HaveIBeenPwned website screenshot

HaveIBeenPwned

Have I Been Pwned (HIBP) is Troy Hunt's free breach-notification and credential-exposure service. The HIBP API v3 lets clients search for email addresses, pastes, stealer-log entries, and monitored domains across the world's largest aggregated breach corpus. A separate free k-anonymity password lookup is offered at api.pwnedpasswords.com.

HaveIBeenPwned publishes 8 APIs on the APIs.io network, including Breached Accounts API, Breaches API, Data Classes API, and 5 more. Tagged areas include Security, Breach Notification, Credential Stuffing, Stealer Logs, and K-Anonymity.

The HaveIBeenPwned catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

HaveIBeenPwned’s developer surface includes authentication, developer portal, signup flow, pricing, engineering blog, support, FAQ, and 19 more developer resources.

58.6/100 strong ▬ flat Agent 37/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
8 APIs 8 Features 5 Use Cases
SecurityBreach NotificationCredential StuffingStealer LogsK-AnonymityPrivacyIdentity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 58.6/100 · strong
Contract Quality 19.2 / 25
Developer Ergonomics 6.1 / 20
Commercial Clarity 14.2 / 20
Operational Transparency 2.7 / 13
Governance 8.3 / 12
Discoverability 8.2 / 10
Agent readiness — 37/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/haveibeenpwned: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 8

Individual APIs this provider publishes, each with its own machine-readable definition.

HaveIBeenPwned Breached Accounts API

Lookup breaches affecting an email address.

HaveIBeenPwned Breaches API

Browse breach metadata in the HIBP corpus.

HaveIBeenPwned Data Classes API

Enumerate classes of data exposed across breaches.

HaveIBeenPwned Domain Search API

Verify and search domains you control.

HaveIBeenPwned Pastes API

Lookup pastes referencing an email address.

HaveIBeenPwned Range Search API

K-anonymity range search for password hashes.

HaveIBeenPwned Stealer Logs API

Search infostealer malware corpora by email or domain.

HaveIBeenPwned Subscription API

Inspect the calling key's subscription state.

Scroll for all 8

Postman Collections 8

Ready-to-run Postman collections for exercising this provider's APIs.

Scroll for all 8

Open Collections 2

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Have I Been Pwned API v3

OPEN COLLECTION

Pwned Passwords API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Haveibeenpwned Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Email Breach Search

Lookup all breaches containing an email address.

K-Anonymity Email Search

Privacy-preserving breach lookup by SHA-1 prefix.

Paste Search

Discover paste-site dumps referencing an email.

Stealer Log Lookup

Surface infostealer captures by email, website domain, or email domain.

Domain Monitoring

Subscribe to monitor owned domains via DNS or email verification.

Subscribed Domains Inventory

Inspect monitored domains and pending renewals.

Pwned Passwords (Free)

K-anonymity password compromise lookups with optional response padding.

Subscription Tier Introspection

Inspect the calling key's tier, RPM, and feature flags.

Scroll for all 8

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Haveibeenpwned Context

12 classes · 22 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

HaveIBeenPwned API Rules

5 rules · 4 warnings 1 info

SPECTRAL

HaveIBeenPwned API Rules

12 rules · 5 errors 7 warnings

SPECTRAL

JSON Schema 6

Standalone JSON Schema definitions for this provider's data models.

Breach

19 properties

JSON SCHEMA

BreachedAccountRangeEntry

2 properties

JSON SCHEMA

Paste

5 properties

JSON SCHEMA

SubscribedDomain

5 properties

JSON SCHEMA

SubscriptionStatus

11 properties

JSON SCHEMA

PwnedPasswordsRangeResult

2 properties

JSON SCHEMA

JSON Structure 3

JSON Structure definitions describing this provider's data shapes.

Hibp Breach Structure

0 properties

JSON STRUCTURE

Hibp Paste Structure

0 properties

JSON STRUCTURE

Hibp Subscription Status Structure

0 properties

JSON STRUCTURE

Examples 15

Example request and response payloads for these APIs.

