Skip to content
Passwordify
For developers

Password security, as an API.

Add the strength scoring, breach screening and policy checks from these tools to your own signup and password-reset flows — one endpoint, no corpus to host, nothing logged.

Try it now with the demo key pk_test_passwordify_demo
Live playground runs locally
password
POST/api/v1/validate
REQUEST BODY
{ "password": "Summer2024!" }
RESPONSE
…

This playground runs in your browser with the same engine that powers the API — no key needed here.

Endpoints

Four calls. Everything you need.

POST /v1/strength

Score a password 0–4 with zxcvbn. Returns guesses, entropy, crack time and actionable feedback.

POST /v1/breach

Check a password against 900M+ breached credentials via k-anonymity — server-side, no corpus to host.

POST /v1/validate

One call for a NIST 800-63B verdict: strength + breach + policy, returning a clean list of violations.

POST /v1/generate

Generate CSPRNG passwords and passphrases from your backend, with an entropy estimate.

Why build on it

The boring parts, handled.

Ship in an afternoon

A single REST endpoint replaces a pile of regex rules and a breach corpus you would otherwise host and update yourself.

Nothing is logged

Passwords sent to the API are processed in memory and never written to disk or logs. Only per-key request counts are kept, for billing.

Standards, not guesswork

Validation follows current NIST 800-63B guidance — screen breaches, drop the arbitrary composition rules and forced expiry.

Predictable & documented

Consistent JSON, real HTTP status codes, rate-limit headers, and examples in curl, JS, C# and Python.

Quickstart

Your first request

Send any password to /v1/validate with the demo key and you'll get a full verdict back. Swap in a live key when you're ready for production traffic.

  • Base URL https://www.passwordify.xyz/api
  • API-key auth via the X-API-Key header
  • JSON in, JSON out — always
quickstart.sh
curl https://www.passwordify.xyz/api/v1/validate \ -H "X-API-Key: pk_test_passwordify_demo" \ -H "Content-Type: application/json" \ -d '{"password":"hunter2"}' { "valid": false, "score": 0, "breached": true, "breachCount": 64627, "violations": ["weak", "found_in_breach"] }
Get started

Need a production key?

Sign in and create your API key in seconds — no sales call, no waitlist. Start on the Free plan and upgrade to Pro from $1.50/mo when you need more volume.