ALL DEVELOPER TOOLS56
Extract Archive
Extract Files From a ZIP, TAR, 7z or RAR Archive
List everything inside an archive, tick the files you want, and pull them out — without uploading the archive anywhere.
Nothing is enforced, but extraction copies the whole archive into the engine's memory in one block and allocates each file you pull out beside it, so a run holds the archive about twice over — measured at 88 MB of engine memory for a 48 MB tar whose largest member was 32 MB.
About Extract Archive
An archive is a container: it holds files, their names, their folder structure and, usually, their compressed bytes. Opening one normally means installing something, or handing the file to a website that unpacks it on a server it owns. This page does neither. It runs libarchive — the same C library behind bsdtar and the archive support in a great deal of desktop software — compiled to WebAssembly and served from this site rather than a CDN, so opening an archive makes no request to anyone. Drop one in and you get its table of contents first: every entry, the path it stores, the size it declares, and whether it is a file, a folder, a symbolic link or an encrypted member. Tick what you want. One file downloads on its own; two or more are bundled into a single ZIP, because browsers cancel a burst of separate downloads. One thing this page cannot do is make an archive, and that is a property of the build rather than a rule anyone imposed: the binary carries sixteen format readers and not one format writer.
Questions
Can this page make a ZIP as well as open one?
No, and the reason is worth knowing because it is stronger than a promise. This page runs a WebAssembly build of libarchive that contains sixteen archive_read_support_format_* entry points — ZIP, TAR, 7-Zip, RAR, RAR5, CPIO, AR, CAB, LHA, ISO9660, XAR, WARC, mtree and the rest — and zero archive_write_set_format_* ones. There is no writer in the binary to call, so no future change to this page could quietly start creating archives. Packing files into a ZIP is what Create ZIP does, on a different library entirely.
My .gz file opened as one file, not a folder of files.
Then it was a single compressed file rather than a compressed archive, and the page said which it found. A .tar.gz is a tar — a real archive with many members — wrapped in gzip, and libarchive reads it. A bare .gz, like access.log.gz, holds one file and nothing else; libarchive is not built with its raw reader, so it cannot open that at all. The browser's own gzip decoder does it instead, which is why the list has exactly one row and the size shown is the one the file records in its last four bytes. There is no browser-native xz or bzip2 decoder, so a bare .xz or .bz2 — as opposed to a .tar.xz or .tar.bz2 — is refused with that explanation rather than opened wrongly.
One of the entries says REFUSED. What did my archive do?
It stored a path that points outside the folder you would unpack into — something beginning with ../, an absolute path like /etc/passwd, or a Windows drive or network path. That is the zip-slip pattern, and an archive built by an ordinary tool does not contain one. Nothing here could write to those locations even if it tried: a browser download goes to your downloads folder and nowhere else. The reason it is shown rather than quietly cleaned up is that the same archive unpacked by tar or unzip on a shell CAN write there, and you should know the file tried before you take it anywhere else. Refused entries are listed with their real stored path and cannot be ticked.
Should I use this or Unzip Files?
Use Unzip Files for an ordinary .zip. It runs on JSZip, which is already part of this site's JavaScript, so it fetches no engine and starts instantly. Come here when the file is not a plain ZIP — a .tar, .7z, .rar, or a tar.gz, tar.xz or tar.bz2 — or when the ZIP's entries are password-protected, which JSZip cannot decrypt at all. The cost of that reach is one 599 KB WebAssembly download the first time something on this page needs the engine, cached by your browser afterwards — a bare .gz never does, because the browser's own gzip decoder reads that one and the engine is not fetched at all. Both read the archive in your tab and neither uploads anything.
The archive is password-protected. Will this open it?
Often, yes. Type the password into ARCHIVE PASSWORD in the rail before extracting; it is handed to the engine running beside this page and is not stored, remembered or sent anywhere. libarchive opens ZipCrypto and AES-encrypted ZIP entries given the right password, and it reports a wrong one as a wrong password rather than handing back garbage. What it will not do is decrypt RAR: this build says so itself, and rather than guess, the page shows you the engine's own refusal for any member it cannot read, naming the entry. Some archives also encrypt their file list, in which case nothing appears until you supply the password and press "Read this archive again".
Is my file uploaded to a server?
No. Transmute processes everything locally in your browser using JavaScript and WebAssembly. Your files never leave your device — there is no server, no upload, no cloud processing.