The method belongs to each file
The method is a 16-bit field in each local header and each central directory record, so one archive can mix methods: most files Deflate, a few stored, one in LZMA. A program that lacks one method can still read the other files, if it is written to continue. The numbers are assigned in PKWARE’s APPNOTE.
| Number | Method | UNQIRO |
|---|---|---|
| 0 | Store | Extracted |
| 8 | Deflate | Extracted |
| 9 | Deflate64 | Listed and named, not extracted |
| 12 | BZIP2 | Listed and named, not extracted |
| 14 | LZMA | Listed and named, not extracted |
| 93 | Zstandard | Listed and named, not extracted |
| 95 | XZ | Listed and named, not extracted |
| 98 | PPMd | Listed and named, not extracted |
Zstandard has two numbers: APPNOTE first assigned 20 and moved it to 93 in its next revision, where 20 became deprecated. UNQIRO names both as Zstandard. Methods 1 to 6 are legacy algorithms that APPNOTE no longer recommends.
Method 99 is a marker, not a method
WinZip AES does not change what compression is used. It sets the method field to 99 to say “this entry is AES encrypted”, and stores the real method in an extra field with the ID 0x9901 (7 bytes of data), together with the AES version (AE-1 or AE-2) and the key length.
| Where | Stored value | Meaning |
|---|---|---|
| Method field | 99 | Marker: look for the AES extra field |
| Flag bit 0 | 1 | The data is encrypted |
| 0x9901: vendor version | 2 | AE-2 |
| 0x9901: vendor ID | “AE” | Always “AE” |
| 0x9901: strength | 3 | 256-bit key |
| 0x9901: method | 8 | The compression actually used |
| UNQIRO reports | 8 | Deflate, “Encrypted” |
UNQIRO reads the real method from 0x9901 and lists the entry with that method and as encrypted. It does not read or show the AES version or the key length. When an entry says 99 but has no readable AES extra field, UNQIRO names its method “AES”.
Three encryption schemes that look alike
Encryption protects the file data. The central directory stays readable in the first two schemes, so a reader can list an encrypted archive without the password.
| Scheme | How it is marked | What stays readable | Method UNQIRO lists |
|---|---|---|---|
| Traditional PKWARE encryption (ZipCrypto) | Flag bit 0; the method field holds the real method | Names, sizes, CRC-32, dates and the method stay readable. APPNOTE calls this encryption weak by today’s standards. | Deflate |
| WinZip AES (AE-1, AE-2) | Flag bit 0, method 99, extra field 0x9901 with the real method | Names and sizes stay readable. AE-2 stores 0 instead of the CRC-32. | Deflate |
| PKWARE strong encryption | Flag bits 0 and 6, extra field 0x0017 | A separately licensed PKWARE scheme; with flag bit 13 even the central directory is encrypted. | Deflate |
The version needed to extract adds to the confusion. APPNOTE ties version 5.1 to AES within PKWARE’s strong encryption, while the WinZip specification leaves the version unchanged, and writers differ. Info-ZIP UnZip 6.0 checks the version first: a file that needs more than it can do is skipped with a message such as “need PK compat. v5.1 (can do v4.6)”, and otherwise method 99 is an “unsupported compression method 99”. Both mean the same: it has no WinZip AES support.
Which program reads what
Only what the programs’ own sources or documentation state:
| Program | Methods it reads | Encryption |
|---|---|---|
| UNQIRO | Store and Deflate; every other method is named | Encrypted files are listed and marked, not decrypted |
Python 3.14 zipfile | Stored, Deflate, BZIP2, LZMA, Zstandard (93); others raise “That compression method is not supported” | Traditional encryption only; strong encryption raises an error; method 99 is not one of its methods |
Java java.util.zip.ZipFile | Stored and Deflate; other methods are rejected when the archive is opened | Encrypted entries are rejected when the archive is opened |
| Info-ZIP UnZip 6.0 | Stored, Deflate and older PKZIP methods; Deflate64 and BZIP2 only when built with them | No WinZip AES |
| Windows File Explorer | Not documented by Microsoft | Does not support encrypted archives (Microsoft) |
The pattern is the same everywhere: the archive is valid, the program lacks one method or one scheme. Other ways a ZIP fails to open are in Why a ZIP file won’t open; how the list with the methods is found is in How a ZIP file is read.
Check your own file
The ZIP tool lists every file of your archive with its method, and marks files that are encrypted or use a method it cannot extract. Its details name all methods the archive uses. Nothing is uploaded.
See which compression methods this ZIP uses (View ZIP Contents)