Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Have I Been Pwned API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fhaveibeenpwned.com%2Fhaveibeenpwned" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fhaveibeenpwned.com%2Fhaveibeenpwned" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Have I Been Pwned API.
Check an account for every breach it appears in
List breached accounts across a subscribed domain
Retrieve the full catalog of breached sites and a single breach's details
Find pastes that contain a given account
Look up stealer-log entries by email, website domain, or email domain
GET STARTED
Read subscription status and the domains attached to a subscription
Patterns agents use Have I Been Pwned API for, with concrete tasks.
★ Agent-Driven Breach Check
An AI agent connected through Jentic checks an email address against Have I Been Pwned and reports which breaches it appears in and what data classes those breaches exposed. Because the account lookup is a single call, the agent screens an address during onboarding or support without a human running the check manually.
Check an email address for breaches, then retrieve each breach's details to report the exposed data classes
Domain Breach Monitoring
Security teams watching a domain list the breached accounts across it. Have I Been Pwned returns breached accounts for a subscribed domain and stealer-log entries by website or email domain, so an agent produces a domain exposure report instead of checking addresses one by one.
Retrieve breached accounts for a subscribed domain and summarize which accounts need password resets
Breach Catalog Enrichment
Dashboards describing a breach pull its record from the catalog, including the data classes it exposed and when it was added. The catalog and single-breach operations let an agent annotate an account hit with the breach's name, date, and exposed fields for a clearer report.
Fetch the latest breach and its data classes and add the details to a monitoring feed
12 endpoints — the have i been pwned api checks whether an email address, account, or domain appears in known data breaches, pastes, and stealer logs.
METHOD
PATH
DESCRIPTION
/breachedaccount/{account}
Get all breaches for an account
/breacheddomain/{domain}
Get breached accounts for a domain
/breaches
Get the catalog of all breaches
/breach/{name}
Get a single breached site
/pasteaccount/{account}
Get all pastes for an account
/stealerlogsByEmail/{email}
Get stealer logs by email address
/subscribeddomains
List subscribed domains
/breachedaccount/{account}
Get all breaches for an account
/breacheddomain/{domain}
Get breached accounts for a domain
/breaches
Get the catalog of all breaches
/breach/{name}
Get a single breached site
/pasteaccount/{account}
Get all pastes for an account
/stealerlogsByEmail/{email}
Get stealer logs by email address
/subscribeddomains
List subscribed domains
What agents get from Jentic-routed access to this vendor.
Setup
Wiring Have I Been Pwned by hand means obtaining the key, setting the `hibp-api-key` header on every request, and respecting the per-tier request pacing yourself. Through Jentic you install once, import Have I Been Pwned from the API Directory, store the key once, and your agent calls the breach and domain lookups.
Permission scoping
Every Have I Been Pwned operation is a read lookup, so there is nothing destructive to guard against. You still choose which lookups your agent may call, so a rule can allow account and domain breach checks while leaving paste or stealer-log reads out unless you add them.
Credential isolation
Your Have I Been Pwned API key is held by your own Jentic One instance, encrypted, and injected into the `hibp-api-key` header at execution time. It never enters the agent's prompt, logs, or context.
Intent-based discovery
Agents search Jentic by intent such as 'check an email for breaches' or 'list breached accounts for a domain', and Jentic returns the matching Have I Been Pwned operation with its input schema so the agent calls the right endpoint without browsing the reference docs.
Alternatives and complements available in the Jentic catalogue.
Specific to using Have I Been Pwned API through Jentic.
What authentication does the Have I Been Pwned API use?
The API uses an API key sent in the `hibp-api-key` request header, per its OpenAPI spec. Through Jentic the key is held by your own Jentic One instance and attached to each request at execution time, so it never appears in your agent's prompt or logs.
Can I check whether an email address is in a breach with the Have I Been Pwned API?
Yes. The account operation returns every breach a given account appears in, and the breach-catalog operations describe each breach and the data classes it exposed. Your agent screens an address and then annotates the result with breach names and dates.
What are the rate limits for the Have I Been Pwned API?
The OpenAPI spec does not specify numeric rate limits, which depend on your subscription tier. Check the Have I Been Pwned API documentation at https://haveibeenpwned.com/API/v3 for the current per-tier limits before running bulk domain scans.
Is there a Have I Been Pwned MCP server?
You do not need an MCP server to give your agent the Have I Been Pwned API. Jentic connects it directly from the API Directory: import it, store your key once, and your agent calls the breach, paste, and stealer-log lookups on demand without loading an extra server's tool definitions into its context.
Can I limit what my agent is allowed to do with the Have I Been Pwned API?
Yes. Every operation is a read lookup, so write a rule that allows only the account-breach and domain-breach lookups and the agent can check whether an address or domain appears in a breach without reading paste or stealer-log data. You choose which lookups it may call, and every call it makes is logged.
How do I check an account for breaches through Jentic?
Install the Jentic One command line with `curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh`, then add the Have I Been Pwned API from the Jentic directory and search by intent such as 'check an email for breaches'. Jentic returns the matching operation with its input schema so your agent builds a valid request. To run it on your own infrastructure, install Jentic One from its GitHub repo.
For Agents
Check whether an email address, account, or domain appears in known data breaches, pastes, or stealer logs, and read the catalog of breached sites and the data classes they exposed, through the Have I Been Pwned API.
Use for: Check whether an email address appears in any known breach, List all breached accounts for a domain I monitor, Get the details of a specific breached site, Find pastes that mention a given email address
Not supported: Does not reset passwords, send breach notifications, or scan networks. Use for looking up breach, paste, and stealer-log exposure of accounts and domains only.
The Have I Been Pwned API checks whether an email address, account, or domain appears in known data breaches, pastes, and stealer logs. It returns the breaches an account is caught in, the full catalog of breached sites and the data classes each exposed, and the pastes an account shows up in. Domain-level operations list breached accounts across a subscribed domain and surface stealer-log entries tied to an email, website domain, or email domain.
This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.
Base layer of spec validity and structural soundness.
Aggregated quality score from linter diagnostics, weighted by severity.
Percentage of `$ref` references that resolve successfully.
Checks whether the API description parses successfully and conforms to its declared specification (e.g., OpenAPI).
Structural correctness score based on schema issues using logarithmic dampening.
Clarity, completeness, and ingestion readiness for developers and tooling.
How richly the API is illustrated with examples.
Percentage of examples that conform to their schemas.
Percentage of operations with complete response definitions (success, client error, server error).
Health of API ingestion, bundling, and resolution within Jentic pipelines.
Semantic breadth, depth, and agent comprehension for AI systems.
Coverage of descriptions across API elements.
Coverage of RFC 9457 Problem Details for error responses.
Coverage, uniqueness, and casing consistency of operationIds for AI inference.
Coverage of summaries across operations/tags/info.
Functional utility, complexity comfort, and AI orchestration readiness.
Agent comfort level based on API operational and structural complexity.
Trust, risk posture, and security compliance.
Average quality of security schemes based on authentication method strength (weakest link for OAuth2).
Findability, semantic richness, and reasoning readiness.
Clarity and depth of descriptions across API elements.
Score it yourself
Every API in the directory is allowlisted, so you can re-score it with no key required.
npx @jentic/api-scorecard-cli score <openapi-url>