createHibpModule is standalone, it does not hook automatically into the username module or any other password flow. Call check() or enforce() yourself wherever you accept a new password.
Setup
lib/theauth.ts
hibp.enforce() before delegating to the username module’s signUp:
Sign-up handler
check() and enforce()
The module exposes two methods with different failure modes.check() does not apply threshold, it always returns the raw breach count:
Manual usage
check() is useful when you want to warn the user without blocking them. enforce() throws a typed HibpBreachedError (with a count property) so you can catch it and return a friendly message:
How k-anonymity works
Configuration
The Pwned Passwords API is free and does not require an API key. PointapiUrl at a self-hosted mirror if you run one:
lib/theauth.ts
If the HIBP API is unreachable and
onError is 'allow' (the default), check() returns 0 and enforce() passes through, a slow network does not block your users from registering. Set onError: 'block' to fail closed instead, check() throws HibpApiError and enforce() propagates it.Configuration reference
number
default:0
Reject passwords seen in more than this many breaches. Default 0 rejects any breach at all.
string
default:"https://api.pwnedpasswords.com"
Base URL for the Pwned Passwords range API.
number
default:5000
Milliseconds to wait for the HIBP API before giving up.
'allow' | 'block'
default:"'allow'"
Behavior when the HIBP API is unreachable or returns an error.
Related
Two-factor auth
Add TOTP as a second layer of protection beyond password quality.
Trusted devices
Skip 2FA on devices you have marked as trusted.
Username and password
theAuth’s built-in password module that HIBP enforcement typically guards.
Compliance
Audit trail, GDPR tooling, and the other compliance-related features.