Hash text (MD5/SHA/BLAKE2/bcrypt)
Hashes text with MD5, SHA-1, SHA-256, SHA-512, SHA3-256, BLAKE2b or bcrypt.
Request
POSThttps://password-security-toolkit.p.apihiver.com/v1/hash
JSON object. Required: text.
Request Body
Edit the values below to test different scenarios.
Parameters and body structure are inherited from this endpoint's definition. Changes here only apply to this test run.
Language
Client
1curl --request POST \
2 --url https://password-security-toolkit.p.apihiver.com/v1/hash \
3 --header 'Accept: application/json' \
4 --header 'Content-Type: application/json' \
5 --header 'X-API-Key: YOUR_API_KEY' \
6 --data '{
7 "text": "hello",
8 "rounds": 4,
9 "algorithm": "bcrypt"
10}'Hash text (MD5/SHA/BLAKE2/bcrypt): Password Security API reference
Hashes text with MD5, SHA-1, SHA-256, SHA-512, SHA3-256, BLAKE2b or bcrypt. This endpoint is part of the Password Security API: Password strength scoring, private breach checks against known leaked passwords, secure password generation, hashing and bcrypt checks.
Hash text (MD5/SHA/BLAKE2/bcrypt): example requests in every language
POST /v1/hash in Shell (cURL)
curl --request POST \
--url https://password-security-toolkit.p.apihiver.com/v1/hash \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'X-API-Key: YOUR_API_KEY' \
--data '{
"text": "hello",
"rounds": 4,
"algorithm": "bcrypt"
}'POST /v1/hash in Shell (HTTPie)
echo '{
"text": "hello",
"rounds": 4,
"algorithm": "bcrypt"
}' | \
http POST https://password-security-toolkit.p.apihiver.com/v1/hash \
Accept:application/json \
Content-Type:application/json \
X-API-Key:YOUR_API_KEYPOST /v1/hash in Shell (Wget)
wget --quiet \
--method POST \
--header 'Content-Type: application/json' \
--header 'Accept: application/json' \
--header 'X-API-Key: YOUR_API_KEY' \
--body-data '{\n "text": "hello",\n "rounds": 4,\n "algorithm": "bcrypt"\n}' \
--output-document \
- https://password-security-toolkit.p.apihiver.com/v1/hashPOST /v1/hash in Node.js (http)
const http = require('https');
const options = {
method: 'POST',
hostname: 'password-security-toolkit.p.apihiver.com',
port: null,
path: '/v1/hash',
headers: {
'Content-Type': 'application/json',
Accept: 'application/json',
'X-API-Key': 'YOUR_API_KEY'
}
};
const req = http.request(options, function (res) {
const chunks = [];
res.on('data', function (chunk) {
chunks.push(chunk);
});
res.on('end', function () {
const body = Buffer.concat(chunks);
console.log(body.toString());
});
});
req.write(JSON.stringify({text: 'hello', rounds: 4, algorithm: 'bcrypt'}));
req.end();POST /v1/hash in Node.js (Request)
const request = require('request');
const options = {
method: 'POST',
url: 'https://password-security-toolkit.p.apihiver.com/v1/hash',
headers: {
'Content-Type': 'application/json',
Accept: 'application/json',
'X-API-Key': 'YOUR_API_KEY'
},
body: {text: 'hello', rounds: 4, algorithm: 'bcrypt'},
json: true
};
request(options, function (error, response, body) {
if (error) throw new Error(error);
console.log(body);
});POST /v1/hash in Node.js (Unirest)
const unirest = require('unirest');
const req = unirest('POST', 'https://password-security-toolkit.p.apihiver.com/v1/hash');
req.headers({
'Content-Type': 'application/json',
Accept: 'application/json',
'X-API-Key': 'YOUR_API_KEY'
});
req.type('json');
req.send({
text: 'hello',
rounds: 4,
algorithm: 'bcrypt'
});
req.end(function (res) {
if (res.error) throw new Error(res.error);
console.log(res.body);
});POST /v1/hash in Node.js (Axios)
const axios = require('axios').default;
const options = {
method: 'POST',
url: 'https://password-security-toolkit.p.apihiver.com/v1/hash',
headers: {
'Content-Type': 'application/json',
Accept: 'application/json',
'X-API-Key': 'YOUR_API_KEY'
},
