Algorithms

Algorithms

Every algorithm the package ships with its digest size and HMAC support and options. Read live from the registry
algorithms()24 algorithms · listing order
OptionsSecurity
SHA-256sha256Cryptographic256-bitHMAC yesno options128-bit collision resistance
SHA-384sha384Cryptographic384-bitHMAC yesno options192-bit collision resistance
SHA-512sha512Cryptographic512-bitHMAC yesno options256-bit collision resistance
SHA-512Halfsha512-halfCryptographic256-bitHMAC nono options128-bit collision resistance
SHA3-256sha3-256Cryptographic256-bitHMAC yesno options128-bit collision resistance
SHA3-512sha3-512Cryptographic512-bitHMAC yesno options256-bit collision resistance
Keccak-256keccak256Cryptographic256-bitHMAC yesno options128-bit collision resistance
BLAKE2bblake2bCryptographic512-bitHMAC yesno options256-bit collision resistance
BLAKE2b-256blake2b-256Cryptographic256-bitHMAC nono options128-bit collision resistance
BLAKE2b-224blake2b-224Cryptographic224-bitHMAC nono options112-bit collision resistance
BLAKE2sblake2sCryptographic256-bitHMAC yesno options128-bit collision resistance
BLAKE3blake3Cryptographic256-bitHMAC nono options128-bit security against collisions and preimages
BLAKE-256blake256Cryptographic256-bitHMAC nono options128-bit collision resistance
RIPEMD-160ripemd160Cryptographic160-bitHMAC yesno options80-bit collision resistance
HASH160hash160Cryptographic160-bitHMAC nono options80-bit collision resistance
HASH256 (double SHA-256)hash256Cryptographic256-bitHMAC nono options128-bit collision resistance
MD5md5Legacy128-bitHMAC yesno optionsBROKEN: collision attacks known since 2004
SHA-1sha1Legacy160-bitHMAC yesno optionsBROKEN: practical collision attack (SHAttered)
CRC-32crc32Non-cryptographic32-bitHMAC nono optionsNOT for security: error-detection checksum only
CRC-16/XMODEMcrc16-xmodemNon-cryptographic16-bitHMAC nono optionsNOT for security
xxHash (XXH64)xxhashNon-cryptographic64-bitHMAC noseed?NOT for security: fast hash for hash tables
FNV-1a (64-bit)fnv1aNon-cryptographic64-bitHMAC nono optionsNOT for security: simple hash for hash tables
scryptscryptPasswordvariableHMAC nosalt?, N?, r?, p?, keyLength?Memory-hard KDF
PBKDF2pbkdf2PasswordvariableHMAC nosalt?, iterations?, digest?, keyLength?OWASP Password Storage Cheat Sheet: >=600000 iterations with HMAC-SHA256
read from the registry in your browser / no networka name with ? is optional

Every row is create(name).info(), computed in your browser from the same registry the CLI and the agent tools read. Sort by digest to see what's 20 bytes and what's 64. The security note behind each row is the library's own, cut to its first clause. Hover it for the rest.

Picking one

For a new design, SHA-256 or BLAKE3 and move on. BLAKE3 when speed matters and you control both ends, SHA-256 when anything else has to agree with you.

For compatibility, the page of the thing you're matching wins. Ethereum wants Keccak-256, not SHA3-256, and the two differ in one padding byte. A Bitcoin address wants HASH160 of the key's bytes, not of its hex. The XRP Ledger wants SHA-512Half, which isn't SHA-512/256. Getting any of those almost right gives you a digest that looks exactly like the correct one.

For checksums somebody else published, whatever they published, MD5 included. For your own tables and dedup, xxHash or FNV-1a. Never for anything an attacker gets to choose.

For a password digest you need to reproduce, scrypt or PBKDF2 with the exact salt and cost it was made with. Salted KDFs explains why the salt comes back.