Skip to content

Export to CSV

Export your grid’s raw data to the CSV format, as a downloadable file, a blob, or a string. Customize your export using Handsontable’s configuration options.

Prerequisites

  • You configured Handsontable in your project.
  • You registered the ExportFile plugin (the examples use registerAllModules()).

Examples

Mind that CSV exports contain only raw data, and don’t include formulas, styling, or formatting information.

Examples 1-3 use hidden rows and hidden columns with indicators turned on. The indicators show where hidden data exists in the grid, and each example explains whether the export includes or skips that hidden data.

Export to file

This example exports all rows and columns, including hidden ones, by setting both exportHiddenRows and exportHiddenColumns to true.

JavaScript
import Handsontable from 'handsontable/base';
import { registerAllModules } from 'handsontable/registry';
// Register all Handsontable's modules.
registerAllModules();
const container = document.querySelector('#example1');
const hot = new Handsontable(container, {
data: [
['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'],
['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'],
['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'],
['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'],
['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'],
['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'],
['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'],
],
colHeaders: true,
rowHeaders: true,
hiddenRows: { rows: [1, 3, 5], indicators: true },
hiddenColumns: { columns: [1, 3, 5], indicators: true },
height: 'auto',
autoWrapRow: true,
autoWrapCol: true,
licenseKey: 'non-commercial-and-evaluation',
});
const exportPlugin = hot.getPlugin('exportFile');
const button = document.querySelector('#export-file');
button.addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
rowHeaders: true,
});
});
TypeScript
import Handsontable from 'handsontable/base';
import { registerAllModules } from 'handsontable/registry';
import { ExportFile } from 'handsontable/plugins';
// Register all Handsontable's modules.
registerAllModules();
const container = document.querySelector('#example1')!;
const hot = new Handsontable(container, {
data: [
['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'],
['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'],
['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'],
['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'],
['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'],
['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'],
['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'],
],
colHeaders: true,
rowHeaders: true,
hiddenRows: { rows: [1, 3, 5], indicators: true },
hiddenColumns: { columns: [1, 3, 5], indicators: true },
height: 'auto',
autoWrapRow: true,
autoWrapCol: true,
licenseKey: 'non-commercial-and-evaluation',
});
const exportPlugin: ExportFile = hot.getPlugin('exportFile');
const button = document.querySelector('#export-file')!;
button.addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
rowHeaders: true,
});
});
HTML
<div class="example-controls-container">
<div class="controls">
<button id="export-file">Download CSV</button>
</div>
</div>
<div id="example1"></div>

Export as a JavaScript Blob object

Open a console in browser developer tools to see the result for the below example. This example keeps hidden indicators in the grid, but exports only visible rows and columns by setting exportHiddenRows and exportHiddenColumns to false.

JavaScript
import Handsontable from 'handsontable/base';
import { registerAllModules } from 'handsontable/registry';
// Register all Handsontable's modules.
registerAllModules();
const container = document.querySelector('#example2');
const hot = new Handsontable(container, {
data: [
['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'],
['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'],
['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'],
['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'],
['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'],
['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'],
['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'],
],
colHeaders: true,
rowHeaders: true,
hiddenRows: { rows: [1, 3, 5], indicators: true },
hiddenColumns: { columns: [1, 3, 5], indicators: true },
height: 'auto',
autoWrapRow: true,
autoWrapCol: true,
licenseKey: 'non-commercial-and-evaluation',
});
const exportPlugin = hot.getPlugin('exportFile');
const button = document.querySelector('#export-blob');
button.addEventListener('click', () => {
const exportedBlob = exportPlugin.exportAsBlob('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: false,
exportHiddenRows: false,
mimeType: 'text/csv',
rowDelimiter: '\r\n',
rowHeaders: true,
});
console.log(exportedBlob);
});
TypeScript
import Handsontable from 'handsontable/base';
import { registerAllModules } from 'handsontable/registry';
import { ExportFile } from 'handsontable/plugins';
// Register all Handsontable's modules.
registerAllModules();
const container = document.querySelector('#example2')!;
const hot = new Handsontable(container, {
data: [
['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'],
['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'],
['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'],
['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'],
['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'],
['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'],
['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'],
],
colHeaders: true,
rowHeaders: true,
hiddenRows: { rows: [1, 3, 5], indicators: true },
hiddenColumns: { columns: [1, 3, 5], indicators: true },
height: 'auto',
autoWrapRow: true,
autoWrapCol: true,
licenseKey: 'non-commercial-and-evaluation',
});
const exportPlugin: ExportFile = hot.getPlugin('exportFile');
const button = document.querySelector('#export-blob')!;
button.addEventListener('click', () => {
const exportedBlob = exportPlugin.exportAsBlob('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: false,
exportHiddenRows: false,
mimeType: 'text/csv',
rowDelimiter: '\r\n',
rowHeaders: true,
});
console.log(exportedBlob);
});
HTML
<div class="example-controls-container">
<div class="controls">
<button id="export-blob">Export as a Blob</button>
</div>
</div>
<div id="example2"></div>

Export as a string

Open a console in browser developer tools to see the result for the below example. Like the Blob example, this export uses only visible data and skips hidden rows and columns.

