Password Security API
FreemiumPassword strength scoring, private breach checks against known leaked passwords, secure password generation, hashing and bcrypt checks.
Documentation
Password strength scoring, private breach checks against known leaked passwords, secure password generation, hashing and bcrypt checks.
What you get
- Strength score (0–4) with crack-time estimate and tips
- Breach check — has this password leaked? Uses k-anonymity: the password never leaves our server
- Generate strong random passwords
- Hash with SHA-256, SHA-512, bcrypt and more, and verify bcrypt hashes
Great for sign-up and password-change forms, security audits, admin tools and education.
Quick start
Subscribe to a plan (the Basic plan is free), then call the API at https://password-security-toolkit.p.apihiver.com with your key in the X-API-Key header:
curl "https://password-security-toolkit.p.apihiver.com/v1/generate?length=16" \
-H "X-API-Key: YOUR_API_KEY"Endpoints
| Method | Path | What it does |
|---|---|---|
POST | /v1/strength | Score a password's strength (0–4) with crack-time estimates and advice |
POST | /v1/breach-check | Has this password appeared in known data breaches? |
GET | /v1/generate | Generate strong random passwords |
POST | /v1/hash | Hash text (MD5/SHA/BLAKE2/bcrypt) |
POST | /v1/verify-bcrypt | Check text against a bcrypt hash |
Open the Endpoints tab to see every parameter, example request and example response, and to try the API live.
Errors
Every error is JSON with the same shape:
{"error": {"code": "INVALID_INPUT", "message": "password: Field required"}}| HTTP | Code | Meaning |
|---|---|---|
| 400 | INVALID_INPUT | A parameter is missing or has the wrong format — the message says which |
| 401 | UNAUTHORIZED | Missing or invalid X-API-Key |
| 429 | — | Plan quota or rate limit reached (see the X-RateLimit-* headers) |
| 502 / 503 / 504 | — | A data source or the API server is temporarily unavailable — retry after a few seconds |
Data & privacy
Data comes from zxcvbn strength estimation and the Have I Been Pwned Pwned Passwords range API (only 5 characters of the hash are sent).
Password Security API FAQ
- Is the Password Security API free?
- Yes. The Basic plan is free and includes 500 requests per month — no card needed. Paid plans start at ₹299 per month for 10,000 requests.
- How much does the Password Security API cost?
- Basic: free for 500 requests; Pro: ₹299/month for 10,000 requests; Ultra: ₹999/month for 50,000 requests; Mega: ₹2,499/month for 2,00,000 requests. Billing is monthly and you can cancel any time.
- How do I use the Password Security API?
- Subscribe to a plan on APIHiver, create an API key in the Console, then send requests to https://password-security-toolkit.p.apihiver.com with your key in the X-API-Key header. You can also try every endpoint in the browser playground first.
- What endpoints does the Password Security API have?
- It has 5 endpoints: Score a password's strength (0–4) with crack-time estimates and advice (POST /v1/strength); Has this password appeared in known data breaches? (POST /v1/breach-check); Generate strong random passwords (GET /v1/generate); Hash text (MD5/SHA/BLAKE2/bcrypt) (POST /v1/hash); Check text against a bcrypt hash (POST /v1/verify-bcrypt).
- What are the Password Security API rate limits?
- Basic: 2 requests per second; Pro: 5 requests per second; Ultra: 10 requests per second; Mega: 20 requests per second. Monthly quotas depend on the plan; every response includes X-RateLimit headers showing what's left.
- Can I use one API key for the Password Security API and other APIs?
- Yes. One APIHiver key works for every API you subscribe to, so you don't need a separate account or key per provider.
Related APIs
Universities API
EducationBy APIHiver · Updated 1w ago
Search universities in 200+ countries, look up a university by web domain, and verify student email addresses.
Phone Number Validation API
SMSBy APIHiver · Updated 1w ago
Validate and format phone numbers for 240+ countries: valid or not, mobile or landline, carrier, region, and E.164 format.
Disposable Email Detection API
CommunicationBy APIHiver · Updated 1w ago
Detect throwaway and temporary email addresses (Mailinator, 10MinuteMail and 8,900+ more domains) at sign-up — single, batch or classify.
Email Validation API
MessagingBy APIHiver · Updated 1w ago
Validate email addresses: syntax, domain and mail-server (MX) checks, disposable detection, typo suggestions and normalisation.
IFSC, GSTIN & UPI Validation API (India)
PaymentsBy APIHiver · Updated 1w ago
Validate Indian payment details — IFSC (with bank and branch), GSTIN, UPI ID format — plus IBAN and card BIN checks.
Endpoints
5 endpoints — full list is in the sidebar on larger screens.