# crypto-hash

> Tiny hashing module that uses the native crypto API in Node.js and the browser

Latest version **4.0.1** (published 2025-12-10) · MIT license · 0 weekly downloads

## Install

```sh
npm install crypto-hash
pnpm add crypto-hash
yarn add crypto-hash
bun add crypto-hash
```

## Health

**Score 60/100 (C)** — status: stable.

Positive: has types; esm support; no vulnerabilities; high quality score.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 4.0.1 |
| Published | 2025-12-10 |
| First published | 2018-03-07 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM |
| Node | >=20 |
| Dependencies | 0 |
| Unpacked size | 12.1 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 645 |
| Author | Sindre Sorhus |
| Maintainers | sindresorhus |
| Keywords | crypto, hash, isomorphic, hashing, hasher, cryptography, sha1, sha256, sha384, sha512, browser |

## Links

- npm: https://www.npmjs.com/package/crypto-hash
- Repository: https://github.com/sindresorhus/crypto-hash
- Homepage: https://github.com/sindresorhus/crypto-hash#readme
- Issues: https://github.com/sindresorhus/crypto-hash/issues
- Funding: https://github.com/sponsors/sindresorhus
- npm.io page: https://npm.io/package/crypto-hash

## Alternatives

- [@gemini-wallet/core](https://npm.io/package/@gemini-wallet/core.md) — 515.6K weekly downloads
- [utility](https://npm.io/package/utility.md) — 416.6K weekly downloads
- [@primno/dpapi](https://npm.io/package/@primno/dpapi.md) — 7.2K weekly downloads
- [pi-readseek](https://npm.io/package/pi-readseek.md) — 3.7K weekly downloads
- [@emilia-protocol/verify](https://npm.io/package/@emilia-protocol/verify.md) — 1.1K weekly downloads

## Recent versions

- 4.0.1 (latest) — 2025-12-10
- 4.0.0 — 2025-09-11
- 3.1.0 — 2024-07-29
- 3.0.0 — 2023-10-22
- 2.0.1 — 2021-12-02
- 2.0.0 — 2021-10-14
- 1.3.0 — 2020-08-12
- 1.2.2 — 2019-07-11
- 1.2.1 — 2019-05-19
- 1.2.0 — 2019-05-03
- 1.1.0 — 2019-04-09
- 1.0.0 — 2018-11-08
- 0.1.0 — 2018-03-07

## README

# crypto-hash

> Tiny hashing module that uses the native crypto API in Node.js and the browser

Useful when you want the same hashing API in all environments. My cat calls it *isomorphic*.

In Node.js it uses [`node:crypto`](https://nodejs.org/api/crypto.html#crypto_class_hash), while in the browser it uses [`window.crypto`](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/digest).

The browser version is only ~300 bytes minified & gzipped.

When used in the browser, it must be in a [secure context (HTTPS)](https://developer.mozilla.org/en-US/docs/Web/API/Crypto/subtle).

This package is for modern browsers. Internet Explorer is not supported.

## Install

```sh
npm install crypto-hash
```

## Usage

```js
import {sha256} from 'crypto-hash';

console.log(await sha256('🦄'));
//=> '36bf255468003165652fe978eaaa8898e191664028475f83f506dabd95298efc'
```

## API

### sha1(input, options?)
### sha256(input, options?)
### sha384(input, options?)
### sha512(input, options?)

Returns a `Promise<string>` with a Hex-encoded hash.

*In Node.js, the operation is executed using [`worker_threads`](https://nodejs.org/api/worker_threads.html). A thread is lazily spawned on the first operation and lives until the end of the program execution. It's `unref`ed, so it won't keep the process alive.*

[SHA-1 is insecure](https://stackoverflow.com/a/38045085/64949) and should not be used for anything sensitive.

#### input

Type: `string` [`ArrayBuffer`](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/ArrayBuffer) [`ArrayBufferView`](https://developer.mozilla.org/en-US/docs/Web/API/ArrayBufferView)

#### options

Type: `object`

##### outputFormat

Type: `string`\
Values: `'hex' | 'buffer'`\
Default: `'hex'`

Setting this to `buffer` makes it return an `ArrayBuffer` instead of a `string`.

## Related

- [hasha](https://github.com/sindresorhus/hasha) - Hashing in Node.js made simple

---
_Source: https://npm.io/package/crypto-hash · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
