100% in-browser · your passwords are never transmitted

Has Your Password Been Leaked? Check Breaches Safely

Check if your password appears in known data breaches using Have-I-Been-Pwned k-anonymity. Only a 5-char hash prefix leaves your device — your password NEVER does. 100% private. Free.

Loading tool…

More tools

All free, all private — everything runs in your browser.

How to use Password Breach Checker

  1. 1Type or paste a password to check. Your browser SHA-1 hashes it locally.
  2. 2Only the first 5 hex characters of the hash are sent to the Have-I-Been-Pwned API.
  3. 3Your browser receives hundreds of matching suffixes and checks for a match locally.
  4. 4See instantly whether the password appears in known breaches — the full password never left your device.

Password Breach Checker FAQ

How can this be safe if it checks a remote database?
It uses k-anonymity. Your browser SHA-1 hashes the password, then sends ONLY the first 5 hex characters of that hash to the Have-I-Been-Pwned API. The API returns every leaked suffix that shares that prefix (hundreds of them), and your browser checks the match locally. The full password — or its full hash — never leaves your device.
What should I do if my password was found in a breach?
Change it everywhere you used it, and never reuse it again. Generate a fresh, strong password here, and store it in a password manager so each account has its own unique password.