JavaScript
import Handsontable from 'handsontable/base';
import { registerAllModules } from 'handsontable/registry';
// Register all Handsontable's modules.
registerAllModules();
const container = document.querySelector('#example3');
const hot = new Handsontable(container, {
data: [
['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'],
['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'],
['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'],
['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'],
['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'],
['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'],
['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'],
],
colHeaders: true,
rowHeaders: true,
hiddenRows: { rows: [1, 3, 5], indicators: true },
hiddenColumns: { columns: [1, 3, 5], indicators: true },
height: 'auto',
autoWrapRow: true,
autoWrapCol: true,
licenseKey: 'non-commercial-and-evaluation',
});
const exportPlugin = hot.getPlugin('exportFile');
const button = document.querySelector('#export-string');
button.addEventListener('click', () => {
const exportedString = exportPlugin.exportAsString('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: false,
exportHiddenRows: false,
rowDelimiter: '\r\n',
rowHeaders: true,
});
console.log(exportedString);
});
TypeScript
import Handsontable from 'handsontable/base';
import { registerAllModules } from 'handsontable/registry';
import { ExportFile } from 'handsontable/plugins';
// Register all Handsontable's modules.
registerAllModules();
const container = document.querySelector('#example3')!;
const hot = new Handsontable(container, {
data: [
['Spring Launch', 'Email', 'North America', '1240', '4.2%', '$12000', 'Q1 2025'],
['Partner Webinar', 'Paid Search', 'EMEA', '860', '6.1%', '$9400', 'Q1 2025'],
['Summer Upsell', 'Social', 'APAC', '1520', '3.7%', '$13800', 'Q2 2025'],
['Product Video', 'Email', 'North America', '980', '5.4%', '$8600', 'Q2 2025'],
['Back-to-School', 'Display', 'LATAM', '1110', '4.8%', '$10100', 'Q3 2025'],
['Holiday Teaser', 'Affiliate', 'EMEA', '1340', '5.9%', '$12700', 'Q4 2025'],
['Loyalty Drive', 'SMS', 'APAC', '790', '7.3%', '$6200', 'Q4 2025'],
],
colHeaders: true,
rowHeaders: true,
hiddenRows: { rows: [1, 3, 5], indicators: true },
hiddenColumns: { columns: [1, 3, 5], indicators: true },
height: 'auto',
autoWrapRow: true,
autoWrapCol: true,
licenseKey: 'non-commercial-and-evaluation',
});
const exportPlugin: ExportFile = hot.getPlugin('exportFile');
const button = document.querySelector('#export-string')!;
button.addEventListener('click', () => {
const exportedString = exportPlugin.exportAsString('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: false,
exportHiddenRows: false,
rowDelimiter: '\r\n',
rowHeaders: true,
});
console.log(exportedString);
});
HTML
<div class="example-controls-container">
<div class="controls">
<button id="export-string">Export as a string</button>
</div>
</div>
<div id="example3"></div>

Prevent CSV Injection attack

“CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. When a spreadsheet program such as Microsoft Excel or LibreOffice Calc is used to open a CSV, any cells starting with = will be interpreted by the software as a formula.” (from OWASP website)

To prevent this attack, set the sanitizeValues option when exporting your data in CSV format.

