Skip to main content

pktfmt

Generate RFC-style ASCII packet diagrams from field definitions.

A modern, pip-installable alternative to protocol that works on Windows and modern Python.

Installation

pip install pktfmt

Features

  • 20+ built-in protocols - TCP, UDP, IP, DNS, and more
  • Custom packet definitions - inline format or JSON files
  • Unicode box drawing - pretty output for modern terminals
  • Variable-length fields - with distinct visual styling
  • Cross-platform - works on Windows, macOS, and Linux
  • Modern Python - supports Python 3.8+

Quick Start

# Show a built-in protocol
pktfmt tcp

# List all available protocols
pktfmt --list

# Custom inline format
pktfmt "Type:16,Length:16,Payload:*"

# Pretty Unicode output
pktfmt udp --unicode

Usage

Built-in Protocols

$ pktfmt tcp
 0                  1                  2                  3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|          Source Port          |        Destination Port       |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                        Sequence Number                        |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                     Acknowledgment Number                     |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|Data Of|Reserve|C|E|U|A|P|R|S|F|             Window            |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|            Checksum           |         Urgent Pointer        |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
:                            Options                            :
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

Custom Inline Format

$ pktfmt "Type:16,Length:16,Payload:*"
 0                  1                  2                  3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|              Type             |             Length            |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
:                            Payload                            :
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

JSON File Format

pktfmt packet.json
{
  "name": "MyPacket",
  "fields": [
    {"name": "Type", "bits": 16},
    {"name": "Length", "bits": 16},
    {"name": "Payload", "bits": "*"}
  ]
}

Unicode Output

$ pktfmt udp --unicode
 0                  1                  2                  3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
┌─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┬─┐
│          Source Port          │        Destination Port       │
├─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┤
│             Length            │            Checksum           │
├─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┼─┤
┊                              Data                             ┊
└─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┴─┘

Options

pktfmt <input> [options]

Options:
  -l, --list              List all built-in protocols
  -b, --bits-per-row N    Bits per row (default: 32)
  -s, --style STYLE       Output style: ascii, unicode
  -u, --unicode           Shortcut for --style unicode
  -o, --output FILE       Write output to FILE instead of stdout
  --no-ruler              Omit the bit number header
  -v, --version           Show version

Pass '-' as the input to read a JSON packet definition from stdin:
  cat packet.json | pktfmt -

Field Syntax

  • Name:N - Fixed-width field of N bits
  • Name:* - Variable-length field (rendered with : or ┊ borders)

Built-in Protocols

Layer Protocols
Layer 2 ethernet, 8021q, arp
Layer 3 ipv4, ipv6, icmp, icmpv6
Layer 4 tcp, udp, sctp
Application dns, dhcp, ntp, tls
Tunneling gre, vxlan, quic
Industrial modbus, dnp3

Why pktfmt?

  • Actually installs via pip - protocol requires manual setup.py installation
  • Works on modern Python - protocol uses deprecated distutils
  • Works on Windows - proper UTF-8 handling
  • Actively maintained - PRs get merged
  • Unicode support - pretty box drawing characters
  • More protocols - 20+ built-in, vs ~10 in protocol

License

MIT

Metadata

Release files for pktfmt 0.4.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pktfmt 0.4.1
File Size Uploaded
pktfmt-0.4.1.tar.gz 14.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pktfmt 0.4.1
File Interpreter ABI Platform
pktfmt-0.4.1-py3-none-any.whl Python 3 none any Details

Total release size: 31.1 kB

Release files / pktfmt-0.4.1.tar.gz

Download URL pktfmt-0.4.1.tar.gz
Size 14.9 kB
Tags Source
SHA-256 checksum
How to use checksums
80256382ac23a6c5a926a183d6787e758398b96491b32aea30fe9b174fc1c6da
BLAKE2b-256 checksum
How to use checksums
4f289419b5a93dab7a247e9fb74508ca103586d075efdcd74d2f567bbe314176
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 26, 2026.

Transparency log

Release files / pktfmt-0.4.1-py3-none-any.whl

Download URL pktfmt-0.4.1-py3-none-any.whl
Size 16.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0e0360f1e8a2d6d41a5ee5ea0dcd6d5b4f2ab74122401d50180dd857d9db194b
BLAKE2b-256 checksum
How to use checksums
a2d13214de61d37349e469a88250c53137550d519f32c4a5c33e5660556493fd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 26, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.4.1 This release

2 release files

0.3.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page