The password validation API with a NIST verdict built in.
Most APIs give you a raw score, or a raw breach hit. Passwordify’s /v1/validate returns a single, actionable pass/fail against NIST 800-63B — length, real strength, and breach exposure — in one call. Add it to your signup and password-reset flows in an afternoon.
Everything a password check needs.
- Strength — real zxcvbn scoring (pattern, dictionary and keyboard-walk aware), not a naïve character-count meter.
- Breach — k-anonymity screening against hundreds of millions of leaked credentials; the password never leaves your control.
- Policy — a NIST 800-63B verdict with a clean list of violations you can surface to users.
curl https://www.passwordify.xyz/api/v1/validate \
-H "X-API-Key: pk_test_passwordify_demo" \
-H "Content-Type: application/json" \
-d '{"password":"hunter2"}'
{
"valid": false,
"score": 0,
"breached": true,
"breachCount": 64627,
"violations": ["weak", "found_in_breach"]
}
Skip the corpus, the cron jobs, and the guesswork.
No breach corpus to host
Downloading, storing and continuously updating a multi-gigabyte breach corpus is a project of its own. One HTTP call replaces it.
Standards, not regex
Composition rules and forced expiry actively hurt security. Get a NIST 800-63B-aligned verdict instead of maintaining brittle regex.
Privacy by construction
Breach checks use k-anonymity and nothing is logged. Compliant-by-default handling of the most sensitive field in your app.
Indie-friendly pricing
Self-serve from $1.50/mo — no enterprise quote, no minimums. Start free with 1,000 requests a month.
Password validation, answered.
What is a password validation API?
A password validation API takes a password and returns a verdict on whether it is acceptable — typically checking length, real-world strength, and whether it appears in known data breaches. Passwordify’s /v1/validate does all three in a single call and returns a clean pass/fail with a list of violations.
Does this follow NIST 800-63B?
Yes. /v1/validate implements current NIST 800-63B guidance: it enforces a sensible minimum length, screens the password against a large breach corpus, and drops outdated rules like forced composition and periodic expiry. You can tune the policy per request.
Do you store the passwords I send?
No. Passwords are processed in memory for the duration of the request and are never logged, cached, or persisted. Breach checks use k-anonymity, so only a short hash prefix is used for the lookup.
How much does it cost?
The Free plan includes 1,000 API requests per month. Pro is $2/mo (or $1.50/mo billed annually) with 100,000 requests per month. No sales call, no enterprise quote — sign up and get a key.