Scroll for all 15

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Haveibeenpwned Authentication

apiKey · 1 scheme

SECURITY

Haveibeenpwned Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Haveibeenpwned Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Haveibeenpwned Agentic Access

17 operations · 3 acting

17 operations · 3 acting

AGENTIC

Use Cases 5

What developers build with this provider.

Account Takeover Prevention

Block sign-ups using credentials known to be in public breaches.

Incident Response Triage

Quickly enumerate breaches and pastes touching an affected user.

Domain Risk Monitoring

Continuously detect when a domain's users appear in new breaches.

Password Strength Enforcement

Reject candidate passwords already present in the Pwned Passwords corpus.

Stealer Log Notification

Detect infostealer-captured credentials before adversaries weaponize them.

Integrations 5

Pre-built integrations with other platforms and tools.

1Password Watchtower

1Password leverages Pwned Passwords to flag compromised credentials.

Mozilla Firefox Monitor

Firefox's breach-notification feature is powered by HIBP.

Okta / Auth0

Identity providers use Pwned Passwords to enforce password policies.

Cloudflare

Cloudflare hosts and accelerates the Pwned Passwords k-anonymity API.

Microsoft Entra (Azure AD)

Banned-password lists can incorporate Pwned Passwords data.

Solutions 6

Packaged solutions this provider offers.

Pwned 1

Entry tier ($3.95/mo) for hobbyists and small projects.

Pwned 2

Mid-volume tier with stealer-log access.

Pwned 3

High-volume tier for security vendors and MSSPs.

Pwned 4

Enterprise tier with auto subdomain verification.

Pwned 5

Top tier ($995/mo) for large identity-protection platforms.

Pwned Passwords (Free)

Always-free k-anonymity password lookup at api.pwnedpasswords.com.

