API Documentation

Integrate Passly into your applications with our REST API

Base URL

Every request starts from this URL. No key, no sign-up.

120
Requests / 10 min
No key
Public API
v1
API version
…
Response time
Productionhttps://passly.fr/api/v1

Endpoints

Three entry points. Expand one to see its parameters, an example and its response.

Rate limiting

A per-IP quota protects the service. The headers tell you where you stand.

Limit per IP

120 requests every 10 minutes

Response headers

  • X-RateLimit-Limit
  • X-RateLimit-Remaining
  • X-RateLimit-Reset

Error 429

Returned when the limit is reached. The Retry-After header indicates how long to wait.

Error codes

Every error returns JSON with a constant shape and an actionable code.

400Bad Request

Invalid or missing parameters

{
    "error": true,
    "message": "Length must be between 4 and 128 characters",
    "code": "invalid_length"
}
429Too Many Requests

Rate limit exceeded

{
    "error": true,
    "message": "Rate limit reached. Please wait 234 seconds",
    "retry_after": 234,
    "reset_at": "2026-01-15T10:35:00.000Z"
}
500Internal Server Error

Internal server error

{
    "error": true,
    "message": "An error occurred. Please try again."
}
503Service Unavailable

Service under maintenance

{
    "error": true,
    "message": "The site is currently under maintenance. Please try again in a few minutes."
}

Codes returned in the code field

  • invalid_length
  • invalid_count
  • invalid_format
  • invalid_words
  • no_charset
  • empty_wordlist

Integration examples

The same call, in the language of your choice. Copy, paste, adapt.

// PasslyClient.js
class PasslyClient {
    constructor(baseURL = 'https://passly.fr/api/v1') {
        this.baseURL = baseURL;
    }

    async generatePassword(options = {}) {
        const response = await fetch(`${this.baseURL}/generate`, {
            method: 'POST',
            headers: { 'Content-Type': 'application/json' },
            body: JSON.stringify({
                length: options.length || 16,
                count: options.count || 1,
                lowercase: options.lowercase !== false,
                uppercase: options.uppercase !== false,
                digits: options.digits !== false,
                special: options.special || false,
                exclude_similar: options.excludeSimilar || false,
                format: options.format || 'random'
            })
        });

        if (!response.ok) {
            throw new Error(`API Error: ${response.status}`);
        }

        return response.json();
    }

    async checkHealth() {
        const response = await fetch(`${this.baseURL}/health`);
        return response.json();
    }
}

// Utilisation
const passly = new PasslyClient();

const result = await passly.generatePassword({
    length: 24,
    special: true,
    excludeSimilar: true
});

console.log('Mot de passe:', result.data.passwords[0]);
console.log('Force:', result.data.strength);
console.log('Entropie:', result.data.entropy_bits, 'bits');