Tools API Blog
Sign in Create account

Password strength

Password strength is an API that scores a password from 0 to 4 based on its length and character variety, so you can use it in a signup form without writing that logic yourself.

How it works

You send the password and it analyzes length, whether it mixes uppercase/lowercase/digits/symbols, an estimated entropy in bits, and whether it's in a short list of the most repeated passwords found in public breaches.

Note: this is NOT a real breached-password checker (like "Have I Been Pwned"): that would require querying a third party's database on every call. This tool only measures STRUCTURE (length and variety), not whether that exact password has appeared in a real breach.

About privacy

The password you send is never stored or written to usage logs: only the result (strong/weak/etc.) gets logged, never the text itself.

All you need

  • Your API key. Create it in your dashboard with "+ Create key". It's shown only once, so copy and save it.
  • In your automation platform, an "HTTP Request" step (n8n, Make, Zapier, Pipedream… all have one).

How to use it in n8n (step by step)

In the HTTP Request node:

  • Method: POST
  • URL: https://api.cofferdock.com/password-strength
  • Send Headers: on → add two: x-api-key = your key, and Content-Type = application/json
  • Send Body: on → Body Content Type: JSON → { "password": "whateverIt123!" }

In Make (HTTP → Make a request module): same method and URL, Body type: Raw, Content type: JSON, with the same body.

Options (inside the JSON)

OptionDefaultWhat it does
password-Required. The password to analyze.

What you get back

score (0 to 4), strength (very_weak/weak/fair/strong/very_strong), length, the 4 has_* flags, entropy_bits and common_password (whether it's in the short list of most repeated ones).