the file-details panel, so a file renamed to .cbor by mistake is easy to spot.
With OpenAnyFile, yes, because nothing is uploaded. The file is read locally through your browser's File API and never leaves your device, so there is no server copy to leak, log or retain. That matters most for the kind of file people are least willing to hand to a random converter site.
Concise Binary Object Representation — an application/cbor format created by IETF (RFC 8949) since 2013. A binary encoding of the JSON data model designed for constrained devices. WebAuthn and passkey attestation objects are CBOR, which is why it shows up in browser security tooling.
Yes — the same engine also opens .dll, .doc, .exe, so you can compare related files without switching tools.
These open with the same engine, so if you have one of these sitting next to your .cbor file, it will open too: