Hash Functions

The hash module computes cryptographic hashes, HMAC values, PBKDF2-derived keys, and non-cryptographic FNV-1 hashes. This page is an API reference of isolated calls. Literal inputs illustrate successful use; when data, secrets, passwords, or salts come from the application, capture and handle the documented second error return before consuming the result.

A hash is not encryption and does not conceal low-entropy input. Do not log passwords, HMAC keys, derived keys, or raw secret-dependent digests. Use HMAC-SHA256 or HMAC-SHA512 for new message-authentication designs and PBKDF2 with a unique random salt for password verifiers.

Loading

local hash = require("hash")

Cryptographic Hashes

MD5

MD5 is not collision-resistant. Use it only for compatibility with protocols that require MD5, not for security decisions.

local hex = hash.md5("data")
local raw = hash.md5("data", true)
Parameter Type Description
data string Data to hash
raw boolean? Return raw bytes instead of hex

Returns: string, error

SHA-1

SHA-1 is not collision-resistant. Use it only for compatibility with protocols that require SHA-1, not for security decisions.

local hex = hash.sha1("data")
local raw = hash.sha1("data", true)
Parameter Type Description
data string Data to hash
raw boolean? Return raw bytes instead of hex

Returns: string, error

SHA-256

local hex = hash.sha256("data")
local raw = hash.sha256("data", true)
Parameter Type Description
data string Data to hash
raw boolean? Return raw bytes instead of hex

Returns: string, error

SHA-512

local hex = hash.sha512("data")
local raw = hash.sha512("data", true)
Parameter Type Description
data string Data to hash
raw boolean? Return raw bytes instead of hex

Returns: string, error

HMACs

HMAC-MD5

Use HMAC-MD5 only for compatibility with a protocol that requires it; prefer HMAC-SHA256 or HMAC-SHA512 for new designs.

local hex = hash.hmac_md5("message", "secret")
local raw = hash.hmac_md5("message", "secret", true)
Parameter Type Description
data string Message to authenticate
secret string Secret key
raw boolean? Return raw bytes instead of hex

Returns: string, error

HMAC-SHA1

Use HMAC-SHA1 only for compatibility with a protocol that requires it; prefer HMAC-SHA256 or HMAC-SHA512 for new designs.

local hex = hash.hmac_sha1("message", "secret")
local raw = hash.hmac_sha1("message", "secret", true)
Parameter Type Description
data string Message to authenticate
secret string Secret key
raw boolean? Return raw bytes instead of hex

Returns: string, error

HMAC-SHA256

local hex = hash.hmac_sha256("message", "secret")
local raw = hash.hmac_sha256("message", "secret", true)
Parameter Type Description
data string Message to authenticate
secret string Secret key
raw boolean? Return raw bytes instead of hex

Returns: string, error

HMAC-SHA512

local hex = hash.hmac_sha512("message", "secret")
local raw = hash.hmac_sha512("message", "secret", true)
Parameter Type Description
data string Message to authenticate
secret string Secret key
raw boolean? Return raw bytes instead of hex

Returns: string, error

Non-Cryptographic Hashes

FNV-1 32-bit

Compute a hash for uses such as hash tables and partitioning.

local n = hash.fnv32("data")
Parameter Type Description
data string Data to hash

Returns: number, error

FNV-1 64-bit

Compute a wider hash for uses such as hash tables and partitioning, reducing collision probability.

local n = hash.fnv64("data")
Parameter Type Description
data string Data to hash

Returns: number, error

Key Derivation

PBKDF2

local key, err = hash.pbkdf2(password, salt, iterations, key_length)
local key, err = hash.pbkdf2(password, salt, iterations, key_length, "sha512")
Parameter Type Description
password string Password/passphrase (non-empty)
salt string Salt value (non-empty)
iterations integer Iteration count (1 to 10,000,000)
key_length integer Desired key length in bytes
hash string? sha256 or sha512 (default: sha256)

Returns: string, error (raw key bytes)

Errors

Condition Kind Retryable
Input not a string errors.INVALID no
Secret not a string (HMAC) errors.INVALID no
Empty password/salt, non-positive or excessive iterations, unsupported hash (PBKDF2) errors.INVALID no

See Error Handling for working with errors.