Has this password appeared in known data breaches?

Checks whether a password appears in known data breaches, and how often. Private: only the first 5 characters of its SHA-1 hash leave our server.

Request

POSThttps://password-security-toolkit.p.apihiver.com/v1/breach-check

JSON object. Required: password.

Request Body

Edit the values below to test different scenarios.

Parameters and body structure are inherited from this endpoint's definition. Changes here only apply to this test run.

Language
Client
1curl --request POST \
2  --url https://password-security-toolkit.p.apihiver.com/v1/breach-check \
3  --header 'Accept: application/json' \
4  --header 'Content-Type: application/json' \
5  --header 'X-API-Key: YOUR_API_KEY' \
6  --data '{
7  "password": "password123"
8}'

Has this password appeared in known data breaches?: Password Security API reference

Checks whether a password appears in known data breaches, and how often. Private: only the first 5 characters of its SHA-1 hash leave our server. This endpoint is part of the Password Security API: Password strength scoring, private breach checks against known leaked passwords, secure password generation, hashing and bcrypt checks.

Example response (200, application/json)

Success.

1{
2  "method": "k-anonymity (only 5 characters of the SHA-1 hash are sent)",
3  "breached": true,
4  "times_seen": 2266543
5}

Errors

  • 400 — A required parameter is missing or a value has the wrong format.
    1{
    2  "error": {
    3    "code": "INVALID_INPUT",
    4    "message": "password: Field required"
    5  }
    6}

Gateway errors (missing key, no subscription, rate limits) are listed in Error codes.