Password Breach Check (HIBP)
Check whether a password has appeared in known data breaches using the Have I Been Pwned range API. Only the first 5 hash characters are ever sent — your password never leaves the browser.
How it works: the password is hashed with SHA-1 locally, and only the first 5 hex characters of that hash are sent to the Have I Been Pwned range API. The full password and hash never leave your browser.
Check a common password
Enter a password you’re curious about and this checks it against hundreds of millions of breached hashes.
Requires an internet connection. Only the first 5 characters of the SHA-1 hash are sent — never the password itself.
FAQ
How does this stay private?
Your password is hashed with SHA-1 entirely in your browser. Only the first 5 hex characters of that hash are sent to the Have I Been Pwned range API, so the full password and full hash never leave your device.
What does “found in a breach” mean?
It means that exact password appears in the Have I Been Pwned corpus of passwords harvested from known data breaches. Someone could try it against your accounts, so change it immediately and use it nowhere else.
Is it safe to check my real password here?
Yes. Because only a 5-character hash prefix is transmitted, even the server performing the lookup cannot reconstruct your password. This is the same k-anonymity technique used by Have I Been Pwned itself.
What should I do if it is breached?
Stop using that password everywhere, change it on any site that used it, and consider a password manager to generate unique random passwords. You can also use the Random Token Generator here to create a strong replacement.