zxcvbn Connector for AI agents.
1 live capability
Audit password security with real crack time estimates and entropy analysis.
Waiting for input…
Why people use zxcvbn
Password Strength Scorer for Cybersecurity Entropy Audits
This Connector automates the heavy lifting. Your agent can run every password through the zxcvbn engine to get a precise 0-4 score and a crack time estimate. You get a clear picture of risk without the manual grunt work.
What Vinkius changes
You get a data-driven security score instead of a generic AI guess.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 5,900+ Connectors
- Real-world use case 01
Auditing API keys
A developer asks the agent to check a set of auto-generated API keys for security compliance before deployment.
- Real-world use case 02
User feedback loops
A sign-up flow tells a user why their password is weak and provides specific suggestions on how to fix it.
- Real-world use case 03
Corporate policy verification
An IT admin verifies if new employee passwords meet actual security standards rather than just checking for a symbol.
Complete set · 1capability
The complete zxcvbn capability set.
These are the exact actions your AI can choose when you ask it to work with zxcvbn.
01
1 capability in this set.
Part of 1 available through zxcvbn.
- 01 Capability
Score password strength
Send a password to the engine to get a 0-4 score and crack time estimates. This capability identifies patterns like keyboard sequences and dates to give you a real sense of security.
Set up in minutes
One URL. Then ask zxcvbn to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use zxcvbn from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_NJZOdN2hIY4Yj0pMDCcP324aC60LQVkrwnFN1xP0/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it zxcvbn, and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable zxcvbn for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_NJZOdN2hIY4Yj0pMDCcP324aC60LQVkrwnFN1xP0/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the zxcvbn URL.
- Step 03
Save and start
Save the connection and enable zxcvbn in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"password-strength-scorer": {
"url": "https://edge.vinkius.com/vk_preview_NJZOdN2hIY4Yj0pMDCcP324aC60LQVkrwnFN1xP0/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using zxcvbn
Open Agent mode in chat and ask: "Using zxcvbn, help me...". 1 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"password-strength-scorer": {
"url": "https://edge.vinkius.com/vk_preview_NJZOdN2hIY4Yj0pMDCcP324aC60LQVkrwnFN1xP0/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using zxcvbn
Ask Copilot: "Using zxcvbn, help me...". 1 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"password-strength-scorer": {
"url": "https://edge.vinkius.com/vk_preview_NJZOdN2hIY4Yj0pMDCcP324aC60LQVkrwnFN1xP0/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using zxcvbn
Open Cascade and ask: "Using zxcvbn, help me...". 1 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"password-strength-scorer": {
"url": "https://edge.vinkius.com/vk_preview_NJZOdN2hIY4Yj0pMDCcP324aC60LQVkrwnFN1xP0/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using zxcvbn
Ask Cline: "Using zxcvbn, help me...". 1 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add password-strength-scorer --transport http "https://edge.vinkius.com/vk_preview_NJZOdN2hIY4Yj0pMDCcP324aC60LQVkrwnFN1xP0/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using zxcvbn
Ask Claude: "Using zxcvbn, show me...". 1 tools are ready
Where the request belongs
Work zxcvbn can move forward.
Security engineers tired of manual audits, IT admins enforcing new policies, and developers building auth systems.
Security Auditor
Uses the capability to check user passwords against entropy standards during a security review.
DevOps Engineer
Audits auto-generated API keys for security compliance before deploying them to production.
App Developer
Integrates real-time feedback into a sign-up flow to help users create stronger passwords.
Build the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsPassword Strength Evaluator
Equip SecOps agents with Dropbox's zxcvbn engine. Algorithmically evaluate password entropy and crack times local.
Password Generator API
Generate secure passwords. audit entropy and length via AI.
IT Compliance Password Gen
Generate unbreakable, cryptographically secure passwords. Enforce strict IT compliance rules, symbol constraints, and entropy requirements.
Password Manager Export Analyzer
Analyze Bitwarden, LastPass, or 1Password CSV exports for weak and duplicate passwords. without EVER sending real passwords to the AI.
Password Entropy Calculator
Calculate password entropy, identify pattern risks, and verify security policy compliance.
Bcrypt Hash Engine
Hash and verify passwords with the industry-standard bcrypt algorithm. Two capabilities in one: hash with configurable salt rounds, and verify against stored hashes. Pure JS. zero compilation.
Bring your own AI
Change the model, client or framework. Keep zxcvbn connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about zxcvbn.
The practical details behind the request, access and result.
How does Password Strength Scorer work for my data?
It runs 100% locally on your machine. Your passwords never leave your environment or hit a network, making it safe for sensitive security audits.
Can I use Password Strength Scorer to check API keys?
Yes, it's excellent for that. It analyzes the entropy of the key to give you a score and a crack time estimate, helping you verify security before deployment.
Is Password Strength Scorer better than standard complexity checks?
Yes, because it looks at real crack difficulty. Instead of just checking for symbols, it detects common patterns, keyboard sequences, and l33t-speak.
Does Password Strength Scorer give actual crack times?
It does. You'll get estimates for different scenarios, including online throttled attacks and local fast hash attacks.
Can I use Password Strength Scorer to help users create better passwords?
Absolutely. The capability provides actionable feedback that explains exactly why a password is weak and gives specific suggestions on how to improve it.
Is Password Strength Scorer safe for production use?
It is safe for analysis because it's local. You can use it to audit credentials or build feedback loops without exposing your data to third-party APIs.
Why can't my AI evaluate password strength?
AI checks superficial rules like 'has uppercase + number + symbol'. zxcvbn does combinatorial analysis. it knows 'P@ssw0rd' is just 'Password' with l33t substitutions, and rates it as weak despite passing every 'rule-based' check.
Is the password sent to any external server?
No. 100% local. The embedded dictionary and pattern matching engine run entirely in-process. Zero network calls, zero data leakage, zero risk.
What do the crack time numbers actually mean?
Four real attack scenarios: Online throttled (100/hour. most login pages), Online unthrottled (10/sec), Local slow hash (10K/sec. bcrypt), Local fast hash (10B/sec. MD5/SHA). Choose the scenario matching your system.
One connection away
Give your agent a direct line to zxcvbn.
Connect zxcvbn once. Keep it beside 5,900+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available