Have I Been Pwned Stealerlogsbyemail API

The Stealerlogsbyemail API from Have I Been Pwned — 1 operation(s) for stealerlogsbyemail.

OpenAPI Specification

have-i-been-pwned-stealerlogsbyemail-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Have I Been Pwned API v3 Breach Stealerlogsbyemail API
  description: Version 3 of the Have I Been Pwned API. Authenticated APIs for breaches by account, pastes, domain search, domain verification, stealer logs, and subscription status require both the hibp-api-key and user-agent headers. Availability varies by subscription tier and is noted per operation. The Pwned Passwords range API is free and does not require authentication.
  version: 3.0.0
  license:
    name: Creative Commons Attribution 4.0 International
    url: https://creativecommons.org/licenses/by/4.0/
servers:
- url: https://haveibeenpwned.com/api/v3
  description: HIBP API v3 server
- url: https://api.pwnedpasswords.com
  description: Pwned Passwords k-Anonymity API (no authentication required)
tags:
- name: Stealerlogsbyemail
paths:
  /stealerlogsbyemail/{email}:
    servers:
    - url: https://haveibeenpwned.com/api/v3
    get:
      summary: Get all stealer log domains for an email address
      description: Available on Pro subscriptions. Searches stealer-log data by the full email address captured by an info stealer. The email address must be on a domain already added to the domain search dashboard and successfully verified. The current subscription must include stealer-log access.
      parameters:
      - $ref: '#/components/parameters/UserAgent'
      - name: email
        in: path
        required: true
        schema:
          type: string
        description: URL-encoded email address to search for stealer logs. Must be on a verified domain in the domain search dashboard.
      security:
      - HibpApiKey: []
      responses:
        '200':
          description: List of website domains sorted alphabetically where this email address appeared in stealer logs
          content:
            application/json:
              schema:
                type: array
                items:
                  type: string
              example:
              - netflix.com
              - spotify.com
        '401':
          description: Unauthorized — the hibp-api-key header was missing, malformed, or invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — no user agent has been specified in the request, the email domain has not been verified for this subscription, or the current subscription product does not include access to stealer logs.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Not found — there are no stealer logs for that email address.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Too many requests — the rate limit has been exceeded.
          headers:
            Retry-After:
              description: Seconds until retry (rounded up to the next whole second)
              schema:
                type: integer
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                statusCode: 429
                message: Rate limit is exceeded. Try again in 2 seconds.
        '503':
          description: Service unavailable — usually returned by Cloudflare if the underlying service is not available.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      x-hibp-subscription-tiers:
      - Pro
      tags:
      - Stealerlogsbyemail
components:
  parameters:
    UserAgent:
      name: user-agent
      in: header
      required: true
      description: User agent string identifying the consuming application. Required on all documented requests, including unauthenticated endpoints; missing user agents may receive HTTP 403 responses.
      schema:
        type: string
  schemas:
    Error:
      type: object
      properties:
        statusCode:
          type: integer
        message:
          type: string
      required:
      - statusCode
      - message
      description: Standard error response returned by most authenticated HIBP APIs.
  securitySchemes:
    HibpApiKey:
      type: apiKey
      in: header
      name: hibp-api-key
      description: HIBP API key passed in the hibp-api-key header. Paid APIs require a 32-character hexadecimal value. On supported test-only endpoints, any 32-character hexadecimal value can be used as a test key for the hibp-integration-tests.com domain.
externalDocs:
  description: Full API documentation and acceptable use policy
  url: https://haveibeenpwned.com/API/v3