Resources

Get Started 2

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: haveibeenpwned
name: HaveIBeenPwned
description: Have I Been Pwned (HIBP) is Troy Hunt's free breach-notification and credential-exposure service. The HIBP API
  v3 lets clients search for email addresses, pastes, stealer-log entries, and monitored domains across the world's largest
  aggregated breach corpus. A separate free k-anonymity password lookup is offered at api.pwnedpasswords.com.
url: https://haveibeenpwned.com/API/v3
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
specificationVersion: '0.20'
created: '2026-05-28'
modified: '2026-05-30'
x-type: company
x-source: public-apis/public-apis
x-category: Security
x-tier: 1
x-tier-reason: real-profile-with-artifacts
image: https://haveibeenpwned.com/Content/Images/PwnedLogoLargeFollowed.png
tags:
- Security
- Breach Notification
- Credential Stuffing
- Stealer Logs
- K-Anonymity
- Privacy
- Identity
apis:
- aid: haveibeenpwned:haveibeenpwned-breached-accounts-api
  name: HaveIBeenPwned Breached Accounts API
  description: Lookup breaches affecting an email address.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Breached Accounts
  properties:
  - type: OpenAPI
    url: openapi/haveibeenpwned-breached-accounts-api-openapi.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: APIReference
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: JSONSchema
    url: json-schema/hibp-breach-schema.json
  - type: JSONSchema
    url: json-schema/hibp-paste-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscribed-domain-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscription-status-schema.json
  - type: JSONSchema
    url: json-schema/hibp-breached-account-range-entry-schema.json
  - type: JSONStructure
    url: json-structure/hibp-breach-structure.json
  - type: JSONStructure
    url: json-structure/hibp-paste-structure.json
  - type: JSONStructure
    url: json-structure/hibp-subscription-status-structure.json
  - type: Examples
    url: examples/hibp-get-breaches-for-account-example.json
  - type: Examples
    url: examples/hibp-get-breaches-by-range-example.json
  - type: Examples
    url: examples/hibp-list-breaches-example.json
  - type: Examples
    url: examples/hibp-get-breach-by-name-example.json
  - type: Examples
    url: examples/hibp-get-latest-breach-example.json
  - type: Examples
    url: examples/hibp-list-data-classes-example.json
  - type: Examples
    url: examples/hibp-get-pastes-for-account-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-website-domain-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-domain-example.json
  - type: Examples
    url: examples/hibp-get-breached-domain-example.json
  - type: Examples
    url: examples/hibp-list-subscribed-domains-example.json
  - type: Examples
    url: examples/hibp-get-subscription-status-example.json
  - type: Examples
    url: examples/hibp-generate-dns-token-example.json
  - type: RateLimits
    url: rate-limits/haveibeenpwned-rate-limits.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: JSONSchema
    url: json-schema/pwned-passwords-range-result-schema.json
  - type: Examples
    url: examples/pwned-passwords-search-range-example.json
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsCloudflareWorker
  - type: Tools
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- aid: haveibeenpwned:haveibeenpwned-breaches-api
  name: HaveIBeenPwned Breaches API
  description: Browse breach metadata in the HIBP corpus.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Breaches
  properties:
  - type: OpenAPI
    url: openapi/haveibeenpwned-breaches-api-openapi.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: APIReference
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: JSONSchema
    url: json-schema/hibp-breach-schema.json
  - type: JSONSchema
    url: json-schema/hibp-paste-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscribed-domain-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscription-status-schema.json
  - type: JSONSchema
    url: json-schema/hibp-breached-account-range-entry-schema.json
  - type: JSONStructure
    url: json-structure/hibp-breach-structure.json
  - type: JSONStructure
    url: json-structure/hibp-paste-structure.json
  - type: JSONStructure
    url: json-structure/hibp-subscription-status-structure.json
  - type: Examples
    url: examples/hibp-get-breaches-for-account-example.json
  - type: Examples
    url: examples/hibp-get-breaches-by-range-example.json
  - type: Examples
    url: examples/hibp-list-breaches-example.json
  - type: Examples
    url: examples/hibp-get-breach-by-name-example.json
  - type: Examples
    url: examples/hibp-get-latest-breach-example.json
  - type: Examples
    url: examples/hibp-list-data-classes-example.json
  - type: Examples
    url: examples/hibp-get-pastes-for-account-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-website-domain-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-domain-example.json
