HIBP Pwned Passwords (range)
FreeGET https://api.pwnedpasswords.com/range/{first5}
HTTPS
Yes
API key
No key
CORS
Usually yes
Use
Free tier
Limits. Public range API. Follow Troy Hunt’s current guidance; add padding as documented.
Commercial. Pwned Passwords range is free. Breach search by account is paid.
Note. Response is text, not JSON: SUFFIX:count per line. Compute SHA-1 in Web Crypto or your backend. Never log the password or the full hash to our site — we do not offer a live checker.
curl -sS "https://api.pwnedpasswords.com/range/21BD1"