Password Security Assessment API

API ID 13745

Generate and audit robust passwords with Password Security Assessment API for enhanced security.

API Documentation

Endpoints

Request
The "Health check" endpoint is designed to assess the operational status and overall health of the API or service. It typically responds with a simple success or failure message, along with relevant status codes and possibly performance metrics such as response time and resource utilization. This endpoint is crucial for monitoring and maintenance purposes, allowing developers and system administrators to identify if the service is running properly, troubleshoot issues, and ensure high availability, making it a vital tool in automated deployment pipelines, uptime monitoring solutions, and systems recovery processes.
Endpoint ID: 31498
GET https://zylalabs.com/api/13745/password+security+assessment+api/31498/health+check
INPUT PARAMETERS

Free test requests remaining: 3 of 3.

This endpoint does not require any input parameters.

API EXAMPLE RESPONSE
JSON
{
    "code": 200,
    "status": "success",
    "data": {
        "healthy": true
    }
}
Health check — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13745/password+security+assessment+api/31498/health+check' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
Generate one or more cryptographically secure passwords to your exact specification. Every password is built using Node's CSPRNG (crypto.randomInt), not a standard pseudo-random generator, so output is suitable for real account credentials, not just placeholder text. Control the character sets included — uppercase letters, lowercase letters, numbers, and symbols — and toggle each independently. Set the exact length (4–128 characters) and request up to 50 passwords in a single call. An "exclude ambiguous characters" option is available for cases where humans need to read and retype the password by hand — it strips easily-confused characters like 0/O and 1/l/I. Common uses: generating default passwords for new user accounts, populating test/QA fixtures, building a "generate a strong password" button in a signup form, or any workflow that needs secure random credentials on demand rather than relying on users to pick their own. Parameters (all optional except none — every field has a sensible default): - length (integer, 4-128, default 16) - count (integer, 1-50, default 1) - uppercase (boolean, default true) - lowercase (boolean, default true) - numbers (boolean, default true) - symbols (boolean, default true) - excludeAmbiguous (boolean, default false) Returns a JSON array of generated passwords. At least one character set must remain enabled, or the request is rejected with a 400.
Endpoint ID: 31499
POST https://zylalabs.com/api/13745/password+security+assessment+api/31499/generate+passwords
INPUT PARAMETERS

Generate passwords — Endpoint Features

Object Description
Request Body Required Json

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

API EXAMPLE RESPONSE
JSON
{
    "code": 200,
    "status": "success",
    "data": {
        "passwords": [
            "DP)zBd^Wm]8X%Zyx"
        ]
    }
}
Generate passwords — CODE SNIPPETS

curl --location --request POST 'https://zylalabs.com/api/13745/password+security+assessment+api/31499/generate+passwords' --header 'Authorization: Bearer YOUR_API_KEY' 

--data-raw '{
  "length": 16,
  "count": 1,
  "uppercase": true,
  "lowercase": true,
  "numbers": true,
  "symbols": true,
  "excludeAmbiguous": false
}'

    
Request
Score the strength of a given password and get specific, actionable feedback on what would make it stronger — useful for enforcing password policy at signup or providing live strength feedback in a password field. Scoring considers length, character variety (mix of uppercase, lowercase, numbers, symbols), repeated-character runs (e.g. "aaaa"), sequential runs (e.g. "abcd" or "1234"), and membership in a list of the most commonly breached/reused passwords — any match against that list forces the score to the minimum regardless of other factors, since a common password is unsafe no matter how it's composed. Returns a numeric score from 0 (very weak) to 4 (very strong), a human-readable label matching that score, and an array of specific feedback strings explaining what's holding the score back (e.g. "Password is very short — use at least 8 characters", "Mix uppercase, lowercase, numbers, and symbols"). When nothing is wrong, feedback confirms the password looks good. This is a heuristic scorer, not a dictionary/breach-database lookup beyond the built-in common-password list — it's designed to catch the most common real-world weaknesses (short length, low variety, predictable patterns, well-known passwords) rather than checking against every leaked credential database in existence. Parameters: - password (string, required) — the password to evaluate. Never logged or stored; scored in memory and discarded.
Endpoint ID: 31500
POST https://zylalabs.com/api/13745/password+security+assessment+api/31500/score+password+strength
INPUT PARAMETERS

