Password Breach Checker API
Network toolhttps://api.findutils.com/api/tools/password-breach-checker/execute Return whether a password appears in known data breaches and how many times, using the Have I Been Pwned k-anonymity range API. Send `password` and it travels to this API over TLS, is hashed here, and only the first 5 characters of its SHA-1 go on to HIBP; the request body is not logged. For end-to-end k-anonymity send `sha1_prefix` (the first 5 hex characters of the SHA-1 you computed) instead, and match your own suffix in the returned `range`.
Request body
application/json-
password
string optional
The password to check. Over this API it is sent to FindUtils over TLS, hashed server-side, and only the 5-character SHA-1 prefix goes to Have I Been Pwned; it is not logged or returned. Use sha1_prefix instead to keep the password on your side.
-
sha1_prefix
string optional
The first 5 hex characters of the SHA-1 hash you computed yourself. Returns every breached suffix in that range; find yours in `range` to finish the check without sending the password or its full hash.
Example arguments
Verified{
"password": "password"
} More Security tools
- Base32 Encode Encode UTF-8 text to RFC 4648 base32 (uppercase, "=" padding).
- Csp Generate Build a Content-Security-Policy header from a preset (strict, typical, google-analytics) and/or your own directives, and get the header…
- Data Sanitizer Sanitize untrusted text and return the cleaned output, a list of changes made, and a risk level.
- Dnpm Configurator Returns the five files of a hardened Docker-based npm wrapper (the ./dnpm bash script, .dnpm/Dockerfile, docker-compose.node.yml…
- Email Header Analyzer Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop…
- Hash Comparison Tool Hash text with MD5, SHA-1, SHA-256, SHA-384, or SHA-512 and compare the hex digest with an expected hash.