Password Generator
Strong, random passwords with adjustable length and character types.
Open tool →Check any password against known data breaches. Your password is never sent anywhere — only a tiny, anonymized fragment of its hash is.
Enter a password above
Real breach data, with the same privacy-first defaults as every other tool here.
Your password never leaves your device. Only a 5-character hash prefix is ever transmitted.
Checked against a database of hundreds of millions of passwords exposed in known breaches.
Flassword doesn't see or store your password either — the check happens entirely in your browser.
Everything you might want to know about the breach checker.
No. Your password is hashed in your browser first. Only the first 5 characters of that hash — never the password, and never the full hash — are sent to check for a match. This technique is called k-anonymity, and it's explained in more detail above.
Have I Been Pwned is a widely trusted, independent breach-notification service run by security researcher Troy Hunt. Its Pwned Passwords database aggregates hundreds of millions of passwords exposed in known data breaches, and offers a free, privacy-preserving API specifically designed for checks like this one.
Stop using it immediately, on every account where it appears, and replace it with a new, unique, randomly generated password. If you reused it anywhere else, change it there too — see our guide on why you should never reuse passwords.
It means it hasn't turned up in a known, indexed breach yet — not that it's inherently strong. A short or predictable password can still be guessed even if it has never leaked. Pair this check with our Password Strength Checker for the full picture.
Checking against real breach data requires comparing against a database of known-exposed passwords that no browser can hold locally. Every other tool on Flassword works fully offline; this is the one exception, and it's built to leak as little information as technically possible while still doing that job.
The same private, client-side approach for everything else you need to generate.
Strong, random passwords with adjustable length and character types.
Open tool →See entropy, crack-time estimates, and tips for any password you type.
Open tool →Memorable Diceware-style passphrases with real entropy behind them.
Open tool →