https://developer.okta.com/blog/2018/06/11/how-to-prevent-yo... ("How to Prevent Your Users from Using Breached Passwords") | https://github.com/OktaSecurityLabs/passprotect-js is an example.
Good behavior:
> The new NIST recommendations mean that every time a user gives you a password, it’s your responsibility as a developer to check their password against a list of breached passwords and prevent the user from using a previously breached password.
SP 800-63 specifically: https://pages.nist.gov/800-63-3/ | https://pages.nist.gov/800-63-4/