Have I Been Pwned website screenshot

Have I Been Pwned

Have I Been Pwned (HIBP) is a free service operated by Troy Hunt that lets individuals and organizations check whether their email addresses, phone numbers, passwords, or domains have appeared in known data breaches, pastes, or stealer logs. The service aggregates billions of compromised records and exposes both free and paid endpoints, including the k-anonymity Pwned Passwords API. The v3 REST API at haveibeenpwned.com requires an hibp-api-key header for breach, paste, domain, and stealer log endpoints and is offered across Core, Pro, and High RPM subscription tiers.

Have I Been Pwned publishes 14 APIs on the APIs.io network, including Breach API, Breachedaccount API, Breacheddomain API, and 11 more. Tagged areas include Security, Data Breaches, Pwned Passwords, Identity, and Threat Intelligence.

The Have I Been Pwned catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Have I Been Pwned’s developer surface includes authentication, documentation, pricing, signup flow, FAQ, engineering blog, developer portal, and 20 more developer resources.

52.8/100 developing ▬ flat Agent 45/100 agent ready Full breakdown ↓
scored 2026-08-21 · rubric v0.12.0
AccessSelf serve
16 APIs 8 Features 5 Use Cases
SecurityData BreachesPwned PasswordsIdentityThreat IntelligenceCredential Stuffing

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-21 · rubric v0.12.0
Composite quality — 52.8/100 · developing
Contract Quality 15.1 / 25
Developer Ergonomics 7.6 / 20
Access Clarity 16.8 / 20
Operational Transparency 2.4 / 13
Contract Governance 3.5 / 12
Discoverability 7.4 / 10
Agent readiness — 45/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
Documented Reversibility 0 / 6
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/have-i-been-pwned: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 16

Individual APIs this provider publishes, each with its own machine-readable definition.

Have I Been Pwned API v3

REST API for searching breached accounts, pastes, breach metadata, domain breach data, and stealer log entries. Authentication requires an hibp-api-key header (32-character key)...

Pwned Passwords API

Free, unauthenticated, k-anonymity-based API to check whether a password hash appears in the 800+ million record Pwned Passwords dataset. Clients submit the first five character...

Have I Been Pwned Breach API

The Breach API from Have I Been Pwned — 1 operation(s) for breach.

Have I Been Pwned Breachedaccount API

The Breachedaccount API from Have I Been Pwned — 2 operation(s) for breachedaccount.

Have I Been Pwned Breacheddomain API

The Breacheddomain API from Have I Been Pwned — 1 operation(s) for breacheddomain.

Have I Been Pwned Breaches API

The Breaches API from Have I Been Pwned — 1 operation(s) for breaches.

Have I Been Pwned Dataclasses API

The Dataclasses API from Have I Been Pwned — 1 operation(s) for dataclasses.

Have I Been Pwned Domainverification API

The Domainverification API from Have I Been Pwned — 3 operation(s) for domainverification.

Have I Been Pwned Latestbreach API

The Latestbreach API from Have I Been Pwned — 1 operation(s) for latestbreach.

Have I Been Pwned Pasteaccount API

The Pasteaccount API from Have I Been Pwned — 1 operation(s) for pasteaccount.

Have I Been Pwned Range API

The Range API from Have I Been Pwned — 1 operation(s) for range.

Have I Been Pwned Stealerlogsbyemail API

The Stealerlogsbyemail API from Have I Been Pwned — 1 operation(s) for stealerlogsbyemail.

Have I Been Pwned Stealerlogsbyemaildomain API

The Stealerlogsbyemaildomain API from Have I Been Pwned — 1 operation(s) for stealerlogsbyemaildomain.

Have I Been Pwned Stealerlogsbywebsitedomain API

The Stealerlogsbywebsitedomain API from Have I Been Pwned — 1 operation(s) for stealerlogsbywebsitedomain.

Have I Been Pwned Subscribeddomains API

The Subscribeddomains API from Have I Been Pwned — 1 operation(s) for subscribeddomains.

Have I Been Pwned Subscription API

The Subscription API from Have I Been Pwned — 1 operation(s) for subscription.

Scroll for all 16

Postman Collections 8

Ready-to-run Postman collections for exercising this provider's APIs.

Scroll for all 8

Open Collections 24

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

Have I Been Pwned API v3

OPEN COLLECTION

Have I Been Pwned API v3

OPEN COLLECTION

Pwned Passwords API

OPEN COLLECTION

Scroll for all 24

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Have I Been Pwned Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Email Breach Search

Lookup all breaches containing an email address.