Score password strength — Endpoint Features

Object Description
Request Body Required Json
Request Body Required Json
Request Body Required Json

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

API EXAMPLE RESPONSE
JSON
{
    "code": 200,
    "status": "success",
    "data": {
        "score": 0,
        "label": "very weak",
        "feedback": [
            "Password is very short — use at least 8 characters",
            "Use at least 12 characters for better security",
            "Mix uppercase, lowercase, numbers, and symbols"
        ]
    }
}
Score password strength — CODE SNIPPETS

curl --location --request POST 'https://zylalabs.com/api/13745/password+security+assessment+api/31500/score+password+strength' --header 'Authorization: Bearer YOUR_API_KEY' 

--data-raw '{
  "password": "hunter2"
}'

    

API Access Key & Authentication

After signing up, every developer is assigned a personal API access key, a unique combination of letters and digits provided to access to our API endpoint. To authenticate with the Password Security Assessment API simply include your bearer token in the Authorization header.

Headers
Header Description
Authorization Required Should be Bearer access_key. See "Your API Access Key" above when you are subscribed.

No long-term commitment. Upgrade, downgrade, or cancel anytime. Free Trial includes up to 50 requests.

(Save 2 months with annual billing 🎉)

🚀 Enterprise Plan

Starts at
$ 10,000/Year


  • Custom Volume
  • Custom Rate Limit
  • Specialized Customer Support
  • Real-Time API Monitoring

Overview

Generate and audit robust passwords with Password Security Assessment API for enhanced security.

Password Security Assessment API FAQs

The "Health check" endpoint returns a status message indicating the API's operational health. The "Generate passwords" endpoint returns an array of securely generated passwords based on specified parameters. The "Score password strength" endpoint returns a numeric score, a label indicating strength, and feedback on how to improve the password.

Key fields include "code" (HTTP status), "status" (success or failure), and "data" (containing specific information like passwords or scoring details). For password scoring, "score," "label," and "feedback" are essential fields.

Users can customize requests with parameters such as "length" (4-128), "count" (1-50), "uppercase," "lowercase," "numbers," "symbols," and "excludeAmbiguous." Each parameter has sensible defaults, allowing flexibility in password generation.

Response data is structured in JSON format, with a top-level object containing "code," "status," and "data." The "data" field varies by endpoint, containing either generated passwords or scoring details, making it easy to parse and utilize.

Common use cases include generating secure passwords for new user accounts, populating test data, enforcing password policies during signup, and providing real-time feedback on password strength in user interfaces.

Users can leverage the generated passwords for secure account creation or testing. The scoring feedback helps improve password policies by identifying weaknesses, guiding users to create stronger passwords based on actionable suggestions.

Data accuracy is maintained through heuristic scoring that evaluates various factors like length, character variety, and common password lists. This approach ensures that the scoring reflects real-world password security practices without relying on extensive breach databases.

Users can expect scores ranging from 0 (very weak) to 4 (very strong), with corresponding feedback. Common patterns include suggestions for increasing length, mixing character types, and avoiding common passwords, helping users understand how to enhance their password security.

General FAQs

To obtain your API key, first sign in to your account and navigate to the API you want to use. From the API's Pricing section, choose a plan and complete the subscription process. Once subscribed, return to the API page and you will see your API Access Key displayed at the top of the documentation page. You can use this key to authenticate your requests.

You can’t switch APIs during the free trial. If you subscribe to a different API, your trial will end and the new subscription will start as a paid plan.

The free trial lasts for 7 days and allows you to make up to 50 API requests.

No, the free trial is available only once, so we recommend using it on the API that interests you the most. Most of our APIs offer a free trial, but some may not include this option.

Yes. If the API offers a free trial, you will see a "Free 7-Day Trial" option in its Pricing section. The trial lasts for 7 days and allows up to 50 API requests, enabling you to evaluate the API before subscribing to a paid plan.