  - type: Examples
    url: examples/hibp-get-breached-domain-example.json
  - type: Examples
    url: examples/hibp-list-subscribed-domains-example.json
  - type: Examples
    url: examples/hibp-get-subscription-status-example.json
  - type: Examples
    url: examples/hibp-generate-dns-token-example.json
  - type: RateLimits
    url: rate-limits/haveibeenpwned-rate-limits.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: JSONSchema
    url: json-schema/pwned-passwords-range-result-schema.json
  - type: Examples
    url: examples/pwned-passwords-search-range-example.json
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsCloudflareWorker
  - type: Tools
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- aid: haveibeenpwned:haveibeenpwned-data-classes-api
  name: HaveIBeenPwned Data Classes API
  description: Enumerate classes of data exposed across breaches.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Data Classes
  properties:
  - type: OpenAPI
    url: openapi/haveibeenpwned-data-classes-api-openapi.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: APIReference
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: JSONSchema
    url: json-schema/hibp-breach-schema.json
  - type: JSONSchema
    url: json-schema/hibp-paste-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscribed-domain-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscription-status-schema.json
  - type: JSONSchema
    url: json-schema/hibp-breached-account-range-entry-schema.json
  - type: JSONStructure
    url: json-structure/hibp-breach-structure.json
  - type: JSONStructure
    url: json-structure/hibp-paste-structure.json
  - type: JSONStructure
    url: json-structure/hibp-subscription-status-structure.json
  - type: Examples
    url: examples/hibp-get-breaches-for-account-example.json
  - type: Examples
    url: examples/hibp-get-breaches-by-range-example.json
  - type: Examples
    url: examples/hibp-list-breaches-example.json
  - type: Examples
    url: examples/hibp-get-breach-by-name-example.json
  - type: Examples
    url: examples/hibp-get-latest-breach-example.json
  - type: Examples
    url: examples/hibp-list-data-classes-example.json
  - type: Examples
    url: examples/hibp-get-pastes-for-account-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-website-domain-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-domain-example.json
  - type: Examples
    url: examples/hibp-get-breached-domain-example.json
  - type: Examples
    url: examples/hibp-list-subscribed-domains-example.json
  - type: Examples
    url: examples/hibp-get-subscription-status-example.json
  - type: Examples
    url: examples/hibp-generate-dns-token-example.json
  - type: RateLimits
    url: rate-limits/haveibeenpwned-rate-limits.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: JSONSchema
    url: json-schema/pwned-passwords-range-result-schema.json
  - type: Examples
    url: examples/pwned-passwords-search-range-example.json
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsCloudflareWorker
  - type: Tools
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- aid: haveibeenpwned:haveibeenpwned-domain-search-api
  name: HaveIBeenPwned Domain Search API
  description: Verify and search domains you control.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Domain Search
  properties:
  - type: OpenAPI
    url: openapi/haveibeenpwned-domain-search-api-openapi.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: APIReference
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: JSONSchema
    url: json-schema/hibp-breach-schema.json
  - type: JSONSchema
    url: json-schema/hibp-paste-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscribed-domain-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscription-status-schema.json
  - type: JSONSchema
    url: json-schema/hibp-breached-account-range-entry-schema.json
  - type: JSONStructure
    url: json-structure/hibp-breach-structure.json
  - type: JSONStructure
    url: json-structure/hibp-paste-structure.json
  - type: JSONStructure
    url: json-structure/hibp-subscription-status-structure.json
  - type: Examples
    url: examples/hibp-get-breaches-for-account-example.json
  - type: Examples
    url: examples/hibp-get-breaches-by-range-example.json
  - type: Examples
    url: examples/hibp-list-breaches-example.json
  - type: Examples
    url: examples/hibp-get-breach-by-name-example.json
  - type: Examples
    url: examples/hibp-get-latest-breach-example.json
  - type: Examples
    url: examples/hibp-list-data-classes-example.json
  - type: Examples
    url: examples/hibp-get-pastes-for-account-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-website-domain-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-domain-example.json
  - type: Examples
    url: examples/hibp-get-breached-domain-example.json
  - type: Examples
    url: examples/hibp-list-subscribed-domains-example.json
