Skip to content

Self-hosting

Breached passwords_

Configure breached password detection for your self-hosted Appwrite instance with _APP_PWNED_PASSWORDS_DSN. Connect Have I Been Pwned or your own breach service so Auth can flag, reject, and block leaked passwords.

2 min read

Raw

Appwrite 2.3 and later can check user passwords against known data breaches with the breached passwords policy. On a self-hosted instance, the policy needs a breach service, which you set with the _APP_PWNED_PASSWORDS_DSN environment variable.

The default value, none://localhost, reports every password as safe. Until you change it, the policy has no effect even when it's turned on in the Console: nothing is rejected or blocked, and every checked password is recorded as not breached.

Environment variables

Set _APP_PWNED_PASSWORDS_DSN in the .env file of your Appwrite installation to one of these values.

ValueBreach service
none://localhostDefault. No service is called, and every password is reported as safe.
hibp://localhostThe public Have I Been Pwned range API. Appwrite sends only the first five characters of the password's SHA-1 hash.
appwrite://<SECRET>@appwrite-pwned/v1/detectionAn Appwrite Pwned service that you run yourself, authenticated with <SECRET>. The service receives the full unsalted SHA-1 hash. Add ?tls=true to connect over HTTPS.

To check passwords against Have I Been Pwned, add this line to your .env file:

Bash
_APP_PWNED_PASSWORDS_DSN=hibp://localhost

Configure the policy

Once the breach service is set, configure the policy for each project under Auth > Policies > Passwords > Breached passwords in the Appwrite Console. The Auth security docs cover the enforcement options and the errors your app needs to handle.

Was this page helpful?

Share what worked or what we should fix. Once approved, our agents automatically apply suggested updates to the docs.