NIST 800-63B password checks, in one API call.
The modern standard is clear: screen for breaches, allow long passphrases, and drop the arbitrary rules. Passwordify’s /v1/validate turns that guidance into a single pass/fail verdict — so your signup flow is compliant by default.
What the standard asks for
- Require a reasonable minimum length (8+), allow long passphrases
- Screen new passwords against known breach corpora
- Accept all printable characters, including spaces and Unicode
- Give clear, specific feedback when a password is rejected
What it drops
- Force composition rules (upper + lower + number + symbol)
- Expire passwords on a fixed schedule with no cause
- Use knowledge-based “security questions”
- Truncate or silently strip characters
A compliant verdict, instantly.
Send a password to /v1/validate and get back whether it passes, its strength score, breach status, and the exact violations to show the user.
curl https://www.passwordify.xyz/api/v1/validate \
-H "X-API-Key: pk_test_passwordify_demo" \
-H "Content-Type: application/json" \
-d '{"password":"correct horse","policy":{"minLength":12}}'
{
"valid": true,
"score": 3,
"breached": false,
"violations": []
}
NIST 800-63B, answered.
What is NIST 800-63B?
NIST Special Publication 800-63B is the U.S. standard for digital identity authentication. Its password (“memorized secret”) guidance recommends screening against breached passwords and a minimum length, while dropping forced composition rules and periodic expiry.
How does Passwordify implement it?
The /v1/validate endpoint enforces a configurable minimum length, screens the password against a large breach corpus using k-anonymity, and runs zxcvbn strength analysis — returning a single valid/invalid verdict plus a list of violations.
Can I customise the policy?
Yes. Each request can set minLength, recommendedLength, maxLength and whether to screen breaches, so you can match your own policy while staying aligned with the standard.