  - type: Examples
    url: examples/hibp-get-subscription-status-example.json
  - type: Examples
    url: examples/hibp-generate-dns-token-example.json
  - type: RateLimits
    url: rate-limits/haveibeenpwned-rate-limits.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: JSONSchema
    url: json-schema/pwned-passwords-range-result-schema.json
  - type: Examples
    url: examples/pwned-passwords-search-range-example.json
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsCloudflareWorker
  - type: Tools
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- aid: haveibeenpwned:haveibeenpwned-pastes-api
  name: HaveIBeenPwned Pastes API
  description: Lookup pastes referencing an email address.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Pastes
  properties:
  - type: OpenAPI
    url: openapi/haveibeenpwned-pastes-api-openapi.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: APIReference
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: JSONSchema
    url: json-schema/hibp-breach-schema.json
  - type: JSONSchema
    url: json-schema/hibp-paste-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscribed-domain-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscription-status-schema.json
  - type: JSONSchema
    url: json-schema/hibp-breached-account-range-entry-schema.json
  - type: JSONStructure
    url: json-structure/hibp-breach-structure.json
  - type: JSONStructure
    url: json-structure/hibp-paste-structure.json
  - type: JSONStructure
    url: json-structure/hibp-subscription-status-structure.json
  - type: Examples
    url: examples/hibp-get-breaches-for-account-example.json
  - type: Examples
    url: examples/hibp-get-breaches-by-range-example.json
  - type: Examples
    url: examples/hibp-list-breaches-example.json
  - type: Examples
    url: examples/hibp-get-breach-by-name-example.json
  - type: Examples
    url: examples/hibp-get-latest-breach-example.json
  - type: Examples
    url: examples/hibp-list-data-classes-example.json
  - type: Examples
    url: examples/hibp-get-pastes-for-account-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-website-domain-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-domain-example.json
  - type: Examples
    url: examples/hibp-get-breached-domain-example.json
  - type: Examples
    url: examples/hibp-list-subscribed-domains-example.json
  - type: Examples
    url: examples/hibp-get-subscription-status-example.json
  - type: Examples
    url: examples/hibp-generate-dns-token-example.json
  - type: RateLimits
    url: rate-limits/haveibeenpwned-rate-limits.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: JSONSchema
    url: json-schema/pwned-passwords-range-result-schema.json
  - type: Examples
    url: examples/pwned-passwords-search-range-example.json
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsCloudflareWorker
  - type: Tools
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- aid: haveibeenpwned:haveibeenpwned-range-search-api
  name: HaveIBeenPwned Range Search API
  description: K-anonymity range search for password hashes.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Range Search
  properties:
  - type: OpenAPI
    url: openapi/haveibeenpwned-range-search-api-openapi.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: APIReference
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: JSONSchema
    url: json-schema/hibp-breach-schema.json
  - type: JSONSchema
    url: json-schema/hibp-paste-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscribed-domain-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscription-status-schema.json
  - type: JSONSchema
    url: json-schema/hibp-breached-account-range-entry-schema.json
  - type: JSONStructure
    url: json-structure/hibp-breach-structure.json
  - type: JSONStructure
    url: json-structure/hibp-paste-structure.json
  - type: JSONStructure
    url: json-structure/hibp-subscription-status-structure.json
  - type: Examples
    url: examples/hibp-get-breaches-for-account-example.json
  - type: Examples
    url: examples/hibp-get-breaches-by-range-example.json
  - type: Examples
    url: examples/hibp-list-breaches-example.json
  - type: Examples
    url: examples/hibp-get-breach-by-name-example.json
  - type: Examples
    url: examples/hibp-get-latest-breach-example.json
  - type: Examples
    url: examples/hibp-list-data-classes-example.json
  - type: Examples
    url: examples/hibp-get-pastes-for-account-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-website-domain-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-domain-example.json
  - type: Examples
    url: examples/hibp-get-breached-domain-example.json
  - type: Examples
    url: examples/hibp-list-subscribed-domains-example.json
  - type: Examples
    url: examples/hibp-get-subscription-status-example.json
  - type: Examples
    url: examples/hibp-generate-dns-token-example.json
  - type: RateLimits
    url: rate-limits/haveibeenpwned-rate-limits.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: JSONSchema
