Breach check
Has your password been breached?
Check any password against 900M+ credentials exposed in real breaches — using k-anonymity, so your password stays on your device.
Privacy by design
How k-anonymity protects you
You should never type a password into a site that sends it away to “check” it. This tool doesn't have to — here's the exact flow.
-
01
Hash locally
Your password is hashed with SHA-1 inside your browser. The raw password never leaves the page.
-
02
Send 5 characters
Only the first five hex characters of that hash are sent to the Pwned Passwords API.
-
03
Match on device
The API returns every hash sharing that prefix. Your browser finds the match — the server never learns which one was yours.
Found in a breach? Do this.
- Stop using it everywhere. Attackers try leaked passwords across every site (credential stuffing).
- Change it on that account first, then anywhere you reused it.
- Replace it with a long, unique, randomly generated password or passphrase.
- Turn on two-factor authentication — ideally a passkey or an authenticator app.
// The whole client-side check, distilled
const hash = sha1(password); // in-browser
const prefix = hash.slice(0, 5);
await fetch(`/range/${prefix}`); // 5 chars only
// → match the suffix locally. Done.
Screen breached passwords at signup
The /v1/breach endpoint does this k-anonymity check server-side.