data: {text: 'hello', rounds: 4, algorithm: 'bcrypt'}
};
try {
const { data } = await axios.request(options);
console.log(data);
} catch (error) {
console.error(error);
}POST /v1/hash in Node.js (Fetch)
const fetch = require('node-fetch');
const url = 'https://password-security-toolkit.p.apihiver.com/v1/hash';
const options = {
method: 'POST',
headers: {
'Content-Type': 'application/json',
Accept: 'application/json',
'X-API-Key': 'YOUR_API_KEY'
},
body: '{"text":"hello","rounds":4,"algorithm":"bcrypt"}'
};
try {
const response = await fetch(url, options);
const data = await response.json();
console.log(data);
} catch (error) {
console.error(error);
}POST /v1/hash in JavaScript (XMLHttpRequest)
const data = JSON.stringify({
text: 'hello',
rounds: 4,
algorithm: 'bcrypt'
});
const xhr = new XMLHttpRequest();
xhr.withCredentials = true;
xhr.addEventListener('readystatechange', function () {
if (this.readyState === this.DONE) {
console.log(this.responseText);
}
});
xhr.open('POST', 'https://password-security-toolkit.p.apihiver.com/v1/hash');
xhr.setRequestHeader('Content-Type', 'application/json');
xhr.setRequestHeader('Accept', 'application/json');
xhr.setRequestHeader('X-API-Key', 'YOUR_API_KEY');
xhr.send(data);POST /v1/hash in JavaScript (Axios)
import axios from 'axios';
const options = {
method: 'POST',
url: 'https://password-security-toolkit.p.apihiver.com/v1/hash',
headers: {
'Content-Type': 'application/json',
Accept: 'application/json',
'X-API-Key': 'YOUR_API_KEY'
},
data: {text: 'hello', rounds: 4, algorithm: 'bcrypt'}
};
try {
const { data } = await axios.request(options);
console.log(data);
} catch (error) {
console.error(error);
}POST /v1/hash in JavaScript (Fetch)
const url = 'https://password-security-toolkit.p.apihiver.com/v1/hash';
const options = {
method: 'POST',
headers: {
'Content-Type': 'application/json',
Accept: 'application/json',
'X-API-Key': 'YOUR_API_KEY'
},
body: '{"text":"hello","rounds":4,"algorithm":"bcrypt"}'
};
try {
const response = await fetch(url, options);
const data = await response.json();
console.log(data);
} catch (error) {
console.error(error);
}POST /v1/hash in JavaScript (jQuery)
const settings = {
async: true,
crossDomain: true,
url: 'https://password-security-toolkit.p.apihiver.com/v1/hash',
method: 'POST',
headers: {
'Content-Type': 'application/json',
Accept: 'application/json',
'X-API-Key': 'YOUR_API_KEY'
},
processData: false,
data: '{\n "text": "hello",\n "rounds": 4,\n "algorithm": "bcrypt"\n}'
};
$.ajax(settings).done(function (response) {
console.log(response);
});POST /v1/hash in Python (http.client)
import http.client
conn = http.client.HTTPSConnection("password-security-toolkit.p.apihiver.com")
payload = "{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}"
headers = {
'Content-Type': "application/json",
'Accept': "application/json",
'X-API-Key': "YOUR_API_KEY"
}
conn.request("POST", "/v1/hash", payload, headers)
res = conn.getresponse()
data = res.read()
print(data.decode("utf-8"))POST /v1/hash in Python (Requests)
import requests
url = "https://password-security-toolkit.p.apihiver.com/v1/hash"
payload = {
"text": "hello",
"rounds": 4,
"algorithm": "bcrypt"
}
headers = {
"Content-Type": "application/json",
"Accept": "application/json",
"X-API-Key": "YOUR_API_KEY"
}
response = requests.post(url, json=payload, headers=headers)
print(response.json())POST /v1/hash in PHP (cURL)
<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://password-security-toolkit.p.apihiver.com/v1/hash",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'text' => 'hello',
'rounds' => 4,
'algorithm' => 'bcrypt'
]),
CURLOPT_HTTPHEADER => [
"Accept: application/json",
"Content-Type: application/json",
"X-API-Key: YOUR_API_KEY"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}POST /v1/hash in PHP (Guzzle)