    url: json-schema/pwned-passwords-range-result-schema.json
  - type: Examples
    url: examples/pwned-passwords-search-range-example.json
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsCloudflareWorker
  - type: Tools
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- aid: haveibeenpwned:haveibeenpwned-stealer-logs-api
  name: HaveIBeenPwned Stealer Logs API
  description: Search infostealer malware corpora by email or domain.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Stealer Logs
  properties:
  - type: OpenAPI
    url: openapi/haveibeenpwned-stealer-logs-api-openapi.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: APIReference
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: JSONSchema
    url: json-schema/hibp-breach-schema.json
  - type: JSONSchema
    url: json-schema/hibp-paste-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscribed-domain-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscription-status-schema.json
  - type: JSONSchema
    url: json-schema/hibp-breached-account-range-entry-schema.json
  - type: JSONStructure
    url: json-structure/hibp-breach-structure.json
  - type: JSONStructure
    url: json-structure/hibp-paste-structure.json
  - type: JSONStructure
    url: json-structure/hibp-subscription-status-structure.json
  - type: Examples
    url: examples/hibp-get-breaches-for-account-example.json
  - type: Examples
    url: examples/hibp-get-breaches-by-range-example.json
  - type: Examples
    url: examples/hibp-list-breaches-example.json
  - type: Examples
    url: examples/hibp-get-breach-by-name-example.json
  - type: Examples
    url: examples/hibp-get-latest-breach-example.json
  - type: Examples
    url: examples/hibp-list-data-classes-example.json
  - type: Examples
    url: examples/hibp-get-pastes-for-account-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-website-domain-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-domain-example.json
  - type: Examples
    url: examples/hibp-get-breached-domain-example.json
  - type: Examples
    url: examples/hibp-list-subscribed-domains-example.json
  - type: Examples
    url: examples/hibp-get-subscription-status-example.json
  - type: Examples
    url: examples/hibp-generate-dns-token-example.json
  - type: RateLimits
    url: rate-limits/haveibeenpwned-rate-limits.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: JSONSchema
    url: json-schema/pwned-passwords-range-result-schema.json
  - type: Examples
    url: examples/pwned-passwords-search-range-example.json
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsCloudflareWorker
  - type: Tools
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- aid: haveibeenpwned:haveibeenpwned-subscription-api
  name: HaveIBeenPwned Subscription API
  description: Inspect the calling key's subscription state.
  humanURL: https://haveibeenpwned.com/API/v3
  baseURL: https://haveibeenpwned.com/api/v3
  tags:
  - Subscription
  properties:
  - type: OpenAPI
    url: openapi/haveibeenpwned-subscription-api-openapi.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3
  - type: APIReference
    url: https://haveibeenpwned.com/API/v3
  - type: Authentication
    url: https://haveibeenpwned.com/API/Key
  - type: JSONSchema
    url: json-schema/hibp-breach-schema.json
  - type: JSONSchema
    url: json-schema/hibp-paste-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscribed-domain-schema.json
  - type: JSONSchema
    url: json-schema/hibp-subscription-status-schema.json
  - type: JSONSchema
    url: json-schema/hibp-breached-account-range-entry-schema.json
  - type: JSONStructure
    url: json-structure/hibp-breach-structure.json
  - type: JSONStructure
    url: json-structure/hibp-paste-structure.json
  - type: JSONStructure
    url: json-structure/hibp-subscription-status-structure.json
  - type: Examples
    url: examples/hibp-get-breaches-for-account-example.json
  - type: Examples
    url: examples/hibp-get-breaches-by-range-example.json
  - type: Examples
    url: examples/hibp-list-breaches-example.json
  - type: Examples
    url: examples/hibp-get-breach-by-name-example.json
  - type: Examples
    url: examples/hibp-get-latest-breach-example.json
  - type: Examples
    url: examples/hibp-list-data-classes-example.json
  - type: Examples
    url: examples/hibp-get-pastes-for-account-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-website-domain-example.json
  - type: Examples
    url: examples/hibp-get-stealer-logs-by-email-domain-example.json
  - type: Examples
    url: examples/hibp-get-breached-domain-example.json
  - type: Examples
    url: examples/hibp-list-subscribed-domains-example.json
  - type: Examples
    url: examples/hibp-get-subscription-status-example.json
  - type: Examples
    url: examples/hibp-generate-dns-token-example.json
  - type: RateLimits
    url: rate-limits/haveibeenpwned-rate-limits.yml
  - type: Documentation
