Skip to content
Passwordify
Breach check

Has your password been breached?

Check any password against 900M+ credentials exposed in real breaches — using k-anonymity, so your password stays on your device.

Privacy by design

How k-anonymity protects you

You should never type a password into a site that sends it away to “check” it. This tool doesn't have to — here's the exact flow.

  1. 01

    Hash locally

    Your password is hashed with SHA-1 inside your browser. The raw password never leaves the page.

  2. 02

    Send 5 characters

    Only the first five hex characters of that hash are sent to the Pwned Passwords API.

  3. 03

    Match on device

    The API returns every hash sharing that prefix. Your browser finds the match — the server never learns which one was yours.

Found in a breach? Do this.

  • Stop using it everywhere. Attackers try leaked passwords across every site (credential stuffing).
  • Change it on that account first, then anywhere you reused it.
  • Replace it with a long, unique, randomly generated password or passphrase.
  • Turn on two-factor authentication — ideally a passkey or an authenticator app.
Generate a safe replacement
breach.js
// The whole client-side check, distilled const hash = sha1(password); // in-browser const prefix = hash.slice(0, 5); await fetch(`/range/${prefix}`); // 5 chars only // → match the suffix locally. Done.

Screen breached passwords at signup

The /v1/breach endpoint does this k-anonymity check server-side.