<?php
$client = new \GuzzleHttp\Client();
$response = $client->request('POST', 'https://password-security-toolkit.p.apihiver.com/v1/hash', [
'body' => '{
"text": "hello",
"rounds": 4,
"algorithm": "bcrypt"
}',
'headers' => [
'Accept' => 'application/json',
'Content-Type' => 'application/json',
'X-API-Key' => 'YOUR_API_KEY',
],
]);
echo $response->getBody();POST /v1/hash in PHP (PECL HTTP v1)
<?php
$request = new HttpRequest();
$request->setUrl('https://password-security-toolkit.p.apihiver.com/v1/hash');
$request->setMethod(HTTP_METH_POST);
$request->setHeaders([
'Content-Type' => 'application/json',
'Accept' => 'application/json',
'X-API-Key' => 'YOUR_API_KEY'
]);
$request->setContentType('application/json');
$request->setBody(json_encode([
'text' => 'hello',
'rounds' => 4,
'algorithm' => 'bcrypt'
]));
try {
$response = $request->send();
echo $response->getBody();
} catch (HttpException $ex) {
echo $ex;
}POST /v1/hash in PHP (PECL HTTP v2)
<?php
$client = new http\Client;
$request = new http\Client\Request;
$body = new http\Message\Body;
$body->append(json_encode([
'text' => 'hello',
'rounds' => 4,
'algorithm' => 'bcrypt'
]));
$request->setRequestUrl('https://password-security-toolkit.p.apihiver.com/v1/hash');
$request->setRequestMethod('POST');
$request->setBody($body);
$request->setHeaders([
'Content-Type' => 'application/json',
'Accept' => 'application/json',
'X-API-Key' => 'YOUR_API_KEY'
]);
$client->enqueue($request)->send();
$response = $client->getResponse();
echo $response->getBody();POST /v1/hash in Java (AsyncHttp)
AsyncHttpClient client = new DefaultAsyncHttpClient();
client.prepare("POST", "https://password-security-toolkit.p.apihiver.com/v1/hash")
.setHeader("Content-Type", "application/json")
.setHeader("Accept", "application/json")
.setHeader("X-API-Key", "YOUR_API_KEY")
.setBody("{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}")
.execute()
.toCompletableFuture()
.thenAccept(System.out::println)
.join();
client.close();POST /v1/hash in Java (java.net.http)
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://password-security-toolkit.p.apihiver.com/v1/hash"))
.header("Content-Type", "application/json")
.header("Accept", "application/json")
.header("X-API-Key", "YOUR_API_KEY")
.method("POST", HttpRequest.BodyPublishers.ofString("{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());POST /v1/hash in Java (OkHttp)
OkHttpClient client = new OkHttpClient();
MediaType mediaType = MediaType.parse("application/json");
RequestBody body = RequestBody.create(mediaType, "{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}");
Request request = new Request.Builder()
.url("https://password-security-toolkit.p.apihiver.com/v1/hash")
.post(body)
.addHeader("Content-Type", "application/json")
.addHeader("Accept", "application/json")
.addHeader("X-API-Key", "YOUR_API_KEY")
.build();
Response response = client.newCall(request).execute();POST /v1/hash in Java (Unirest)
HttpResponse<String> response = Unirest.post("https://password-security-toolkit.p.apihiver.com/v1/hash")
.header("Content-Type", "application/json")
.header("Accept", "application/json")
.header("X-API-Key", "YOUR_API_KEY")
.body("{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}")
.asString();POST /v1/hash in C# (HttpClient)
using System.Net.Http.Headers;
var client = new HttpClient();
var request = new HttpRequestMessage
{
Method = HttpMethod.Post,
RequestUri = new Uri("https://password-security-toolkit.p.apihiver.com/v1/hash"),
Headers =
{
{ "Accept", "application/json" },
{ "X-API-Key", "YOUR_API_KEY" },
},
Content = new StringContent("{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}")
{
Headers =
{
