Score a password's strength (0–4) with crack-time estimates and advice

Scores a password from 0 (very weak) to 4 (very strong), estimates how long it would take to crack, and gives tips to improve it.

Request

POSThttps://password-security-toolkit.p.apihiver.com/v1/strength

JSON object. Required: password.

Request Body

Edit the values below to test different scenarios.

Parameters and body structure are inherited from this endpoint's definition. Changes here only apply to this test run.

Language
Client
1curl --request POST \
2  --url https://password-security-toolkit.p.apihiver.com/v1/strength \
3  --header 'Accept: application/json' \
4  --header 'Content-Type: application/json' \
5  --header 'X-API-Key: YOUR_API_KEY' \
6  --data '{
7  "password": "Tr0ub4dor&3"
8}'

Score a password's strength (0–4) with crack-time estimates and advice: Password Security API reference

Scores a password from 0 (very weak) to 4 (very strong), estimates how long it would take to crack, and gives tips to improve it. This endpoint is part of the Password Security API: Password strength scoring, private breach checks against known leaked passwords, secure password generation, hashing and bcrypt checks.

Example response (200, application/json)

Success.

1{
2  "score": 4,
3  "length": 11,
4  "rating": "very strong",
5  "warning": null,
6  "crack_time": {
7    "online": "centuries",
8    "online_throttled": "centuries",
9    "offline_fast_hash": "10 seconds",
10    "offline_slow_hash": "4 months"
11  },
12  "suggestions": [],
13  "guesses_log10": 11
14}

Errors

  • 400 — A required parameter is missing or a value has the wrong format.
    1{
    2  "error": {
    3    "code": "INVALID_INPUT",
    4    "message": "password: Field required"
    5  }
    6}

Gateway errors (missing key, no subscription, rate limits) are listed in Error codes.