Have I Been Pwned MCP server
Breach intelligence API: email search, domain monitoring, passwords and stealer logs.
Little public usage data yet
Reviews
Write oneNobody has reviewed Have I Been Pwned yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Have I Been Pwned tools (17, 3 write)
write = sends, deletes, buys or postshibp_generate_domain_verification_dns_tokenFreeGenerate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request. Requires an authenticated subscription with domain-verification access.
hibp_get_breachFreeLook up a single public HIBP breach by its canonical breach name, such as Adobe.
hibp_get_breached_accountFreeSearch HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification filters to refine the result.
hibp_get_breached_account_rangeFreeQuery the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anonymity access; compare each returned suffix with the remaining hash characters locally because a prefix alone cannot identify an account.
hibp_get_breached_domainFreeReturn breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.
hibp_get_latest_breachFreeReturn the most recently added public breach currently loaded into HIBP.
hibp_get_paste_accountFreeSearch for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from breached-account lookup.
hibp_get_pwned_passwords_rangeFreeQuery the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.
hibp_get_stealer_logs_by_emailwrite actionFreeReturn website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
hibp_get_stealer_logs_by_email_domainwrite actionFreeReturn email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
hibp_get_stealer_logs_by_website_domainFreeReturn email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
hibp_get_subscription_statusFreeReturn the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use it to confirm access before feature-dependent lookups.
hibp_list_breachesFreeList public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.
hibp_list_data_classesFreeList the data classes used across public HIBP breach models, such as email addresses or passwords.
hibp_list_subscribed_domainsFreeList the domains associated with the authenticated HIBP subscription.
hibp_send_domain_verification_emailwrite actionFreeSend a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.
hibp_verify_domain_verification_dns_tokenFreeComplete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.
Public scan report
scanner v0.1.9 · 2026-09-25 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 429ms20/20
- Tool poisoning17 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 3 write-action tools with no auth3/15
- Maintenanceno repository listed3/15
- Maintainer identityno repository or website to verify2/10
Findings (2)
- highWrite-action tools reachable without authentication
auth.open-write - lowNo source repository listed
maint.no-repo
Install directly
claude mcp add --transport http hibp https://haveibeenpwned.com/mcp
Have I Been Pwned: common questions
- Is Have I Been Pwned MCP server safe?
- With care: it is graded C, so read the findings first (57/100). Read the Have I Been Pwned safety report
- How do I install Have I Been Pwned?
- It runs remotely at haveibeenpwned.com. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Have I Been Pwned need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Have I Been Pwned maintained?
- The latest release is v1.0.0.
- Is Have I Been Pwned up?
- 100% of our last 28 checks got an answer. We check remote servers about four times a day.
- What can I use instead of Have I Been Pwned?
- Servers from other publishers that do the same job: OpenOSINT MCP server, MCP server and Shipmail MCP server. Compare all Have I Been Pwned alternatives.
Alternatives to Have I Been Pwned
Same job from other publishers: the closest match first, then the best rated.
- OpenOSINTAI-powered OSINT agent & MCP server. 16 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.not reviewedEstablishedC
- MCP20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.not reviewedGrowingA
- ShipmailShipmail MCP server for AI agent custom-domain email inboxes with REST API and webhooks.not reviewedGrowingA
smbCloud Mail & AuthEmail infrastructure and authentication for developers: domains, inbox routes, auth apps, deploys.not reviewedGrowingA
MCP ServerAI agents read & send email, manage mailboxes, domains and webhooks via the QMailing API.not reviewedGrowingA