ContentType = new MediaTypeHeaderValue("application/json")
}
}
};
using (var response = await client.SendAsync(request))
{
response.EnsureSuccessStatusCode();
var body = await response.Content.ReadAsStringAsync();
Console.WriteLine(body);
}POST /v1/hash in C# (RestSharp)
var client = new RestClient("https://password-security-toolkit.p.apihiver.com/v1/hash");
var request = new RestRequest("", Method.Post);
request.AddHeader("Content-Type", "application/json");
request.AddHeader("Accept", "application/json");
request.AddHeader("X-API-Key", "YOUR_API_KEY");
request.AddParameter("application/json", "{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}", ParameterType.RequestBody);
var response = client.Execute(request);POST /v1/hash in Go (NewRequest)
package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://password-security-toolkit.p.apihiver.com/v1/hash"
payload := strings.NewReader("{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
req.Header.Add("Accept", "application/json")
req.Header.Add("X-API-Key", "YOUR_API_KEY")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(res)
fmt.Println(string(body))
}POST /v1/hash in Ruby (net::http)
require 'uri'
require 'net/http'
url = URI("https://password-security-toolkit.p.apihiver.com/v1/hash")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request["Accept"] = 'application/json'
request["X-API-Key"] = 'YOUR_API_KEY'
request.body = "{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}"
response = http.request(request)
puts response.read_bodyPOST /v1/hash in Swift (NSURLSession)
import Foundation
let headers = [
"Content-Type": "application/json",
"Accept": "application/json",
"X-API-Key": "YOUR_API_KEY"
]
let parameters = [
"text": "hello",
"rounds": 4,
"algorithm": "bcrypt"
] as [String : Any]
let postData = JSONSerialization.data(withJSONObject: parameters, options: [])
let request = NSMutableURLRequest(url: NSURL(string: "https://password-security-toolkit.p.apihiver.com/v1/hash")! as URL,
cachePolicy: .useProtocolCachePolicy,
timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data
let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
if (error != nil) {
print(error as Any)
} else {
let httpResponse = response as? HTTPURLResponse
print(httpResponse)
}
})
dataTask.resume()POST /v1/hash in Objective-C (NSURLSession)
#import <Foundation/Foundation.h>
NSDictionary *headers = @{ @"Content-Type": @"application/json",
@"Accept": @"application/json",
@"X-API-Key": @"YOUR_API_KEY" };
NSDictionary *parameters = @{ @"text": @"hello",
@"rounds": @4,
@"algorithm": @"bcrypt" };
NSData *postData = [NSJSONSerialization dataWithJSONObject:parameters options:0 error:nil];
NSMutableURLRequest *request = [NSMutableURLRequest requestWithURL:[NSURL URLWithString:@"https://password-security-toolkit.p.apihiver.com/v1/hash"]
cachePolicy:NSURLRequestUseProtocolCachePolicy
timeoutInterval:10.0];
[request setHTTPMethod:@"POST"];
[request setAllHTTPHeaderFields:headers];
[request setHTTPBody:postData];
NSURLSession *session = [NSURLSession sharedSession];
NSURLSessionDataTask *dataTask = [session dataTaskWithRequest:request
completionHandler:^(NSData *data, NSURLResponse *response, NSError *error) {
if (error) {
NSLog(@"%@", error);
} else {
NSHTTPURLResponse *httpResponse = (NSHTTPURLResponse *) response;
NSLog(@"%@", httpResponse);
}
}];
[dataTask resume];POST /v1/hash in Kotlin (OkHttp)
val client = OkHttpClient()
val mediaType = MediaType.parse("application/json")
val body = RequestBody.create(mediaType, "{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}")
val request = Request.Builder()
.url("https://password-security-toolkit.p.apihiver.com/v1/hash")
.post(body)
.addHeader("Content-Type", "application/json")
.addHeader("Accept", "application/json")
