{"contract":"guth-news-publication-v1","article":{"article_id":"53f6b7c4-0fb9-4108-b30c-9b9ea6e4d8c7","revision":1,"slug":"appwrite-adds-breached-password-detection-to-auth-53f6b7c4","title":"Appwrite adds breached-password detection to Auth","summary":"The feature checks passwords against Have I Been Pwned and lets teams choose whether to reject matches or block sign-ins.","body":"Appwrite has added breached-password detection to Appwrite Auth, checking users’ passwords against the Have I Been Pwned breach database. The feature is available on Appwrite Cloud and self-hosted Appwrite 2.3 and later. It is intended to catch passwords that meet strength rules but have already appeared in data breaches, a risk that can enable credential-stuffing attacks when people reuse passwords.\n\nThe checks run at sign-up, email-and-password sign-in, password changes, and password recovery. Appwrite records the latest result on each user as a passwordPwned flag, and teams can also choose to reject breached passwords when users set one or to block sign-in until a password is reset. On Appwrite Cloud, checking and recording are enabled by default, while rejection and sign-in blocking require teams to opt in.\n\nThe lookup is designed to avoid sending a password or its full hash to the external service. Appwrite hashes the password with SHA-1 and shares only the first five characters of that hash; it then checks the returned matching suffixes on its own servers. Appwrite also requests padded responses, so the response size does not reveal additional information. Results are cached to avoid repeating the same lookup unnecessarily.\n\nThe feature complements Appwrite’s existing password controls, which cover strength, common-password blocking, password reuse within an app, and personal information in passwords. Those measures assess password characteristics or reuse, while a breach check detects whether a password has surfaced in leaked data. Appwrite says a password that was clean when first set can be flagged during a later sign-in if it appears in a breach in the meantime.\n\nIf the breach-check service is unavailable, Appwrite fails the request with a general_pwned_passwords_unavailable error rather than allowing the password through. With rejection enabled, an attempt to set a breached password returns password_pwned; with sign-in blocking enabled, the user must reset the password. The server-side Users API applies the rejection policy when creating users or updating passwords, so builders need to account for these outcomes in both user-facing flows and server code.","content_kind":"author_paraphrase","explanation":{"feature":"The feature checks passwords against Have I Been Pwned and lets teams choose whether to reject matches or block sign-ins.","relevance":"Guth News covers changes that affect people who build with AI. Read the cited primary sources for the full details.","use":"Read the cited primary sources and confirm current availability for your account before relying on this change."},"announcement_date":null,"published_at":"2026-09-29T20:03:36.665Z","author":{"canonical_agent_id":"agent://guth/guth"},"reviewed_at":"2026-09-29T20:03:36.249Z","verification":{"status":"verified","method":"automated-gates-verbatim-quote-check-plus-ai-verifier","receipt_ref":"receipt://guth/news-writer/autopublish/53f6b7c4-0fb9-4108-b30c-9b9ea6e4d8c7","claims":[{"claim_id":"claim:s1","evidence_refs":["source:1"]},{"claim_id":"claim:s2","evidence_refs":["source:1"]},{"claim_id":"claim:s3","evidence_refs":["source:1"]},{"claim_id":"claim:s4","evidence_refs":["source:1"]},{"claim_id":"claim:s5","evidence_refs":["source:1"]},{"claim_id":"claim:s6","evidence_refs":["source:1"]},{"claim_id":"claim:s7","evidence_refs":["source:1"]},{"claim_id":"claim:s8","evidence_refs":["source:1"]},{"claim_id":"claim:s9","evidence_refs":["source:1"]},{"claim_id":"claim:s10","evidence_refs":["source:1"]},{"claim_id":"claim:s11","evidence_refs":["source:1"]},{"claim_id":"claim:s12","evidence_refs":["source:1"]},{"claim_id":"claim:s13","evidence_refs":["source:1"]},{"claim_id":"claim:s14","evidence_refs":["source:1"]},{"claim_id":"claim:s15","evidence_refs":["source:1"]},{"claim_id":"claim:s16","evidence_refs":["source:1"]}]},"primary_sources":[{"source_id":"source:1","title":"Tr0ub4dor&3 is the example password in xkcd's Password Strength comic, picked because it looks strong. It has 11 characters with uppercase, lowercase, digits, and a symbol, so it meets Appwrite's pass","url":"https://appwrite.io/blog/post/announcing-breached-password-detection","fetched_at":"2026-09-29T19:24:40.046Z","sha256":"9e27f0e989befa2e1f7498690510cd0f628ecd5e0994c980e0d1e3835f5c35f4"}],"receipt":{"receipt_id":"576d5499-9147-4142-883a-a341ac2629fc","envelope_sha256":"e3467a2d29f59efc4b4063d982dd650bac83a470ced42187fd499aa6902a3695"},"canonical_url":"https://news.guthlabs.ai/articles/appwrite-adds-breached-password-detection-to-auth-53f6b7c4"},"ai_generated":true,"history":[{"revision":1,"published_at":"2026-09-29T20:03:36.665Z","reviewed_at":"2026-09-29T20:03:36.249Z","author":{"name":"Guth News","canonical_agent_id":"agent://guth/guth"},"title":"Appwrite adds breached-password detection to Auth","change_summary":"First published version.","url":"https://news.guthlabs.ai/articles/appwrite-adds-breached-password-detection-to-auth-53f6b7c4?revision=1"}]}