Password strength
Password strength is an API that scores a password from 0 to 4 based on its length and character variety, so you can use it in a signup form without writing that logic yourself.
How it works
You send the password and it analyzes length, whether it mixes uppercase/lowercase/digits/symbols, an estimated entropy in bits, and whether it's in a short list of the most repeated passwords found in public breaches.
Note: this is NOT a real breached-password checker (like "Have I Been Pwned"): that would require querying a third party's database on every call. This tool only measures STRUCTURE (length and variety), not whether that exact password has appeared in a real breach.
About privacy
The password you send is never stored or written to usage logs: only the result (strong/weak/etc.) gets logged, never the text itself.
All you need
- Your API key. Create it in your dashboard with "+ Create key". It's shown only once, so copy and save it.
- In your automation platform, an "HTTP Request" step (n8n, Make, Zapier, Pipedream… all have one).
How to use it in n8n (step by step)
In the HTTP Request node:
- Method:
POST - URL:
https://api.cofferdock.com/password-strength - Send Headers: on → add two:
x-api-key= your key, andContent-Type=application/json - Send Body: on → Body Content Type: JSON →
{ "password": "whateverIt123!" }
In Make (HTTP → Make a request module): same method and URL, Body type: Raw, Content type: JSON, with the same body.
Options (inside the JSON)
| Option | Default | What it does |
|---|---|---|
password | - | Required. The password to analyze. |
API overview
- Endpoint:
POST https://api.cofferdock.com/password-strength - Auth: header
x-api-key: YOUR_KEY. - Input:
application/jsonONLY. - Engine: length/variety rules + entropy estimate (log2 of the character pool used), pure JS. Does not query any breached-password database.
- Limits: 30 requests/min per IP. 1 call = 1 credit.
Options
| Option | Default | Description |
|---|---|---|
password | - | Required. Non-empty string, up to 256 characters (400 otherwise). |
Examples
curl:
curl -X POST "https://api.cofferdock.com/password-strength" \
-H "x-api-key: YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"password":"whateverIt123!"}'
JavaScript (Node 18+):
const r = await fetch('https://api.cofferdock.com/password-strength', {
method: 'POST',
headers: { 'x-api-key': 'YOUR_KEY', 'Content-Type': 'application/json' },
body: JSON.stringify({ password: 'whateverIt123!' }),
});
const { score, strength } = await r.json();
Response
{ "success": true, "score": 3, "strength": "strong", "length": 12,
"has_lowercase": true, "has_uppercase": true, "has_digit": true,
"has_symbol": true, "entropy_bits": 78.6, "common_password": false,
"meta": { "used": 12, "remaining": 488 } }
What you get back
score (0 to 4), strength (very_weak/weak/fair/strong/very_strong), length, the 4 has_* flags, entropy_bits and common_password (whether it's in the short list of most repeated ones).