.addHeader("X-API-Key", "YOUR_API_KEY")
.build()
val response = client.newCall(request).execute()POST /v1/hash in C (libcurl)
CURL *hnd = curl_easy_init();
curl_easy_setopt(hnd, CURLOPT_CUSTOMREQUEST, "POST");
curl_easy_setopt(hnd, CURLOPT_URL, "https://password-security-toolkit.p.apihiver.com/v1/hash");
struct curl_slist *headers = NULL;
headers = curl_slist_append(headers, "Content-Type: application/json");
headers = curl_slist_append(headers, "Accept: application/json");
headers = curl_slist_append(headers, "X-API-Key: YOUR_API_KEY");
curl_easy_setopt(hnd, CURLOPT_HTTPHEADER, headers);
curl_easy_setopt(hnd, CURLOPT_POSTFIELDS, "{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}");
CURLcode ret = curl_easy_perform(hnd);POST /v1/hash in Clojure (clj-http)
(require '[clj-http.client :as client])
(client/post "https://password-security-toolkit.p.apihiver.com/v1/hash" {:headers {:X-API-Key "YOUR_API_KEY"}
:content-type :json
:form-params {:text "hello"
:rounds 4
:algorithm "bcrypt"}
:accept :json})POST /v1/hash in OCaml (CoHTTP)
open Cohttp_lwt_unix
open Cohttp
open Lwt
let uri = Uri.of_string "https://password-security-toolkit.p.apihiver.com/v1/hash" in
let headers = Header.add_list (Header.init ()) [
("Content-Type", "application/json");
("Accept", "application/json");
("X-API-Key", "YOUR_API_KEY");
] in
let body = Cohttp_lwt_body.of_string "{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}" in
Client.call ~headers ~body `POST uri
>>= fun (res, body_stream) ->
(* Do stuff with the result *)POST /v1/hash in R (httr)
library(httr)
url <- "https://password-security-toolkit.p.apihiver.com/v1/hash"
payload <- "{\n \"text\": \"hello\",\n \"rounds\": 4,\n \"algorithm\": \"bcrypt\"\n}"
encode <- "json"
response <- VERB("POST", url, body = payload, add_headers('X-API-Key' = 'YOUR_API_KEY'), content_type("application/json"), accept("application/json"), encode = encode)
content(response, "text")POST /v1/hash in PowerShell (Invoke-WebRequest)
$headers=@{}
$headers.Add("Content-Type", "application/json")
$headers.Add("Accept", "application/json")
$headers.Add("X-API-Key", "YOUR_API_KEY")
$response = Invoke-WebRequest -Uri 'https://password-security-toolkit.p.apihiver.com/v1/hash' -Method POST -Headers $headers -ContentType 'application/json' -Body '{
"text": "hello",
"rounds": 4,
"algorithm": "bcrypt"
}'POST /v1/hash in PowerShell (Invoke-RestMethod)
$headers=@{}
$headers.Add("Content-Type", "application/json")
$headers.Add("Accept", "application/json")
$headers.Add("X-API-Key", "YOUR_API_KEY")
$response = Invoke-RestMethod -Uri 'https://password-security-toolkit.p.apihiver.com/v1/hash' -Method POST -Headers $headers -ContentType 'application/json' -Body '{
"text": "hello",
"rounds": 4,
"algorithm": "bcrypt"
}'POST /v1/hash in HTTP (HTTP/1.1)
POST /v1/hash HTTP/1.1
Content-Type: application/json
Accept: application/json
X-Api-Key: YOUR_API_KEY
Host: password-security-toolkit.p.apihiver.com
Content-Length: 61
{
"text": "hello",
"rounds": 4,
"algorithm": "bcrypt"
}Example response (200, application/json)
Success.
1{
2 "hash": "$2b$04$ku91naBk2FJMLxevl0QU9.aADGvGT8OWFlW5RXFTOrkUVYbmGiboe",
3 "algorithm": "bcrypt"
4}Errors
- 400 — A required parameter is missing or a value has the wrong format.
1{ 2 "error": { 3 "code": "INVALID_INPUT", 4 "message": "text: Field required" 5 } 6}
Gateway errors (missing key, no subscription, rate limits) are listed in Error codes.
Other Password Security API endpoints
- POSTScore a password's strength (0–4) with crack-time estimates and advice
- POSTHas this password appeared in known data breaches?
- GETGenerate strong random passwords
- POSTCheck text against a bcrypt hash
Password Security API pricing →·Password Security API overview →