P
Guides
Language
Tools
Password & Security
P
Password Strength Checker
Score any password and estimate crack time
P
Password Generator
Create strong random passwords up to 128 chars
R
Random String Generator
Random tokens, IDs and keys with any charset
P
Passphrase Generator
Memorable multi-word passphrases (Diceware)
T
TOTP / 2FA Code Generator
Time-based one-time codes and otpauth secrets
P
Password Breach Checker
Check if a password appeared in known breaches
here
Hash & Crypto
S
SHA-256 Generator
Hash text to a 64-char SHA-256 digest
M
MD5 Generator
Compute the 32-char MD5 checksum of any text
S
SHA-1 Generator
Generate the 40-char SHA-1 hash of any input
S
SHA-512 Generator
Hash text to a 128-character SHA-512 digest
H
HMAC Generator
HMAC-MD5, SHA-1, SHA-256 & SHA-512 with secret key
B
bcrypt Generator / Checker
Hash passwords with bcrypt and verify hashes
P
PBKDF2 Key Derivation
Derive keys from a password with salt and iterations
A
AES Encrypt / Decrypt Text
Encrypt text with AES-256-GCM and a password
F
File Hash / Checksum
Compute SHA hashes of any file locally
Networking
I
IP Address Checker
Identify IPv4 vs IPv6, public/private and more
I
IPv4 Calculator
Network, broadcast, hosts, subnet mask & wildcard
I
IPv6 Calculator
Expand, compress and subnet IPv6 addresses
S
Subnet Calculator
CIDR ranges, wildcard masks and usable hosts
M
MAC Address Generator
Random valid MAC addresses, unicast or multicast
P
Port Checker
Learn what each TCP/UDP port number means
D
DNS Lookup
Resolve A, AAAA, MX, NS, TXT and CNAME records
W
WHOIS Lookup
Domain registration, expiry and registrar info
Web & HTTP
H
HTTP Header Analyzer
Security, caching & SEO headers explained
U
User-Agent Parser
Decode browser, OS and device from any UA
M
MIME Type Lookup
File extension to MIME type reference
H
HTTP Status Code Lookup
Every status code 1xx–5xx explained
U
URL Encoder / Decoder
Percent-encode URLs and parse query strings
C
Color Contrast Checker (WCAG)
Check text contrast against WCAG AA & AAA
Developer Utilities
U
UUID / ULID Generator
UUID v4, v7, ULID and NanoID in bulk
J
JWT Decoder & Signer
Decode, inspect and sign JSON Web Tokens
B
Base64 Encoder / Decoder
Encode and decode Base64, standard or URL-safe
Q
QR Code Generator
QR codes for links, Wi-Fi and vCards
J
JSON Formatter & Validator
Format, minify and validate JSON instantly
T
Unix Timestamp Converter
Convert Unix timestamps to dates and back
R
Regex Tester
Test regular expressions with live matches
D
Diff Checker
Compare two texts and highlight differences
L
Lorem Ipsum Generator
Placeholder paragraphs, sentences or words
N
Number Base Converter
Convert between binary, octal, decimal and hex
C
Color Converter (HEX / RGB / HSL)
Convert colors and copy HEX, RGB or HSL
C
CSV to JSON Converter
Convert CSV to JSON and JSON back to CSV
C
Case Converter & Slug Generator
camelCase, snake_case, kebab-case, Title & slug
W
Word & Character Counter
Words, characters, sentences and reading time
Password Breach Checker · 100% Private
100% Free · No Signup · No Server

Password Breach Checker

Find out in one second whether a password has appeared in a known data breach. This tool uses the Have I Been Pwned range API with k-anonymity: your browser hashes the password and sends only the first 5 characters of the hash. The password itself never leaves your device.

Instant breach lookup
k-anonymity — only 5 hash chars sent
Billions of leaked records
No account, no logging
Advertisement
Advertisement
Trusted & free

It is completely free, private and requires no signup.

Change it immediately

If a password appears in a breach, replace it everywhere it is still used.

Check reused passwords

Credential stuffing works because people reuse passwords — one leak unlocks many accounts.

A match is not always a hack

It means the password was in a known dataset. Treat it as compromised and rotate it.

Use a manager afterwards

Generating unique passwords per site is the only durable fix.

