Mmcp.market

Have I Been Pwned MCP server

by troyhunt·io.github.troyhunt/hibp·v1.0.0

Breach intelligence API: email search, domain monitoring, passwords and stealer logs.

C57/100grade C
What users say
No reviews yet
Be the first
Safety scan
C57/100

full report

Adoption
New

Little public usage data yet

Reviews

Write one

Nobody has reviewed Have I Been Pwned yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Have I Been Pwned tools (17, 3 write)

write = sends, deletes, buys or posts
  • hibp_generate_domain_verification_dns_tokenFree

    Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request. Requires an authenticated subscription with domain-verification access.

  • hibp_get_breachFree

    Look up a single public HIBP breach by its canonical breach name, such as Adobe.

  • hibp_get_breached_accountFree

    Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification filters to refine the result.

  • hibp_get_breached_account_rangeFree

    Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anonymity access; compare each returned suffix with the remaining hash characters locally because a prefix alone cannot identify an account.

  • hibp_get_breached_domainFree

    Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.

  • hibp_get_latest_breachFree

    Return the most recently added public breach currently loaded into HIBP.

  • hibp_get_paste_accountFree

    Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from breached-account lookup.

  • hibp_get_pwned_passwords_rangeFree

    Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.

  • hibp_get_stealer_logs_by_emailwrite actionFree

    Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.

  • hibp_get_stealer_logs_by_email_domainwrite actionFree

    Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.

  • hibp_get_stealer_logs_by_website_domainFree

    Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.

  • hibp_get_subscription_statusFree

    Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use it to confirm access before feature-dependent lookups.

  • hibp_list_breachesFree

    List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.

  • hibp_list_data_classesFree

    List the data classes used across public HIBP breach models, such as email addresses or passwords.

  • hibp_list_subscribed_domainsFree

    List the domains associated with the authenticated HIBP subscription.

  • hibp_send_domain_verification_emailwrite actionFree

    Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.

  • hibp_verify_domain_verification_dns_tokenFree

    Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.

Public scan report

scanner v0.1.9 · 2026-09-25 · same rubric, same numbers if you re-run it

1 high1 low
  • –Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 429ms20/20
  • Tool poisoning17 tool descriptions checked15/15
  • Auth qualityopen endpoint exposes 3 write-action tools with no auth3/15
  • Maintenanceno repository listed3/15
  • Maintainer identityno repository or website to verify2/10

Findings (2)

  • highWrite-action tools reachable without authenticationauth.open-write
  • lowNo source repository listedmaint.no-repo
Overall 57/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http hibp https://haveibeenpwned.com/mcp
Add to Cursor

Have I Been Pwned: common questions

Is Have I Been Pwned MCP server safe?
With care: it is graded C, so read the findings first (57/100). Read the Have I Been Pwned safety report
How do I install Have I Been Pwned?
It runs remotely at haveibeenpwned.com. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Have I Been Pwned need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Have I Been Pwned maintained?
The latest release is v1.0.0.
Is Have I Been Pwned up?
100% of our last 28 checks got an answer. We check remote servers about four times a day.
What can I use instead of Have I Been Pwned?
Servers from other publishers that do the same job: OpenOSINT MCP server, MCP server and Shipmail MCP server. Compare all Have I Been Pwned alternatives.

Alternatives to Have I Been Pwned

Same job from other publishers: the closest match first, then the best rated.

All Have I Been Pwned alternatives →
  • OpenOSINT
    AI-powered OSINT agent & MCP server. 16 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.
    C
  • MCP
    20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
    A
  • Shipmail
    Shipmail MCP server for AI agent custom-domain email inboxes with REST API and webhooks.
    A
  • smbCloud Mail & Auth
    Email infrastructure and authentication for developers: domains, inbox routes, auth apps, deploys.
    A
  • MCP Server
    AI agents read & send email, manage mailboxes, domains and webhooks via the QMailing API.
    A

More from troyhunt →