Zyla API Hub is like a big store for APIs, where you can find thousands of them all in one place. We also offer dedicated support and real-time monitoring of all APIs. Once you sign up, you can pick and choose which APIs you want to use. Just remember, each API needs its own subscription. But if you subscribe to multiple ones, you'll use the same key for all of them, making things easier for you.

Prices are listed in USD (United States Dollar), EUR (Euro), CAD (Canadian Dollar), AUD (Australian Dollar), and GBP (British Pound). We accept all major debit and credit cards. Our payment system uses the latest security technology and is powered by Stripe, one of the world's most reliable payment companies. If you have any trouble paying by card, just contact us at [email protected]

Additionally, if you already have an active subscription in any of these currencies (USD, EUR, CAD, AUD, GBP), that currency will remain for subsequent subscriptions. You can change the currency at any time as long as you don't have any active subscriptions.
The local currency shown on the pricing page is based on the country of your IP address and is provided for reference only. The actual prices are in USD (United States Dollar). When you make a payment, the charge will appear on your card statement in USD, even if you see the equivalent amount in your local currency on our website. This means you cannot pay directly with your local currency.
Occasionally, a bank may decline the charge due to its fraud protection settings. We suggest reaching out to your bank initially to check if they are blocking our charges. Also, you can access the Billing Portal and change the card associated to make the payment. If these does not work and you need further assistance, please contact our team at [email protected]
Prices are determined by a recurring monthly or yearly subscription, depending on the chosen plan.
API calls are deducted from your plan based on successful requests. Each plan comes with a specific number of calls that you can make per month. Only successful calls, indicated by a Status 200 response, will be counted against your total. This ensures that failed or incomplete requests do not impact your monthly quota.
Zyla API Hub works on a recurring monthly subscription system. Your billing cycle will start the day you purchase one of the paid plans, and it will renew the same day of the next month. So be aware to cancel your subscription beforehand if you want to avoid future charges.
To upgrade your current subscription plan, simply go to the pricing page of the API and select the plan you want to upgrade to. The upgrade will be instant, allowing you to immediately enjoy the features of the new plan. Please note that any remaining calls from your previous plan will not be carried over to the new plan, so be aware of this when upgrading. You will be charged the full amount of the new plan.
To check how many API calls you have left for the current month, refer to the 'X-Zyla-API-Calls-Monthly-Remaining' field in the response header. For example, if your plan allows 1,000 requests per month and you've used 100, this field in the response header will indicate 900 remaining calls.

You can monitor your API usage through the response headers included with every request:

x-zyla-api-calls-monthly-used: Shows the total number of API requests you have used during the current billing period.
x-zyla-api-calls-monthly-remaining: Shows the number of API requests you have remaining for the current billing period.

The 'X-Zyla-RateLimit-Reset' header shows the number of seconds until your rate limit resets. This tells you when your request count will start fresh. For example, if it displays 3,600, it means 3,600 seconds are left until the limit resets.

Yes, you can cancel your subscription at any time. Simply go to the Pricing section of the API you're subscribed to and click the "Unsubscribe" button.

Please note that upgrades, downgrades, and cancellations take effect immediately. Once your subscription is canceled, access to the service will end immediately, regardless of any remaining API calls in your quota.

After 7 days, you will be charged the full amount for the plan you were subscribed to during the trial. Therefore, it's important to cancel before the trial period ends. Refund requests for forgetting to cancel on time are not accepted.
When you subscribe to an API free trial, you can make up to 50 API calls. If you wish to make additional API calls beyond this limit, the API will prompt you to perform an "Start Your Paid Plan." You can find the "Start Your Paid Plan" button in your profile under Subscription -> Choose the API you are subscribed to -> Pricing tab.
You can contact us through our chat channel to receive immediate assistance. We are always online from 8 am to 5 pm (EST). If you reach us after that time, we will get back to you as soon as possible. Additionally, you can contact us via email at [email protected]

Please have a look at our Refund Policy: https://zylalabs.com/terms#refund


Related APIs