Slik beskytter k-anonymitet passordet ditt
Only the first 5 characters of your password's SHA-1 hash are sent to the API. The API returns ~800 possible matches for that prefix, and we check the rest locally. Your full password never leaves your browser.
(Dokumentasjon på engelsk)
What it does
Reusing a password that has already leaked is one of the most common ways accounts get taken over. This tool checks a password against Pwned Passwords — the corpus of hundreds of millions of real passwords from known data breaches maintained by Have I Been Pwned (HIBP) — and tells you how many times it has appeared in a breach.
It does this with k-anonymity: the password is SHA-1 hashed in your browser, and only the first 5 characters of the hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
suffix that shares that prefix (about 800 candidates), and your browser matches the remaining 35 characters locally. The API never sees enough information to reconstruct your password — even a hostile operator could not learn it.How to use it
- Type or paste a password into the field. Use the eye toggle to show or hide it.
- Click Check password (or press Enter). The lookup takes a moment while the
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
is computed and the range is fetched. - Read the verdict: a green box means the password has not been found in any known breach; a red box shows exactly how many breaches it appeared in.
- Expand How k-anonymity protects your password to see the
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
prefix that was sent and how many candidate hashes were checked locally.
If the lookup cannot reach the API, the tool says so explicitly — an unreachable network is never reported as “no breaches found”.
Examples
Checking the password password:
SHA-1 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8
Sent to API 5BAA6 (the only 5 characters that leave your browser)
Checked ~800 candidate suffixes returned for that prefix, matched locally
Result This password appeared in 3.7M+ data breaches ✗ (the live count is shown)
Checking a long random password:
Input Zx9#qL-vTtR2mW4n
Flow hash locally → send the 5-char prefix → match the suffix against ~800 candidates
Result This password has not been found in any known breaches ✓
Good to know
- Your password never leaves your browser. The SHA-1
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
is computed locally with the Web Crypto API, and only 5 of its 40 hex characters are transmitted. That prefix identifies a bucket of ~800 hashes, not your password. - “Not found” is not “strong”. The check only says the exact password is absent from known breach corpora.
Tr0ub4dor&3-style guesses can be absent yet still weak — pair this with the Password Strength Analyser and a generated password. - SHA-1 is fine here. The
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
is used as a lookup key, not for authentication. A preimage attack on SHA-1 would not help an attacker who only ever receives 5 hex characters of it. - Related tools: Password Strength Analyser, Password Generator, Passphrase Generator.