Export to CSV
Export your grid’s raw data to the CSV format, as a downloadable file, a blob, or a string. Customize your export using Handsontable’s configuration options.
Prerequisites
- You configured Handsontable in your project.
- You registered the
ExportFileplugin (the examples useregisterAllModules()).
Examples
Mind that CSV exports contain only raw data, and don’t include formulas, styling, or formatting information.
Examples 1-3 use hidden rows and hidden columns with indicators turned on. The indicators show where hidden data exists in the grid, and each example explains whether the export includes or skips that hidden data.
Export to file
This example exports all rows and columns, including hidden ones, by setting both exportHiddenRows and exportHiddenColumns to true.
/* file: app.component.ts */import { Component, ViewChild } from '@angular/core';import { GridSettings, HotTableComponent, HotTableModule} from '@handsontable/angular-wrapper';
@Component({ standalone: true, imports: [HotTableModule], selector: 'app-example1', template: ` <div class="example-controls-container"> <div class="controls"> <button (click)="exportFile()">Download CSV</button> </div> </div>
<hot-table [settings]="hotSettings!" [data]="hotData"> </hot-table> `,})export class AppComponent { @ViewChild(HotTableComponent, {static: false}) hotTable!: HotTableComponent;
readonly hotData = [ ['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'], ['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'], ['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'], ['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'], ['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'], ['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'], ['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'], ];
readonly hotSettings: GridSettings = { colHeaders: true, rowHeaders: true, hiddenRows: { rows: [1, 3, 5], indicators: true }, hiddenColumns: { columns: [1, 3, 5], indicators: true }, height: 'auto', autoWrapRow: true, autoWrapCol: true, };
exportFile() { const exportPlugin = this.hotTable.hotInstance!.getPlugin('exportFile');
exportPlugin.downloadFile('csv', { bom: false, columnDelimiter: ',', colHeaders: false, exportHiddenColumns: true, exportHiddenRows: true, fileExtension: 'csv', filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]', mimeType: 'text/csv', rowDelimiter: '\r\n', rowHeaders: true, }); }}/* end-file */
/* file: app.config.ts */import { ApplicationConfig, provideZoneChangeDetection } from '@angular/core';import { registerAllModules } from 'handsontable/registry';import { HOT_GLOBAL_CONFIG, HotGlobalConfig, NON_COMMERCIAL_LICENSE } from '@handsontable/angular-wrapper';
// register Handsontable's modulesregisterAllModules();
export const appConfig: ApplicationConfig = { providers: [ provideZoneChangeDetection({ eventCoalescing: true }), { provide: HOT_GLOBAL_CONFIG, useValue: { license: NON_COMMERCIAL_LICENSE } as HotGlobalConfig, }, ],};/* end-file */<div> <app-example1></app-example1></div>Export as a JavaScript Blob object
Open a console in browser developer tools to see the result for the below example.
This example keeps hidden indicators in the grid, but exports only visible rows and columns by setting exportHiddenRows and exportHiddenColumns to false.
/* file: app.component.ts */import { Component, ViewChild } from '@angular/core';import { GridSettings, HotTableComponent, HotTableModule} from '@handsontable/angular-wrapper';
@Component({ standalone: true, imports: [HotTableModule], selector: 'app-example2', template: ` <div class="example-controls-container"> <div class="controls"> <button (click)="exportBlob()">Export as a Blob</button> </div> </div>
<hot-table [settings]="hotSettings!" [data]="hotData"> </hot-table> `,})export class AppComponent { @ViewChild(HotTableComponent, {static: false}) hotTable!: HotTableComponent;
readonly hotData = [ ['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'], ['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'], ['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'], ['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'], ['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'], ['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'], ['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'], ];
readonly hotSettings: GridSettings = { colHeaders: true, rowHeaders: true, hiddenRows: { rows: [1, 3, 5], indicators: true }, hiddenColumns: { columns: [1, 3, 5], indicators: true }, height: 'auto', autoWrapRow: true, autoWrapCol: true, };
exportBlob() { const exportPlugin = this.hotTable.hotInstance!.getPlugin('exportFile');
const exportedBlob = exportPlugin.exportAsBlob('csv', { bom: false, columnDelimiter: ',', colHeaders: false, exportHiddenColumns: false, exportHiddenRows: false, mimeType: 'text/csv', rowDelimiter: '\r\n', rowHeaders: true, });
console.log(exportedBlob); }}/* end-file */
/* file: app.config.ts */import { ApplicationConfig, provideZoneChangeDetection } from '@angular/core';import { registerAllModules } from 'handsontable/registry';import { HOT_GLOBAL_CONFIG, HotGlobalConfig, NON_COMMERCIAL_LICENSE } from '@handsontable/angular-wrapper';
// register Handsontable's modulesregisterAllModules();
export const appConfig: ApplicationConfig = { providers: [ provideZoneChangeDetection({ eventCoalescing: true }), { provide: HOT_GLOBAL_CONFIG, useValue: { license: NON_COMMERCIAL_LICENSE } as HotGlobalConfig, }, ],};/* end-file */<div> <app-example2></app-example2></div>Export as a string
Open a console in browser developer tools to see the result for the below example. Like the Blob example, this export uses only visible data and skips hidden rows and columns.