JavaScript
import Handsontable from 'handsontable/base';
import { registerAllModules } from 'handsontable/registry';
// Register all Handsontable's modules.
registerAllModules();
const container = document.querySelector('#example4');
const hot = new Handsontable(container, {
data: [
['https://api.acme-inventory.com/live-stock', '=WEBSERVICE("https://api.acme-inventory.com/live-stock")'],
['https://status.vertex-logistics.com/feed', '=WEBSERVICE("https://status.vertex-logistics.com/feed")'],
['http://malicious.example/payload.exe', '=CMD("| calc.exe")'],
['https://news.example.com/q2-briefing', '=HYPERLINK("http://malicious.example","Open report")'],
['https://cdn.example.com/daily.csv', '+SUM(1,1)'],
],
colHeaders: true,
rowHeaders: true,
height: 'auto',
autoWrapRow: true,
autoWrapCol: true,
licenseKey: 'non-commercial-and-evaluation',
});
const exportPlugin = hot.getPlugin('exportFile');
document.querySelector('#no-sanitization').addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
});
});
document.querySelector('#recommended-sanitization').addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
sanitizeValues: true,
});
});
document.querySelector('#regexp-sanitization').addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
sanitizeValues: /WEBSERVICE|CMD|HYPERLINK|^\+/,
});
});
document.querySelector('#function-sanitization').addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
sanitizeValues: (value) => {
return /WEBSERVICE|CMD|HYPERLINK|^\+/.test(value) ? 'REMOVED SUSPICIOUS CELL CONTENT' : value;
},
});
});
TypeScript
import Handsontable from 'handsontable/base';
import { registerAllModules } from 'handsontable/registry';
import { ExportFile } from 'handsontable/plugins';
// Register all Handsontable's modules.
registerAllModules();
const container = document.querySelector('#example4')!;
const hot = new Handsontable(container, {
data: [
['https://api.acme-inventory.com/live-stock', '=WEBSERVICE("https://api.acme-inventory.com/live-stock")'],
['https://status.vertex-logistics.com/feed', '=WEBSERVICE("https://status.vertex-logistics.com/feed")'],
['http://malicious.example/payload.exe', '=CMD("| calc.exe")'],
['https://news.example.com/q2-briefing', '=HYPERLINK("http://malicious.example","Open report")'],
['https://cdn.example.com/daily.csv', '+SUM(1,1)'],
],
colHeaders: true,
rowHeaders: true,
height: 'auto',
autoWrapRow: true,
autoWrapCol: true,
licenseKey: 'non-commercial-and-evaluation',
});
const exportPlugin: ExportFile = hot.getPlugin('exportFile');
document.querySelector('#no-sanitization')!.addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
});
});
document.querySelector('#recommended-sanitization')!.addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
sanitizeValues: true,
});
});
document.querySelector('#regexp-sanitization')!.addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
sanitizeValues: /WEBSERVICE|CMD|HYPERLINK|^\+/,
});
});
document.querySelector('#function-sanitization')!.addEventListener('click', () => {
exportPlugin.downloadFile('csv', {
bom: false,
columnDelimiter: ',',
colHeaders: false,
exportHiddenColumns: true,
exportHiddenRows: true,
fileExtension: 'csv',
filename: 'Handsontable-CSV-file_[YYYY]-[MM]-[DD]',
mimeType: 'text/csv',
rowDelimiter: '\r\n',
sanitizeValues: (value) => {
return /WEBSERVICE|CMD|HYPERLINK|^\+/.test(value) ? 'REMOVED SUSPICIOUS CELL CONTENT' : value;
},
});
});
HTML
<div class="example-controls-container">
<div class="controls">
<button id="no-sanitization">Download CSV with no sanitization</button>
<button id="recommended-sanitization">Download CSV with recommended sanitization</button>
<button id="regexp-sanitization">Download CSV with sanitization using a regexp</button>
<button id="function-sanitization">Download CSV with sanitization using a function</button>
</div>
</div>
<div id="example4"></div>

Result

After completing this guide, you can export grid data as a downloadable CSV file, a JavaScript Blob, or a string. You can customize delimiters, ranges, headers, and value sanitization through the export configuration.

Available methods

The plugin exposes the following methods to export data.

Each method takes two parameters. The first, format, is required. The second, options, is an optional object that overrides or extends the default export configuration. The table below lists all supported options for CSV export.

Available options in the export configuration

PropertyType / DefaultDescription
bomBoolean, default truePrepend output with BOM (UTF-8). Browser uses EF BB BF.
colHeadersBoolean, default falseInclude column headers. Does not support the NestedHeaders plugin.
columnDelimiterString, default ','Column delimiter.
exportHiddenColumnsBoolean, default falseInclude hidden columns.
exportHiddenRowsBoolean, default falseInclude hidden rows.
fileExtensionString, default 'csv'File extension. Used by downloadFile().
filenameString, default 'Handsontable [YYYY]-[MM]-[DD]'File name. Placeholders [YYYY], [MM], [DD] are replaced with the current date. Used by downloadFile().
mimeTypeString, default 'text/csv'MIME type. Used by downloadFile() and exportAsBlob().
rangeArray, default []Cell range to export: [startRow, startColumn, endRow, endColumn] (visual indexes).
rowDelimiterString, default '\r\n'Row delimiter.
rowHeadersBoolean, default falseInclude row headers.
sanitizeValuesBoolean | RegExp | Function, default falseValue sanitization. true = OWASP CSV injection rules; RegExp = escape matching values; Function = replace with return value.

Plugins