Skip to content
Passwordify
Developer API

The password validation API with a NIST verdict built in.

Most APIs give you a raw score, or a raw breach hit. Passwordify’s /v1/validate returns a single, actionable pass/fail against NIST 800-63B — length, real strength, and breach exposure — in one call. Add it to your signup and password-reset flows in an afternoon.

One call, complete verdict

Everything a password check needs.

  • Strength — real zxcvbn scoring (pattern, dictionary and keyboard-walk aware), not a naïve character-count meter.
  • Breach — k-anonymity screening against hundreds of millions of leaked credentials; the password never leaves your control.
  • Policy — a NIST 800-63B verdict with a clean list of violations you can surface to users.
validate.sh
curl https://www.passwordify.xyz/api/v1/validate \ -H "X-API-Key: pk_test_passwordify_demo" \ -H "Content-Type: application/json" \ -d '{"password":"hunter2"}' { "valid": false, "score": 0, "breached": true, "breachCount": 64627, "violations": ["weak", "found_in_breach"] }
Why not roll your own

Skip the corpus, the cron jobs, and the guesswork.

No breach corpus to host

Downloading, storing and continuously updating a multi-gigabyte breach corpus is a project of its own. One HTTP call replaces it.

Standards, not regex

Composition rules and forced expiry actively hurt security. Get a NIST 800-63B-aligned verdict instead of maintaining brittle regex.

Privacy by construction

Breach checks use k-anonymity and nothing is logged. Compliant-by-default handling of the most sensitive field in your app.

Indie-friendly pricing

Self-serve from $1.50/mo — no enterprise quote, no minimums. Start free with 1,000 requests a month.

FAQ

Password validation, answered.

What is a password validation API?

A password validation API takes a password and returns a verdict on whether it is acceptable — typically checking length, real-world strength, and whether it appears in known data breaches. Passwordify’s /v1/validate does all three in a single call and returns a clean pass/fail with a list of violations.

Does this follow NIST 800-63B?

Yes. /v1/validate implements current NIST 800-63B guidance: it enforces a sensible minimum length, screens the password against a large breach corpus, and drops outdated rules like forced composition and periodic expiry. You can tune the policy per request.

Do you store the passwords I send?

No. Passwords are processed in memory for the duration of the request and are never logged, cached, or persisted. Breach checks use k-anonymity, so only a short hash prefix is used for the lookup.

How much does it cost?

The Free plan includes 1,000 API requests per month. Pro is $2/mo (or $1.50/mo billed annually) with 100,000 requests per month. No sales call, no enterprise quote — sign up and get a key.