/* file: app.component.ts */import { Component, ViewChild } from '@angular/core';import { GridSettings, HotTableComponent, HotTableModule} from '@handsontable/angular-wrapper';
@Component({ standalone: true, imports: [HotTableModule], selector: 'app-example3', template: ` <div class="example-controls-container"> <div class="controls"> <button (click)="exportString()">Export as a string</button> </div> </div>
<hot-table [settings]="hotSettings!" [data]="hotData"> </hot-table> `,})export class AppComponent { @ViewChild(HotTableComponent, {static: false}) hotTable!: HotTableComponent;
readonly hotData = [ ['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'], ['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'], ['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'], ['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'], ['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'], ['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'], ['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'], ];
readonly hotSettings: GridSettings = { colHeaders: true, rowHeaders: true, hiddenRows: { rows: [1, 3, 5], indicators: true }, hiddenColumns: { columns: [1, 3, 5], indicators: true }, height: 'auto', autoWrapRow: true, autoWrapCol: true, };
exportString() { const exportPlugin = this.hotTable.hotInstance!.getPlugin('exportFile');
const exportedString = exportPlugin.exportAsString('csv', { bom: false, columnDelimiter: ',', colHeaders: false, exportHiddenColumns: false, exportHiddenRows: false, rowDelimiter: '\r\n', rowHeaders: true, });
console.log(exportedString); }}/* end-file */
/* file: app.config.ts */import { ApplicationConfig, provideZoneChangeDetection } from '@angular/core';import { registerAllModules } from 'handsontable/registry';import { HOT_GLOBAL_CONFIG, HotGlobalConfig, NON_COMMERCIAL_LICENSE } from '@handsontable/angular-wrapper';
// register Handsontable's modulesregisterAllModules();
export const appConfig: ApplicationConfig = { providers: [ provideZoneChangeDetection({ eventCoalescing: true }), { provide: HOT_GLOBAL_CONFIG, useValue: { license: NON_COMMERCIAL_LICENSE } as HotGlobalConfig, }, ],};/* end-file */<div> <app-example3></app-example3></div>Prevent CSV Injection attack
“CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. When a spreadsheet program such as Microsoft Excel or LibreOffice Calc is used to open a CSV, any cells starting with = will be interpreted by the software as a formula.” (from OWASP website)
To prevent this attack, set the sanitizeValues option when exporting your data in CSV format.
/* file: app.component.ts */import { Component, ViewChild, ViewEncapsulation } from '@angular/core';import { GridSettings, HotTableComponent, HotTableModule } from '@handsontable/angular-wrapper';
@Component({ selector: 'app-example4', standalone: true, imports: [HotTableModule], template: ` <div class="example-controls-container"> <div class="controls"> <button (click)="downloadCSVWithNoSanitization()">Download CSV with no sanitization</button> <button (click)="downloadCSVWithRecommendedSanitization()">Download CSV with recommended sanitization</button> <button (click)="downloadCSVWithRegexpSanitization()">Download CSV with sanitization using a regexp</button> <button (click)="downloadCSVWithFunctionSanitization()">Download CSV with sanitization using a function</button> </div> </div>
<hot-table [settings]="hotSettings!" [data]="hotData"> </hot-table> `, encapsulation: ViewEncapsulation.None})export class AppComponent { @ViewChild(HotTableComponent, {static: false}) hotTable!: HotTableComponent;
readonly hotData = [ ['https://api.acme-inventory.com/live-stock', '=WEBSERVICE("https://api.acme-inventory.com/live-stock")'], ['https://status.vertex-logistics.com/feed', '=WEBSERVICE("https://status.vertex-logistics.com/feed")'], ['http://malicious.example/payload.exe', '=CMD("| calc.exe")'], ['https://news.example.com/q2-briefing', '=HYPERLINK("http://malicious.example","Open report")'], ['https://cdn.example.com/daily.csv', '+SUM(1,1)'], ];
readonly hotSettings: GridSettings = { colHeaders: true, rowHeaders: true, height: 'auto', autoWrapRow: true, autoWrapCol: true, };
downloadCSVWithNoSanitization() { const exportPlugin = this.hotTable.hotInstance!.getPlugin('exportFile');
