Public APIs
HaveIBeenPwned favicon

HaveIBeenPwned

Security

Passwords which have previously been exposed in data breaches.

HaveIBeenPwned's website screenshot

About HaveIBeenPwned

HaveIBeenPwned's API v3 is a RESTful service for searching pwned email addresses and passwords. It supports searching breaches for a specific email address either by sending the address directly to the API or via a privacy-preserving k-anonymity hash range lookup, and returns matching breach names by default or the full breach model on request. It also covers domain search (verifying domains via DNS or email, then listing all breached email addresses for a domain or all subscribed domains), retrieval of all breaches in the system, a single breach by name, the most recently added breach, and data classes, plus paste data associated with an email address and stealer log lookups (domains for an email address, email addresses for a website domain, and email aliases for an email domain).

Authorization via an "hibp-api-key" header is required for email address search, domain search, paste search, and stealer log endpoints; the Pwned Passwords API (hash-range search, NTLM hash search, and full hash list download) requires no authorization. A test API key is available for use against designated test email addresses in place of a paid subscription. Every request must include a descriptive user-agent header, and endpoint availability varies by subscription tier (Core, Pro, High RPM). An MCP server is also published, exposing HIBP's breach metadata, Pwned Passwords, stealer logs, domain workflows, and subscriber features to AI agents and MCP-capable clients via the Model Context Protocol.

This API is intended for developers building applications that check email addresses, domains, or passwords against known data breaches, such as security tools, identity monitoring services, or password validation features.

Key features

  • Search for pwned email addresses across known data breaches
  • Privacy-preserving k-anonymity hash range search for email addresses
  • Domain search to find all breached email addresses for a verified domain
  • Free Pwned Passwords API to check password hashes (including NTLM) against breach data
  • Stealer log lookups by email address or website/email domain
  • MCP server exposing HIBP tools for AI agents and MCP-capable clients

Frequently asked questions

Is there a free tier?

The Pwned Passwords API is free and requires no authorisation, but searching by email address or domain requires a paid HIBP subscription key. A test API key is also available for limited access to test email addresses.

How do I authenticate requests?

Authenticated endpoints require an HIBP subscription key passed in the "hibp-api-key" header, and every request must also include a user agent header or it returns an HTTP 403.

Can I use HIBP with AI agents?

Yes, Have I Been Pwned publishes an MCP server that exposes HIBP tools for breach metadata, Pwned Passwords, stealer logs, domain workflows, and subscriber features via the Model Context Protocol.

Who is this API for?

It is aimed at developers building apps or services that need to check whether email addresses, passwords, or domains have appeared in known data breaches.

What data can I search for a domain?

Once a domain is verified via DNS or email, the API can return all breached email addresses and subscribed domains associated with it.

Advertise here

Featured products

  • SerpApi - Search API favicon
  • Screenshot Scout favicon
  • TalorData favicon
  • CoreClaw favicon

Show your product to thousands of developers

· 100k monthly pageviews
· 7k newsletter subscribers

Advertise your product