K-Anonymity Email Search

Privacy-preserving breach lookup by SHA-1 prefix.

Paste Search

Discover paste-site dumps referencing an email.

Stealer Log Lookup

Surface infostealer captures by email, website domain, or email domain.

Domain Monitoring

Subscribe to monitor owned domains via DNS or email verification.

Subscribed Domains Inventory

Inspect monitored domains and pending renewals.

Pwned Passwords (Free)

K-anonymity password compromise lookups with optional response padding.

Subscription Tier Introspection

Inspect the calling key's tier, RPM, and feature flags.

Scroll for all 8

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Have I Been Pwned Context

12 classes · 22 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Have I Been Pwned API Rules

5 rules · 4 warnings 1 info

SPECTRAL

Have I Been Pwned API Rules

12 rules · 5 errors 7 warnings

SPECTRAL

JSON Schema 6

Standalone JSON Schema definitions for this provider's data models.

Breach

19 properties

JSON SCHEMA

BreachedAccountRangeEntry

2 properties

JSON SCHEMA

Paste

5 properties

JSON SCHEMA

SubscribedDomain

5 properties

JSON SCHEMA

SubscriptionStatus

11 properties

JSON SCHEMA

PwnedPasswordsRangeResult

2 properties

JSON SCHEMA

JSON Structure 3

JSON Structure definitions describing this provider's data shapes.

Hibp Breach Structure

0 properties

JSON STRUCTURE

Hibp Paste Structure

0 properties

JSON STRUCTURE

Hibp Subscription Status Structure

0 properties

JSON STRUCTURE

Examples 15

Example request and response payloads for these APIs.

Scroll for all 15

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Have I Been Pwned Authentication

apiKey · 1 scheme

SECURITY

Have I Been Pwned Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Have I Been Pwned Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Have I Been Pwned Agentic Access

17 operations · 3 acting

17 operations · 3 acting

AGENTIC

Use Cases 5

What developers build with this provider.

Account Takeover Prevention

Block sign-ups using credentials known to be in public breaches.

Incident Response Triage

Quickly enumerate breaches and pastes touching an affected user.

Domain Risk Monitoring

Continuously detect when a domain's users appear in new breaches.

Password Strength Enforcement

Reject candidate passwords already present in the Pwned Passwords corpus.

Stealer Log Notification

Detect infostealer-captured credentials before adversaries weaponize them.

Integrations 5

Pre-built integrations with other platforms and tools.

1Password Watchtower

1Password leverages Pwned Passwords to flag compromised credentials.

Mozilla Firefox Monitor

Firefox's breach-notification feature is powered by HIBP.

Okta / Auth0

Identity providers use Pwned Passwords to enforce password policies.

Cloudflare

Cloudflare hosts and accelerates the Pwned Passwords k-anonymity API.

Microsoft Entra (Azure AD)

Banned-password lists can incorporate Pwned Passwords data.

Solutions 6

Packaged solutions this provider offers.

Pwned 1

Entry tier ($3.95/mo) for hobbyists and small projects.

Pwned 2

Mid-volume tier with stealer-log access.

Pwned 3

High-volume tier for security vendors and MSSPs.

Pwned 4

Enterprise tier with auto subdomain verification.

Pwned 5

Top tier ($995/mo) for large identity-protection platforms.

Pwned Passwords (Free)

Always-free k-anonymity password lookup at api.pwnedpasswords.com.

