Breach Check
See whether a password shows up in known data breaches - without sending the password itself. Only a short piece of a one-way hash leaves your browser.
Check a password
Type a password below, opt in to the check, then run it. PassTip hashes the password on your device and asks Have I Been Pwned only for matching hash prefixes - your full password never leaves this browser.
21BD1).
What never leaves: the password itself, and the rest of the hash. Matching is finished on your device.
How this works
Explain like I'm not a security expert
Think of your password as a sealed envelope. Before anything is checked online, your browser turns that password into a long fingerprint (a hash). That fingerprint cannot be turned back into the password.
Then PassTip only sends the first five characters of that fingerprint to Have I Been Pwned - like asking “do you have any fingerprints that start with these five letters?” The service replies with a list of matching endings. Your browser compares the rest of the fingerprint locally.
So the service never sees your password, and never sees enough of the fingerprint to know which password you typed. That privacy pattern is called k-anonymity.
What exactly is sent over the network?
One HTTPS request to api.pwnedpasswords.com with a 5-character hash prefix. Example path: /range/21BD1.
Your password text is not included. The full hash is not included. PassTip also asks the API to pad responses so traffic patterns are harder to fingerprint.
What do the results mean?
Found in breaches means this exact password has appeared in leaked datasets collected by Have I Been Pwned. If you still use it anywhere, change it.
Not found means it was not in that database. That is good news, but it does not guarantee the password is strong - it only means it was not seen in those known leaks.
Is this optional?
Yes. The check is opt-in. Nothing is sent until you tick the consent box and press Check password. You can clear the field anytime; the password is not stored by PassTip.