Back to Guides
Guide2 October 2026

How to Enable Supabase Leaked Password Protection and Why It Matters

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is Supabase leaked password protection?
  3. How does the k - anonymity check work?
  4. Which plans include the feature?
  5. Default state and how to enable it
  6. Performance impact
  7. Recommended complementary hardening steps
  8. How to verify the protection works
  9. Common pitfalls
  10. When to consider upgrading Supabase
  11. Related resources

Key takeaways

What is Supabase leaked password protection?

Supabase leaked password protection is a credential - stuffing mitigation that rejects passwords previously exposed in data - breach dumps. It queries the open - source HaveIBeenPwned "Pwned Passwords" API using a k - anonymity lookup, so the full password hash never leaves Supabase’s servers.

How does the k - anonymity check work?

When a user signs up, Supabase hashes the password locally with SHA - 1, extracts the first five hexadecimal characters, and sends that prefix to the HaveIBeenPwned endpoint. The service returns a list of hash suffixes that share the same prefix; Supabase then compares the remaining suffix locally. If a match is found, the password is rejected. This method protects user privacy while still leveraging a massive breach database.

Which plans include the feature?

The toggle is only available on the Pro plan and above. Free tier projects cannot enable the protection; attempting to do so will result in a disabled UI control.

Default state and how to enable it

For new Supabase projects the protection is off by default. To turn it on:

  1. Open the Supabase dashboard.
  2. Navigate to Auth → Providers → Email.
  3. Locate the toggle labeled Prevent the use of leaked passwords.
  4. Switch the toggle to On and save the changes.

Performance impact

The k - anonymity request is tiny - typically adding only a few milliseconds to the sign - up flow. Because only a 5 - character prefix is transmitted, network overhead is negligible.

How to verify the protection works

After enabling the toggle, test with a known breached password such as "password123" (which appears in the HaveIBeenPwned database). The sign - up should be blocked with an error indicating the password has been compromised. Conversely, a strong, unique password should succeed.

Common pitfalls

When to consider upgrading Supabase

If your application handles sensitive user data, compliance requirements, or high - value accounts, the added security of leaked password protection combined with Pro - tier features (such as advanced auth rules and higher request limits) often justifies the cost.


This article follows the latest Supabase guidance as of 2026 and reflects the current feature set.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary