openapi: 3.0.3
info:
title: Have I Been Pwned API v3 Breach Subscribeddomains API
description: Version 3 of the Have I Been Pwned API. Authenticated APIs for breaches by account, pastes, domain search, domain verification, stealer logs, and subscription status require both the hibp-api-key and user-agent headers. Availability varies by subscription tier and is noted per operation. The Pwned Passwords range API is free and does not require authentication.
version: 3.0.0
license:
name: Creative Commons Attribution 4.0 International
url: https://creativecommons.org/licenses/by/4.0/
servers:
- url: https://haveibeenpwned.com/api/v3
description: HIBP API v3 server
- url: https://api.pwnedpasswords.com
description: Pwned Passwords k-Anonymity API (no authentication required)
tags:
- name: Subscribeddomains
paths:
/subscribeddomains:
servers:
- url: https://haveibeenpwned.com/api/v3
get:
summary: Get all subscribed domains for API key
description: Available on Core and Pro subscriptions. Returns the domains associated with the supplied hibp-api-key after they have been added to the domain search dashboard and verified.
parameters:
- $ref: '#/components/parameters/UserAgent'
security:
- HibpApiKey: []
responses:
'200':
description: List of subscribed domains
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/SubscribedDomain'
'401':
description: Unauthorized — the hibp-api-key header was missing, malformed, or invalid.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Forbidden — no user agent has been specified in the request.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
x-hibp-subscription-tiers:
- Core
- Pro
tags:
- Subscribeddomains
components:
parameters:
UserAgent:
name: user-agent
in: header
required: true
description: User agent string identifying the consuming application. Required on all documented requests, including unauthenticated endpoints; missing user agents may receive HTTP 403 responses.
schema:
type: string
schemas:
SubscribedDomain:
type: object
properties:
DomainName:
type: string
description: The full domain name that has been successfully verified.
PwnCount:
type: integer
nullable: true
description: The total number of breached email addresses found on the domain at last search (will be null if no searches yet performed).
PwnCountExcludingSpamLists:
type: integer
nullable: true
description: The number of breached email addresses found on the domain at last search, excluding any breaches flagged as a spam list (will be null if no searches yet performed).
PwnCountExcludingSpamListsAtLastSubscriptionRenewal:
type: integer
nullable: true
description: The total number of breached email addresses found on the domain when the current subscription was taken out (will be null if no searches yet performed). This number ensures the domain remains searchable throughout the subscription period even if the volume of breached accounts grows beyond the subscription's scope.
NextSubscriptionRenewal:
type: string
format: date-time
nullable: true
description: The date and time the current subscription ends in ISO 8601 format. The PwnCountExcludingSpamListsAtLastSubscriptionRenewal value is locked in until this time (will be null if there have been no subscriptions).
required:
- DomainName
Error:
type: object
properties:
statusCode:
type: integer
message:
type: string
required:
- statusCode
- message
description: Standard error response returned by most authenticated HIBP APIs.
securitySchemes:
HibpApiKey:
type: apiKey
in: header
name: hibp-api-key
description: HIBP API key passed in the hibp-api-key header. Paid APIs require a 32-character hexadecimal value. On supported test-only endpoints, any 32-character hexadecimal value can be used as a test key for the hibp-integration-tests.com domain.
externalDocs:
description: Full API documentation and acceptable use policy
url: https://haveibeenpwned.com/API/v3