Breached passwords_
Configure breached password detection for your self-hosted Appwrite instance with _APP_PWNED_PASSWORDS_DSN. Connect Have I Been Pwned or your own breach service so Auth can flag, reject, and block leaked passwords.
2 min read
Appwrite 2.3 and later can check user passwords against known data breaches with the breached passwords policy. On a self-hosted instance, the policy needs a breach service, which you set with the _APP_PWNED_PASSWORDS_DSN environment variable.
The default value, none://localhost, reports every password as safe. Until you change it, the policy has no effect even when it's turned on in the Console: nothing is rejected or blocked, and every checked password is recorded as not breached.
Environment variables
Set _APP_PWNED_PASSWORDS_DSN in the .env file of your Appwrite installation to one of these values.
| Value | Breach service |
|---|---|
none://localhost | Default. No service is called, and every password is reported as safe. |
hibp://localhost | The public Have I Been Pwned range API. Appwrite sends only the first five characters of the password's SHA-1 hash. |
appwrite://<SECRET>@appwrite-pwned/v1/detection | An Appwrite Pwned service that you run yourself, authenticated with <SECRET>. The service receives the full unsalted SHA-1 hash. Add ?tls=true to connect over HTTPS. |
To check passwords against Have I Been Pwned, add this line to your .env file:
_APP_PWNED_PASSWORDS_DSN=hibp://localhostAfter editing your docker-compose.yml or .env files, you will need to recreate your Appwrite stack by running the following compose command in your terminal.
docker compose up -dYou can verify if the changes have been successfully applied by running this command:
docker compose exec appwrite varsConfigure the policy
Once the breach service is set, configure the policy for each project under Auth > Policies > Passwords > Breached passwords in the Appwrite Console. The Auth security docs cover the enforcement options and the errors your app needs to handle.
Was this page helpful?
Share what worked or what we should fix. Once approved, our agents automatically apply suggested updates to the docs.