exportPlugin.downloadFile('csv', { bom: false, columnDelimiter: ',', colHeaders: false, exportHiddenColumns: true, exportHiddenRows: true, fileExtension: 'csv', filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]', mimeType: 'text/csv', rowDelimiter: '\r\n', }); }
downloadCSVWithRecommendedSanitization() { const exportPlugin = this.hotTable.hotInstance!.getPlugin('exportFile');
exportPlugin.downloadFile('csv', { bom: false, columnDelimiter: ',', colHeaders: false, exportHiddenColumns: true, exportHiddenRows: true, fileExtension: 'csv', filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]', mimeType: 'text/csv', rowDelimiter: '\r\n', sanitizeValues: true, }); }
downloadCSVWithRegexpSanitization() { const exportPlugin = this.hotTable.hotInstance!.getPlugin('exportFile');
exportPlugin.downloadFile('csv', { bom: false, columnDelimiter: ',', colHeaders: false, exportHiddenColumns: true, exportHiddenRows: true, fileExtension: 'csv', filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]', mimeType: 'text/csv', rowDelimiter: '\r\n', sanitizeValues: /WEBSERVICE|CMD|HYPERLINK|^\+/, }); }
downloadCSVWithFunctionSanitization() { const exportPlugin = this.hotTable.hotInstance!.getPlugin('exportFile');
exportPlugin.downloadFile('csv', { bom: false, columnDelimiter: ',', colHeaders: false, exportHiddenColumns: true, exportHiddenRows: true, fileExtension: 'csv', filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]', mimeType: 'text/csv', rowDelimiter: '\r\n', sanitizeValues: (value: string) => { return /WEBSERVICE|CMD|HYPERLINK|^\+/.test(value) ? 'REMOVED SUSPICIOUS CELL CONTENT' : value; }, }); }}/* end-file */
/* file: app.config.ts */import { ApplicationConfig, provideZoneChangeDetection } from '@angular/core';import { registerAllModules } from 'handsontable/registry';import { HOT_GLOBAL_CONFIG, HotGlobalConfig, NON_COMMERCIAL_LICENSE } from '@handsontable/angular-wrapper';
registerAllModules();
export const appConfig: ApplicationConfig = { providers: [ provideZoneChangeDetection({ eventCoalescing: true }), { provide: HOT_GLOBAL_CONFIG, useValue: { license: NON_COMMERCIAL_LICENSE, } as HotGlobalConfig, }, ],};/* end-file */<div> <app-example4></app-example4></div>Result
After completing this guide, you can export grid data as a downloadable CSV file, a JavaScript Blob, or a string. You can customize delimiters, ranges, headers, and value sanitization through the export configuration.
Available methods
The plugin exposes the following methods to export data.
downloadFile(format, options)- generates a downloadable file directly in the browser. Synchronous; supports text-based formats only (e.g. CSV). For XLSX, usedownloadFileAsync.downloadFileAsync(format, options)- generates a downloadable file and returns aPromise. Supports all formats including XLSX.exportAsBlob(format, options)- allows you to export a JavaScript Blob object.exportAsString(format, options)- allows you to export data as a string. Supports text-based formats only (e.g. CSV).
Each method takes two parameters. The first, format, is required. The second, options, is an optional object that overrides or extends the default export configuration. The table below lists all supported options for CSV export.
Available options in the export configuration
| Property | Type / Default | Description |
|---|---|---|
bom | Boolean, default true | Prepend output with BOM (UTF-8). Browser uses EF BB BF. |
colHeaders | Boolean, default false | Include column headers. Does not support the NestedHeaders plugin. |
columnDelimiter | String, default ',' | Column delimiter. |
exportHiddenColumns | Boolean, default false | Include hidden columns. |
exportHiddenRows | Boolean, default false | Include hidden rows. |
fileExtension | String, default 'csv' | File extension. Used by downloadFile(). |
filename | String, default 'Handsontable [YYYY]-[MM]-[DD]' | File name. Placeholders [YYYY], [MM], [DD] are replaced with the current date. Used by downloadFile(). |
mimeType | String, default 'text/csv' | MIME type. Used by downloadFile() and exportAsBlob(). |
range | Array, default [] | Cell range to export: [startRow, startColumn, endRow, endColumn] (visual indexes). |
rowDelimiter | String, default '\r\n' | Row delimiter. |
rowHeaders | Boolean, default false | Include row headers. |
sanitizeValues | Boolean | RegExp | Function, default false | Value sanitization. true = OWASP CSV injection rules; RegExp = escape matching values; Function = replace with return value. |
Related blog articles
Related API reference
Plugins