You might also like
5
Hash chars sent
SHA-1
Lookup hash
0
Passwords stored
100%
Private
Step by Step

How it works

Find out in one second whether a password has appeared in a known data breach. This tool uses the Have I Been Pwned range API with k-anonymity: your browser hashes the password and sends only the first 5 characters of the hash. The password itself never leaves your device.

Enter the exact password on its own — not your username, and not a variation you have never used.

Your browser computes the SHA-1 hash and asks the breach database about the first five characters only.

If it appears in breaches, change it everywhere and replace it with a unique generated password.

Examples & Data

Examples & Data

Password Typical result Action
password Found in millions Change now
123456 Found in millions Change now
Kx!9#mP2@vLq7$dR Not found Keep it unique

The absence of a hit is good news, but it does not guarantee a password is strong — check strength too.

All tools

Password Strength Checker
Score any password and estimate crack time
Password Generator
Create strong random passwords up to 128 chars
Random String Generator
Random tokens, IDs and keys with any charset
Passphrase Generator
Memorable multi-word passphrases (Diceware)
TOTP / 2FA Code Generator
Time-based one-time codes and otpauth secrets
Password Breach Checker
Check if a password appeared in known breaches
SHA-256 Generator
Hash text to a 64-char SHA-256 digest
MD5 Generator
Compute the 32-char MD5 checksum of any text
SHA-1 Generator
Generate the 40-char SHA-1 hash of any input
SHA-512 Generator
Hash text to a 128-character SHA-512 digest
HMAC Generator
HMAC-MD5, SHA-1, SHA-256 & SHA-512 with secret key
bcrypt Generator / Checker
Hash passwords with bcrypt and verify hashes
PBKDF2 Key Derivation
Derive keys from a password with salt and iterations
AES Encrypt / Decrypt Text
Encrypt text with AES-256-GCM and a password
File Hash / Checksum
Compute SHA hashes of any file locally
IP Address Checker
Identify IPv4 vs IPv6, public/private and more
IPv4 Calculator
Network, broadcast, hosts, subnet mask & wildcard
IPv6 Calculator
Expand, compress and subnet IPv6 addresses
Subnet Calculator
CIDR ranges, wildcard masks and usable hosts
MAC Address Generator
Random valid MAC addresses, unicast or multicast
Port Checker
Learn what each TCP/UDP port number means
DNS Lookup
Resolve A, AAAA, MX, NS, TXT and CNAME records
WHOIS Lookup
Domain registration, expiry and registrar info
HTTP Header Analyzer
Security, caching & SEO headers explained
User-Agent Parser
Decode browser, OS and device from any UA
MIME Type Lookup
File extension to MIME type reference
HTTP Status Code Lookup
Every status code 1xx–5xx explained
URL Encoder / Decoder
Percent-encode URLs and parse query strings
Color Contrast Checker (WCAG)
Check text contrast against WCAG AA & AAA
UUID / ULID Generator
UUID v4, v7, ULID and NanoID in bulk
JWT Decoder & Signer
Decode, inspect and sign JSON Web Tokens
Base64 Encoder / Decoder
Encode and decode Base64, standard or URL-safe
QR Code Generator
QR codes for links, Wi-Fi and vCards
JSON Formatter & Validator
Format, minify and validate JSON instantly
Unix Timestamp Converter
Convert Unix timestamps to dates and back
Regex Tester
Test regular expressions with live matches
Diff Checker
Compare two texts and highlight differences
Lorem Ipsum Generator
Placeholder paragraphs, sentences or words
Number Base Converter
Convert between binary, octal, decimal and hex
Color Converter (HEX / RGB / HSL)
Convert colors and copy HEX, RGB or HSL
CSV to JSON Converter
Convert CSV to JSON and JSON back to CSV
Case Converter & Slug Generator
camelCase, snake_case, kebab-case, Title & slug
Word & Character Counter
Words, characters, sentences and reading time

Ready to try it?

It is completely free, private and requires no signup.

Use the tool now
100% Free No signup Private & secure
Advertisement
Help Center

Frequently Asked Questions

Yes. The password is hashed in your browser. Only a 5-character prefix of the SHA-1 hash is sent, and that prefix matches hundreds of thousands of different passwords, so the request cannot reveal yours.

A service by Troy Hunt that aggregates billions of records from public data breaches. The range API answers by hash prefix, which is what makes k-anonymity possible.

It means the password appeared in a breach somewhere. Attackers test such lists automatically, so treat the password as compromised and replace it now.

No. Nothing is stored or logged — the hash is used for the request and discarded immediately.

Advertisement