Skip to content

Password Breach Checker API

Network tool
POST https://api.findutils.com/api/tools/password-breach-checker/execute

Return whether a password appears in known data breaches and how many times, using the Have I Been Pwned k-anonymity range API. Send `password` and it travels to this API over TLS, is hashed here, and only the first 5 characters of its SHA-1 go on to HIBP; the request body is not logged. For end-to-end k-anonymity send `sha1_prefix` (the first 5 hex characters of the SHA-1 you computed) instead, and match your own suffix in the returned `range`.

Request body

application/json
  • password

    string optional

    The password to check. Over this API it is sent to FindUtils over TLS, hashed server-side, and only the 5-character SHA-1 prefix goes to Have I Been Pwned; it is not logged or returned. Use sha1_prefix instead to keep the password on your side.

  • sha1_prefix

    string optional

    The first 5 hex characters of the SHA-1 hash you computed yourself. Returns every breached suffix in that range; find yours in `range` to finish the check without sending the password or its full hash.

Example arguments

Verified
{
  "password": "password"
}