    url: https://haveibeenpwned.com/API/v3#PwnedPasswords
  - type: JSONSchema
    url: json-schema/pwned-passwords-range-result-schema.json
  - type: Examples
    url: examples/pwned-passwords-search-range-example.json
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction
  - type: SDKs
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsCloudflareWorker
  - type: Tools
    url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
common:
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/haveibeenpwned/overview
- type: AgenticAccess
  url: agentic-access/haveibeenpwned-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/haveibeenpwned-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/haveibeenpwned-domain-security.yml
- type: Authentication
  url: authentication/haveibeenpwned-authentication.yml
- type: Website
  url: https://haveibeenpwned.com
- type: Portal
  url: https://haveibeenpwned.com
- type: Signup
  url: https://haveibeenpwned.com/API/Key
- type: Pricing
  url: https://haveibeenpwned.com/API/Key
- type: Plans
  url: plans/haveibeenpwned-plans-pricing.yml
- type: RateLimits
  url: rate-limits/haveibeenpwned-rate-limits.yml
- type: TermsOfService
  url: https://haveibeenpwned.com/API/v3#License
- type: PrivacyPolicy
  url: https://haveibeenpwned.com/Privacy
- type: StatusPage
  url: https://status.haveibeenpwned.com
- type: Blog
  url: https://www.troyhunt.com
- type: GitHubOrganization
  url: https://github.com/HaveIBeenPwned
- type: Support
  url: https://haveibeenpwned.com/Contact
- type: FAQ
  url: https://haveibeenpwned.com/FAQs
- type: PublicAPIsListing
  url: https://github.com/public-apis/public-apis
- type: SpectralRules
  url: rules/hibp-rules.yml
- type: JSONLD
  url: json-ld/haveibeenpwned-context.jsonld
- type: Vocabulary
  url: vocabulary/haveibeenpwned-vocabulary.yml
- type: Tools
  url: https://github.com/HaveIBeenPwned/EmailAddressExtractor
  title: Email Address Extractor (CLI)
- type: Tools
  url: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
  title: Pwned Passwords Downloader (CLI)
- type: Tools
  url: https://github.com/HaveIBeenPwned/cloudflare-prometheus-exporter
  title: Cloudflare Prometheus Exporter
- type: Branding
  url: https://github.com/HaveIBeenPwned/Branding
- type: Features
  data:
  - name: Email Breach Search
    description: Lookup all breaches containing an email address.
  - name: K-Anonymity Email Search
    description: Privacy-preserving breach lookup by SHA-1 prefix.
  - name: Paste Search
    description: Discover paste-site dumps referencing an email.
  - name: Stealer Log Lookup
    description: Surface infostealer captures by email, website domain, or email domain.
  - name: Domain Monitoring
    description: Subscribe to monitor owned domains via DNS or email verification.
  - name: Subscribed Domains Inventory
    description: Inspect monitored domains and pending renewals.
  - name: Pwned Passwords (Free)
    description: K-anonymity password compromise lookups with optional response padding.
  - name: Subscription Tier Introspection
    description: Inspect the calling key's tier, RPM, and feature flags.
- type: UseCases
  data:
  - name: Account Takeover Prevention
    description: Block sign-ups using credentials known to be in public breaches.
  - name: Incident Response Triage
    description: Quickly enumerate breaches and pastes touching an affected user.
  - name: Domain Risk Monitoring
    description: Continuously detect when a domain's users appear in new breaches.
  - name: Password Strength Enforcement
    description: Reject candidate passwords already present in the Pwned Passwords corpus.
  - name: Stealer Log Notification
    description: Detect infostealer-captured credentials before adversaries weaponize them.
- type: Integrations
  data:
  - name: 1Password Watchtower
    description: 1Password leverages Pwned Passwords to flag compromised credentials.
  - name: Mozilla Firefox Monitor
    description: Firefox's breach-notification feature is powered by HIBP.
  - name: Okta / Auth0
    description: Identity providers use Pwned Passwords to enforce password policies.
  - name: Cloudflare
    description: Cloudflare hosts and accelerates the Pwned Passwords k-anonymity API.
  - name: Microsoft Entra (Azure AD)
    description: Banned-password lists can incorporate Pwned Passwords data.
- type: Solutions
  data:
  - name: Pwned 1
    description: Entry tier ($3.95/mo) for hobbyists and small projects.
  - name: Pwned 2
    description: Mid-volume tier with stealer-log access.
  - name: Pwned 3
    description: High-volume tier for security vendors and MSSPs.
  - name: Pwned 4
    description: Enterprise tier with auto subdomain verification.
  - name: Pwned 5
    description: Top tier ($995/mo) for large identity-protection platforms.
  - name: Pwned Passwords (Free)
    description: Always-free k-anonymity password lookup at api.pwnedpasswords.com.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com