canonical: https://jentic.com/apis/haveibeenpwned.com/haveibeenpwned

# Have I Been Pwned API

The Have I Been Pwned API checks whether an email address, account, or domain appears in known data breaches, pastes, and stealer logs. It returns the breaches an account is caught in, the full catalog of breached sites and the data classes each exposed, and the pastes an account shows up in. Domain-level operations list breached accounts across a subscribed domain and surface stealer-log entries tied to an email, website domain, or email domain.

## For AI agents

Check whether an email address, account, or domain appears in known data breaches, pastes, or stealer logs, and read the catalog of breached sites and the data classes they exposed, through the Have I Been Pwned API.

## Scope

Does not reset passwords, send breach notifications, or scan networks. Use for looking up breach, paste, and stealer-log exposure of accounts and domains only.

## Capabilities

- Check an account for every breach it appears in
- List breached accounts across a subscribed domain
- Retrieve the full catalog of breached sites and a single breach's details
- Find pastes that contain a given account
- Look up stealer-log entries by email, website domain, or email domain
- Read subscription status and the domains attached to a subscription

## Use cases

### Agent-Driven Breach Check

An AI agent connected through Jentic checks an email address against Have I Been Pwned and reports which breaches it appears in and what data classes those breaches exposed. Because the account lookup is a single call, the agent screens an address during onboarding or support without a human running the check manually.

Example prompt: Check an email address for breaches, then retrieve each breach's details to report the exposed data classes

### Domain Breach Monitoring

Security teams watching a domain list the breached accounts across it. Have I Been Pwned returns breached accounts for a subscribed domain and stealer-log entries by website or email domain, so an agent produces a domain exposure report instead of checking addresses one by one.

Example prompt: Retrieve breached accounts for a subscribed domain and summarize which accounts need password resets

### Breach Catalog Enrichment

Dashboards describing a breach pull its record from the catalog, including the data classes it exposed and when it was added. The catalog and single-breach operations let an agent annotate an account hit with the breach's name, date, and exposed fields for a clearer report.

Example prompt: Fetch the latest breach and its data classes and add the details to a monitoring feed

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | `/breachedaccount/{account}` | Get all breaches for an account |
| GET | `/breacheddomain/{domain}` | Get breached accounts for a domain |
| GET | `/breaches` | Get the catalog of all breaches |
| GET | `/breach/{name}` | Get a single breached site |
| GET | `/pasteaccount/{account}` | Get all pastes for an account |
| GET | `/stealerlogsByEmail/{email}` | Get stealer logs by email address |
| GET | `/subscribeddomains` | List subscribed domains |

## Key resources

- **Breached accounts** — Check an account for breaches and list breached accounts across a domain
- **Breaches** — Retrieve the full breach catalog, a single breach, and the latest breach
- **Data classes** — List the data classes breaches can expose
- **Pastes** — Find pastes that contain a given account
- **Stealer logs** — Look up stealer-log entries by email, website domain, or email domain
- **Subscription** — Read subscription status and subscribed domains

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 60 / 100
- **Maturity:** AI-Aware
- **Dimensions:**
  - Foundational Compliance: 100 / 100
  - Developer Experience & Jentic Compatibility: 57 / 100
  - AI-Readiness & Agent Experience: 43 / 100
  - Agent Usability: 94 / 100
  - Security: 50 / 100
  - AI Discoverability: 57 / 100
- **View full report:** https://jentic.com/apis/haveibeenpwned.com/haveibeenpwned/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring Have I Been Pwned by hand means obtaining the key, setting the `hibp-api-key` header on every request, and respecting the per-tier request pacing yourself. Through Jentic you install once, import Have I Been Pwned from the API Directory, store the key once, and your agent calls the breach and domain lookups.
- **Permission scoping:** Every Have I Been Pwned operation is a read lookup, so there is nothing destructive to guard against. You still choose which lookups your agent may call, so a rule can allow account and domain breach checks while leaving paste or stealer-log reads out unless you add them.
- **Credential handling:** Your Have I Been Pwned API key is held by your own Jentic One instance, encrypted, and injected into the `hibp-api-key` header at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'check an email for breaches' or 'list breached accounts for a domain', and Jentic returns the matching Have I Been Pwned operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Censys Search API** — Censys inventories hosts and certificates for attack-surface monitoring, a different exposure lens than Have I Been Pwned's breach data.
- **Shodan API** — Shodan maps internet-exposed devices and services, complementing Have I Been Pwned's account breach checks.
- **AbuseIPDB API** — AbuseIPDB reports IP address abuse reputation, pairing with breach checks for a fuller risk picture.

## FAQ

### What authentication does the Have I Been Pwned API use?

The API uses an API key sent in the `hibp-api-key` request header, per its OpenAPI spec. Through Jentic the key is held by your own Jentic One instance and attached to each request at execution time, so it never appears in your agent's prompt or logs.

### Can I check whether an email address is in a breach with the Have I Been Pwned API?

Yes. The account operation returns every breach a given account appears in, and the breach-catalog operations describe each breach and the data classes it exposed. Your agent screens an address and then annotates the result with breach names and dates.

### What are the rate limits for the Have I Been Pwned API?

The OpenAPI spec does not specify numeric rate limits, which depend on your subscription tier. Check the Have I Been Pwned API documentation at https://haveibeenpwned.com/API/v3 for the current per-tier limits before running bulk domain scans.

### Is there a Have I Been Pwned MCP server?

You do not need an MCP server to give your agent the Have I Been Pwned API. Jentic connects it directly from the API Directory: import it, store your key once, and your agent calls the breach, paste, and stealer-log lookups on demand without loading an extra server's tool definitions into its context.

### Can I limit what my agent is allowed to do with the Have I Been Pwned API?

Yes. Every operation is a read lookup, so write a rule that allows only the account-breach and domain-breach lookups and the agent can check whether an address or domain appears in a breach without reading paste or stealer-log data. You choose which lookups it may call, and every call it makes is logged.

### How do I check an account for breaches through Jentic?

Install the Jentic One command line with `curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh`, then add the Have I Been Pwned API from the Jentic directory and search by intent such as 'check an email for breaches'. Jentic returns the matching operation with its input schema so your agent builds a valid request. To run it on your own infrastructure, install Jentic One from its GitHub repo.
