HIBP passwords downloader in Go
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Ralph Schaer cde73a46c5 upgrade
2026-10-04 10:06:20 +02:00
.github/workflows Harden downloads and automate releases 2026-09-05 09:58:37 +02:00
.gitignore Use goreleaser 2023-03-11 11:02:04 +01:00
.goreleaser.yaml update Go module dependencies and improve error handling in downloader 2026-06-19 20:14:41 +02:00
go.mod upgrade 2026-10-04 10:06:20 +02:00
go.sum upgrade 2026-10-04 10:06:20 +02:00
LICENSE Initial commit 2023-03-09 16:49:38 +01:00
main.go Harden downloads and automate releases 2026-09-05 09:58:37 +02:00
main_test.go Harden downloads and automate releases 2026-09-05 09:58:37 +02:00
README.md Harden downloads and automate releases 2026-09-05 09:58:37 +02:00
Taskfile.yml Harden downloads and automate releases 2026-09-05 09:58:37 +02:00

hibp-passwords-downloader

A Go downloader for the Have I Been Pwned Pwned Passwords hash ranges. It can download SHA-1 or NTLM ranges either as one file per range or merged into a single text file.

Range files are named after their five-character prefix and contain the suffixes returned by the API. A merged file restores each prefix and contains complete hashes in HASH:COUNT format.

Installation

Download the latest version from the releases page.

Usage

Linux/macOS:

./hibp-passwords-downloader [flags] [outputFileOrFolder]

Windows:

hibp-passwords-downloader.exe [flags] [outputFileOrFolder]

If outputFileOrFolder is omitted, the downloader writes range files into hibp-passwords. With --single, it writes hibp-passwords.txt.

Flags

Flag Shorthand Default Description
--parallelism -p 8 * CPU cores, capped at 64 Number of parallel range requests. Values above 64 are capped. Use 0 for the default.
--overwrite -o false Overwrite existing output files while writing results.
--single -s false Merge all ranges into a single .txt file. Without this flag, ranges are stored as individual files in a folder.
--ntlm -n false Fetch NTLM hashes instead of SHA-1 hashes.
--resume -r false Resume a previous download by skipping existing non-empty range files.
--version Print the binary version.
--help -h Print help.

Requests use the standard HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables. Transient failures are retried, including the delay supplied by a Retry-After response header.

Examples

Download all SHA-1 hashes to individual range files in the pwnd directory:

./hibp-passwords-downloader pwnd

Download all SHA-1 hashes to a single text file:

./hibp-passwords-downloader -s pwnedpasswords.txt

Download all NTLM hashes to a single text file:

./hibp-passwords-downloader -n -s pwnedpasswords_ntlm.txt

Resume an interrupted folder download:

./hibp-passwords-downloader -r pwnd

Press Ctrl+C to stop cleanly. Every completed range is retained, so the same command can be restarted with --resume. In single-file mode, resumable ranges are kept in a hidden sibling folder until the final file has been merged successfully:

./hibp-passwords-downloader -s -r pwnedpasswords.txt

Building from source

You need Go, GoReleaser, and Task installed.

git clone https://github.com/ralscha/hibp-passwords-downloader.git
cd hibp-passwords-downloader
task build

For a simple local build without GoReleaser:

go build ./...

Releasing

Create and push a version tag such as v1.1.0. The release workflow runs the tests, builds Linux, Windows, and macOS archives with GoReleaser, and publishes them with a checksum file on the corresponding GitHub release.

task release-tag TAG=v1.1.0

Use task tag TAG=v1.1.0 and task push-tag TAG=v1.1.0 when you want to create and push the tag separately. Run task snapshot to build the complete release matrix locally without publishing it.