# hash-object

> Get the hash of an object

Latest version **5.1.0** (published 2026-02-03) · MIT license · 0 weekly downloads

## Install

```sh
npm install hash-object
pnpm add hash-object
yarn add hash-object
bun add hash-object
```

## Health

**Score 60/100 (C)** — status: stable.

Positive: has types; esm support; no vulnerabilities; high quality score.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 5.1.0 |
| Published | 2026-02-03 |
| First published | 2014-10-16 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM |
| Node | >=18 |
| Dependencies | 4 |
| Unpacked size | 9 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 140 |
| Author | Sindre Sorhus |
| Maintainers | sindresorhus |
| Keywords | hash, hashing, crypto, object, plain, hex, base64, md5, sha1, sha256, sha512, sum, uint8array, bytes, checksum |

## Links

- npm: https://www.npmjs.com/package/hash-object
- Repository: https://github.com/sindresorhus/hash-object
- Homepage: https://github.com/sindresorhus/hash-object#readme
- Issues: https://github.com/sindresorhus/hash-object/issues
- Funding: https://github.com/sponsors/sindresorhus
- npm.io page: https://npm.io/package/hash-object

## Dependencies (4)

- [is-obj](https://npm.io/package/is-obj.md) ^3.0.0
- [sort-keys](https://npm.io/package/sort-keys.md) ^5.0.0
- [type-fest](https://npm.io/package/type-fest.md) ^4.6.0
- [decircular](https://npm.io/package/decircular.md) ^0.1.0

## Alternatives

- [@gemini-wallet/core](https://npm.io/package/@gemini-wallet/core.md) — 515.6K weekly downloads
- [utility](https://npm.io/package/utility.md) — 416.6K weekly downloads
- [@primno/dpapi](https://npm.io/package/@primno/dpapi.md) — 7.2K weekly downloads
- [pi-readseek](https://npm.io/package/pi-readseek.md) — 3.7K weekly downloads
- [@emilia-protocol/verify](https://npm.io/package/@emilia-protocol/verify.md) — 1.1K weekly downloads

## Recent versions

- 5.1.0 (latest) — 2026-02-03
- 5.0.1 — 2023-11-14
- 5.0.0 — 2023-11-06
- 0.1.7 — 2014-10-19
- 0.1.6 — 2014-10-19
- 0.1.5 — 2014-10-17
- 0.1.4 — 2014-10-16
- 0.1.3 — 2014-10-16
- 0.1.2 — 2014-10-16
- 0.1.1 — 2014-10-16
- 0.1.0 — 2014-10-16

## README

# hash-object

> Get the hash of an object

## Install

```sh
npm install hash-object
```

## Usage

```js
import hashObject from 'hash-object';

hashObject({'🦄': '🌈'}, {algorithm: 'sha1'});
//=> '3de3bc784035b559784fc276f47493d60555fba3'
```

An async version that uses the Web Crypto API is also available. This works in browsers, edge runtimes, and Node.js 20+:

```js
import hashObject from 'hash-object/async';

await hashObject({'🦄': '🌈'}, {algorithm: 'sha1'});
//=> '3de3bc784035b559784fc276f47493d60555fba3'
```

> [!NOTE]
> The async version only supports `sha1`, `sha256`, `sha384`, `sha512` algorithms and `hex`, `base64`, `buffer` encodings.

## API

### hashObject(object, options?)

The output is deterministic for repeated runs on the same Node.js / browser version. It should also be fairly deterministic across JavaScript engines. However, because the stability of grapheme clusters across Unicode versions is not guaranteed, determinism cannot be guaranteed across JavaScript engines and versions. There are also other factors that can make it nondeterministic, like values with floating point numbers and dates.

#### object

Type: `object`

#### options

Type: `object`

##### encoding

Type: `'hex' | 'base64' | 'buffer' | 'latin1'`\
Default: `'hex'`

The encoding of the returned hash.

##### algorithm

Type: `string`\
Default: `'sha512'`\
Values: `'md5' | 'sha1' | 'sha256' | 'sha512' | …` *([Platform dependent](https://nodejs.org/api/crypto.html#crypto_crypto_createhash_algorithm))*

The async version only supports `'sha1'`, `'sha256'`, `'sha384'`, and `'sha512'`.

*Don't use `'md5'` or `'sha1'` for anything sensitive. [They're insecure.](http://googleonlinesecurity.blogspot.no/2014/09/gradually-sunsetting-sha-1.html)*

## Related

- [hasha](https://github.com/sindresorhus/hasha) - Hashing made simple. Get the hash of a buffer/string/stream/file.

---
_Source: https://npm.io/package/hash-object · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
