Simple pricing, indie-friendly.
The strength analyzer, breach checker, and generator are free in your browser — unlimited, no account. When you’re ready to add the same checks to your app, Pro starts at $1.50/mo.
Free
For learning, prototypes, and personal projects.
$0 /mo
No card required
- Unlimited browser tools — forever
- 1,000 API requests / mo
- 1 API key
- Strength, breach, validate & generate
- Community support
Pro
For production apps validating real signups.
$2 /mo
Billed monthly
- Everything in Free
- 100,000 API requests / mo
- 5 API keys
- Higher burst limits
- Email support
Prefer to pay less? Annual billing saves 25% — $1.50/mo, billed as $18 once a year. Upgrades are handled securely by Stripe; cancel anytime from your dashboard.
Free and Pro, side by side.
| Feature | Free | Pro |
|---|---|---|
| Browser tools (strength, breach, generator) | Unlimited | Unlimited |
| Monthly API requests | 1,000 | 100,000 |
| API keys | 1 | 5 |
| Strength endpoint | ||
| Breach endpoint | ||
| Validate endpoint (NIST 800-63B) | ||
| Generate endpoint | ||
| Support | Community |
Questions, answered.
Are the browser tools really free?
Yes — the strength analyzer, breach checker, and generator are unlimited and free on every plan, with no account and no expiry. They run entirely in your browser.
What counts as a request?
One call to any /v1 endpoint (strength, breach, validate, or generate) is one request, regardless of payload size. Generating several passwords in one /v1/generate call still counts as a single request.
What happens if I hit my monthly limit?
Requests beyond your plan’s monthly quota return a 429 with a clear quota_exceeded error and X-Quota-* headers, so you always know where you stand. Upgrade to Pro for 100× the headroom.
Can I cancel anytime?
Yes. Manage or cancel your subscription from your dashboard at any time via the Stripe billing portal. Annual plans run until the end of the paid period.
Do you store passwords sent to the API?
No. Passwords are processed in memory for the duration of the request and are never logged, cached, or persisted. Only per-key request counts are kept, for billing.
How do breach checks stay private?
k-anonymity. The password is hashed with SHA-1 and only the first 5 hex characters of the hash are used to query the breach corpus — the full hash and the password never leave your control.
Start free, upgrade when you need to.
Every plan runs the same zxcvbn scoring, k-anonymity breach checks, and NIST 800-63B validation — only the request volume changes.