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: have-i-been-pwned
name: Have I Been Pwned
description: Have I Been Pwned (HIBP) is a free service operated by Troy Hunt that lets individuals and organizations check
  whether their email addresses, phone numbers, passwords, or domains have appeared in known data breaches, pastes, or stealer
  logs. The service aggregates billions of compromised records and exposes both free and paid endpoints, including the k-anonymity
  Pwned Passwords API. The v3 REST API at haveibeenpwned.com requires an hibp-api-key header for breach, paste, domain, and
  stealer log endpoints and is offered across Core, Pro, and High RPM subscription tiers.
type: Index
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/have-i-been-pwned.png
tags:
- Security
- Data Breaches
- Pwned Passwords
- Identity
- Threat Intelligence
- Credential Stuffing
url: https://raw.githubusercontent.com/api-evangelist/have-i-been-pwned/refs/heads/main/apis.yml
created: '2026-05-11'
modified: '2026-08-08'
specificationVersion: '0.23'
apis:
- aid: have-i-been-pwned:api-v3
  name: Have I Been Pwned API v3
  description: REST API for searching breached accounts, pastes, breach metadata, domain breach data, and stealer log entries.
    Authentication requires an hibp-api-key header (32-character key) along with a descriptive user-agent header. Most endpoints
    require a paid subscription; rate limits range from 600 to 100,000 requests per minute depending on tier.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Breaches
  - Pastes
  - Stealer Logs
  - Domain Search
  - Account Search
  properties:
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: Pricing
    url: https://haveibeenpwned.com/API/Key
- aid: have-i-been-pwned:pwned-passwords
  name: Pwned Passwords API
  description: Free, unauthenticated, k-anonymity-based API to check whether a password hash appears in the 800+ million record
    Pwned Passwords dataset. Clients submit the first five characters of a SHA-1 hash and receive a list of matching suffixes
    with counts. No rate limit and no attribution required.
  humanURL: https://haveibeenpwned.com/API/v3#PwnedPasswords
  baseURL: https://api.pwnedpasswords.com
  tags:
  - Passwords
  - K-Anonymity
  - SHA-1
  - Credential Stuffing
  properties:
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: Project
    url: https://haveibeenpwned.com/Passwords
- aid: have-i-been-pwned:have-i-been-pwned-breach-api
  name: Have I Been Pwned Breach API
  description: The Breach API from Have I Been Pwned — 1 operation(s) for breach.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Breach
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-breach-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-breachedaccount-api
  name: Have I Been Pwned Breachedaccount API
  description: The Breachedaccount API from Have I Been Pwned — 2 operation(s) for breachedaccount.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Breachedaccount
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-breachedaccount-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-breacheddomain-api
  name: Have I Been Pwned Breacheddomain API
  description: The Breacheddomain API from Have I Been Pwned — 1 operation(s) for breacheddomain.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Breacheddomain
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-breacheddomain-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-breaches-api
  name: Have I Been Pwned Breaches API
  description: The Breaches API from Have I Been Pwned — 1 operation(s) for breaches.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Breaches
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-breaches-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-dataclasses-api
  name: Have I Been Pwned Dataclasses API
  description: The Dataclasses API from Have I Been Pwned — 1 operation(s) for dataclasses.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - DataClasses
  tags_raw:
  - Dataclasses
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-dataclasses-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-domainverification-api
  name: Have I Been Pwned Domainverification API
  description: The Domainverification API from Have I Been Pwned — 3 operation(s) for domainverification.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Domain Verification
  tags_raw:
  - Domainverification
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-domainverification-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-latestbreach-api
  name: Have I Been Pwned Latestbreach API
  description: The Latestbreach API from Have I Been Pwned — 1 operation(s) for latestbreach.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Latestbreach
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-latestbreach-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-pasteaccount-api
  name: Have I Been Pwned Pasteaccount API
  description: The Pasteaccount API from Have I Been Pwned — 1 operation(s) for pasteaccount.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Pasteaccount
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-pasteaccount-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-range-api
  name: Have I Been Pwned Range API
  description: The Range API from Have I Been Pwned — 1 operation(s) for range.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Range
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-range-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-stealerlogsbyemail-api
  name: Have I Been Pwned Stealerlogsbyemail API
  description: The Stealerlogsbyemail API from Have I Been Pwned — 1 operation(s) for stealerlogsbyemail.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Stealerlogsbyemail
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-stealerlogsbyemail-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-stealerlogsbyemaildomain-api
  name: Have I Been Pwned Stealerlogsbyemaildomain API
  description: The Stealerlogsbyemaildomain API from Have I Been Pwned — 1 operation(s) for stealerlogsbyemaildomain.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Stealerlogsbyemaildomain
