Skip to main content
theAuth integrates with the HaveIBeenPwned Pwned Passwords API to detect compromised passwords at sign-up and password change. It uses the k-anonymity model, only the first 5 characters of the SHA-1 hash are sent to the API. Your users’ actual passwords never leave your server. createHibpModule is standalone, it does not hook automatically into the username module or any other password flow. Call check() or enforce() yourself wherever you accept a new password.

Setup

lib/theauth.ts
Call hibp.enforce() before delegating to the username module’s signUp:
Sign-up handler

check() and enforce()

The module exposes two methods with different failure modes. check() does not apply threshold, it always returns the raw breach count:
Manual usage
check() is useful when you want to warn the user without blocking them. enforce() throws a typed HibpBreachedError (with a count property) so you can catch it and return a friendly message:

How k-anonymity works

The full password hash is never transmitted. The API response contains partial hashes from other users’ passwords, so the provider cannot determine which password you were checking.

Configuration

The Pwned Passwords API is free and does not require an API key. Point apiUrl at a self-hosted mirror if you run one:
lib/theauth.ts
If the HIBP API is unreachable and onError is 'allow' (the default), check() returns 0 and enforce() passes through, a slow network does not block your users from registering. Set onError: 'block' to fail closed instead, check() throws HibpApiError and enforce() propagates it.

Configuration reference

number
default:0
Reject passwords seen in more than this many breaches. Default 0 rejects any breach at all.
string
default:"https://api.pwnedpasswords.com"
Base URL for the Pwned Passwords range API.
number
default:5000
Milliseconds to wait for the HIBP API before giving up.
'allow' | 'block'
default:"'allow'"
Behavior when the HIBP API is unreachable or returns an error.

Two-factor auth

Add TOTP as a second layer of protection beyond password quality.

Trusted devices

Skip 2FA on devices you have marked as trusted.

Username and password

theAuth’s built-in password module that HIBP enforcement typically guards.

Compliance

Audit trail, GDPR tooling, and the other compliance-related features.
Last modified on October 7, 2026