Search tools

ZIP Compression Methods and Encryption: Who Reads What

Every file in a ZIP records its own compression method. Stored (0) and Deflate (8) are the common ground: Python, Java, Info-ZIP UnZip and UNQIRO all read them. Deflate64, BZIP2, LZMA, Zstandard and XZ are valid ZIP methods that only some programs read. Method 99 is not a compression method at all: it marks WinZip AES encryption, and the method actually used is stored in the entry’s AES extra field (0x9901). A program without the method or the encryption may call a valid archive unsupported, invalid or corrupt.

The method belongs to each file

The method is a 16-bit field in each local header and each central directory record, so one archive can mix methods: most files Deflate, a few stored, one in LZMA. A program that lacks one method can still read the other files, if it is written to continue. The numbers are assigned in PKWARE’s APPNOTE.

Methods in use today, by APPNOTE number. The names and the last column are taken from UNQIRO’s ZIP reader when this page is built.
Number Method UNQIRO
0 Store Extracted
8 Deflate Extracted
9 Deflate64 Listed and named, not extracted
12 BZIP2 Listed and named, not extracted
14 LZMA Listed and named, not extracted
93 Zstandard Listed and named, not extracted
95 XZ Listed and named, not extracted
98 PPMd Listed and named, not extracted

Zstandard has two numbers: APPNOTE first assigned 20 and moved it to 93 in its next revision, where 20 became deprecated. UNQIRO names both as Zstandard. Methods 1 to 6 are legacy algorithms that APPNOTE no longer recommends.

Method 99 is a marker, not a method

WinZip AES does not change what compression is used. It sets the method field to 99 to say “this entry is AES encrypted”, and stores the real method in an extra field with the ID 0x9901 (7 bytes of data), together with the AES version (AE-1 or AE-2) and the key length.

One entry marked as WinZip AES, written for this page and read back by UNQIRO’s ZIP reader when it was built. Its data is filler, not real encryption.
Where Stored value Meaning
Method field 99 Marker: look for the AES extra field
Flag bit 0 1 The data is encrypted
0x9901: vendor version 2 AE-2
0x9901: vendor ID “AE” Always “AE”
0x9901: strength 3 256-bit key
0x9901: method 8 The compression actually used
UNQIRO reports 8 Deflate, “Encrypted”

UNQIRO reads the real method from 0x9901 and lists the entry with that method and as encrypted. It does not read or show the AES version or the key length. When an entry says 99 but has no readable AES extra field, UNQIRO names its method “AES”.

Three encryption schemes that look alike

Encryption protects the file data. The central directory stays readable in the first two schemes, so a reader can list an encrypted archive without the password.

How each scheme is marked, and how UNQIRO’s reader classed an example entry of each when this page was built. The ZIP tool marks all three as “Encrypted”.
Scheme How it is marked What stays readable Method UNQIRO lists
Traditional PKWARE encryption (ZipCrypto) Flag bit 0; the method field holds the real method Names, sizes, CRC-32, dates and the method stay readable. APPNOTE calls this encryption weak by today’s standards. Deflate
WinZip AES (AE-1, AE-2) Flag bit 0, method 99, extra field 0x9901 with the real method Names and sizes stay readable. AE-2 stores 0 instead of the CRC-32. Deflate
PKWARE strong encryption Flag bits 0 and 6, extra field 0x0017 A separately licensed PKWARE scheme; with flag bit 13 even the central directory is encrypted. Deflate

The version needed to extract adds to the confusion. APPNOTE ties version 5.1 to AES within PKWARE’s strong encryption, while the WinZip specification leaves the version unchanged, and writers differ. Info-ZIP UnZip 6.0 checks the version first: a file that needs more than it can do is skipped with a message such as “need PK compat. v5.1 (can do v4.6)”, and otherwise method 99 is an “unsupported compression method 99”. Both mean the same: it has no WinZip AES support.

Which program reads what

Only what the programs’ own sources or documentation state:

ZIP support of common readers, from their source code or documentation.
Program Methods it reads Encryption
UNQIRO Store and Deflate; every other method is named Encrypted files are listed and marked, not decrypted
Python 3.14 zipfile Stored, Deflate, BZIP2, LZMA, Zstandard (93); others raise “That compression method is not supported” Traditional encryption only; strong encryption raises an error; method 99 is not one of its methods
Java java.util.zip.ZipFile Stored and Deflate; other methods are rejected when the archive is opened Encrypted entries are rejected when the archive is opened
Info-ZIP UnZip 6.0 Stored, Deflate and older PKZIP methods; Deflate64 and BZIP2 only when built with them No WinZip AES
Windows File Explorer Not documented by Microsoft Does not support encrypted archives (Microsoft)

The pattern is the same everywhere: the archive is valid, the program lacks one method or one scheme. Other ways a ZIP fails to open are in Why a ZIP file won’t open; how the list with the methods is found is in How a ZIP file is read.

Check your own file

The ZIP tool lists every file of your archive with its method, and marks files that are encrypted or use a method it cannot extract. Its details name all methods the archive uses. Nothing is uploaded.

See which compression methods this ZIP uses (View ZIP Contents)

Sources