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-stealerlogsbyemaildomain-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-stealerlogsbywebsitedomain-api
  name: Have I Been Pwned Stealerlogsbywebsitedomain API
  description: The Stealerlogsbywebsitedomain API from Have I Been Pwned — 1 operation(s) for stealerlogsbywebsitedomain.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Stealerlogsbywebsitedomain
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-stealerlogsbywebsitedomain-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-subscribeddomains-api
  name: Have I Been Pwned Subscribeddomains API
  description: The Subscribeddomains API from Have I Been Pwned — 1 operation(s) for subscribeddomains.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Subscribeddomains
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-subscribeddomains-api-openapi.yml
- aid: have-i-been-pwned:have-i-been-pwned-subscription-api
  name: Have I Been Pwned Subscription API
  description: The Subscription API from Have I Been Pwned — 1 operation(s) for subscription.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Subscription
  properties:
  - type: OpenAPI
    url: openapi/have-i-been-pwned-subscription-api-openapi.yml
common:
- type: AgenticAccess
  url: agentic-access/have-i-been-pwned-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/have-i-been-pwned-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/have-i-been-pwned-domain-security.yml
- type: Authentication
  url: authentication/have-i-been-pwned-authentication.yml
- type: GitHubOrganization
  url: https://github.com/HaveIBeenPwned
- type: LinkedIn
  url: https://www.linkedin.com/company/haveibeenpwned
- type: Website
  url: https://haveibeenpwned.com
- type: Documentation
  url: https://haveibeenpwned.com/API/v3
- type: Pricing
  url: https://haveibeenpwned.com/API/Key
- type: Signup
  url: https://haveibeenpwned.com/API/Key
- type: FAQ
  url: https://haveibeenpwned.com/FAQs
- type: Blog
  url: https://www.troyhunt.com
- type: Twitter
  url: https://twitter.com/haveibeenpwned
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/haveibeenpwned/overview
- type: Portal
  url: https://haveibeenpwned.com
- type: Plans
  url: plans/have-i-been-pwned-plans-pricing.yml
- type: RateLimits
  url: rate-limits/have-i-been-pwned-rate-limits.yml
- type: TermsOfService
  url: https://haveibeenpwned.com/API/v3#License
- type: PrivacyPolicy
  url: https://haveibeenpwned.com/Privacy
- type: StatusPage
  url: https://status.haveibeenpwned.com
- type: Support
  url: https://haveibeenpwned.com/Contact
- type: PublicAPIsListing
  url: https://github.com/public-apis/public-apis
- type: SpectralRules
  url: rules/hibp-rules.yml
- type: JSONLD
  url: json-ld/have-i-been-pwned-context.jsonld
- type: Vocabulary
  url: vocabulary/have-i-been-pwned-vocabulary.yml
- type: Tools
  url: https://github.com/HaveIBeenPwned/EmailAddressExtractor
  title: Email Address Extractor (CLI)
- type: Branding
  url: https://github.com/HaveIBeenPwned/Branding
- type: Features
  data:
  - name: Email Breach Search
    description: Lookup all breaches containing an email address.
  - name: K-Anonymity Email Search
    description: Privacy-preserving breach lookup by SHA-1 prefix.
  - name: Paste Search
    description: Discover paste-site dumps referencing an email.
  - name: Stealer Log Lookup
    description: Surface infostealer captures by email, website domain, or email domain.
  - name: Domain Monitoring
    description: Subscribe to monitor owned domains via DNS or email verification.
  - name: Subscribed Domains Inventory
    description: Inspect monitored domains and pending renewals.
  - name: Pwned Passwords (Free)
    description: K-anonymity password compromise lookups with optional response padding.
  - name: Subscription Tier Introspection
    description: Inspect the calling key's tier, RPM, and feature flags.
  url: ''
- type: UseCases
  data:
  - name: Account Takeover Prevention
    description: Block sign-ups using credentials known to be in public breaches.
  - name: Incident Response Triage
    description: Quickly enumerate breaches and pastes touching an affected user.
  - name: Domain Risk Monitoring
    description: Continuously detect when a domain's users appear in new breaches.
  - name: Password Strength Enforcement
    description: Reject candidate passwords already present in the Pwned Passwords corpus.
  - name: Stealer Log Notification
    description: Detect infostealer-captured credentials before adversaries weaponize them.
  url: ''
- type: Integrations
  data:
  - name: 1Password Watchtower
    description: 1Password leverages Pwned Passwords to flag compromised credentials.
  - name: Mozilla Firefox Monitor
    description: Firefox's breach-notification feature is powered by HIBP.
  - name: Okta / Auth0
    description: Identity providers use Pwned Passwords to enforce password policies.
  - name: Cloudflare
    description: Cloudflare hosts and accelerates the Pwned Passwords k-anonymity API.
  - name: Microsoft Entra (Azure AD)
    description: Banned-password lists can incorporate Pwned Passwords data.
  url: ''
- type: Solutions
  data:
  - name: Pwned 1
    description: Entry tier ($3.95/mo) for hobbyists and small projects.
  - name: Pwned 2
    description: Mid-volume tier with stealer-log access.
  - name: Pwned 3
    description: High-volume tier for security vendors and MSSPs.
  - name: Pwned 4
    description: Enterprise tier with auto subdomain verification.
  - name: Pwned 5
    description: Top tier ($995/mo) for large identity-protection platforms.
  - name: Pwned Passwords (Free)
    description: Always-free k-anonymity password lookup at api.pwnedpasswords.com.
  url: ''
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
x-merged-from:
- haveibeenpwned

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/have-i-been-pwned"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/have-i-been-pwned/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/have-i-been-pwned/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.