
A Python Library and CLI for the Pwned Passwords v2 API

pwnedpasswords is a small Python wrapper and command line utility that lets you check if a passphrase has been pwned using the Pwned Passwords v2 API.

API v2

The API allows the list of pwned accounts (email addresses and usernames) to be quickly searched via a RESTful service. Getting all data classes · Sample paste response · Overview · Searching by a range

I've Just Launched Pwned Passwords V2 With Half a Billion ...

Pwned Passwords V2 is now live! Everything you need to use them is over on the Pwned Passwords page of HIBP where you can check them online, ...

Pwned Passwords

Pwned Passwords are hundreds of millions of real world passwords previously exposed in data breaches. This exposure makes them unsuitable for ongoing use.


Top 20K hashes from the Troy Hunt / haveibeenpwned Pwned Passwords list v2 (2018-02-21). # with frequency count and cracked plaintext passwords.

Upgrading common password prevention

Troy Hunt has released Pwned Passwords v2 has part of his Have I Been Pwned service, which tracks data breaches: Have I been pwned?

Validating Leaked Passwords with k-Anonymity

Today, v2 of Pwned Passwords was released as part of the Have I Been Pwned service offered by Troy Hunt. Containing over half a billion real ...

