io.github.troyhunt/hibp
name:io.github.troyhunt/hibp
Breach intelligence API: email search, domain monitoring, passwords and stealer logs.
- transport:
- remote
- credential class:
- self-provisionable
Owner verification
Not yet verified. Verifying proves you control this server and is free, permanently — it never changes a published score.
Start verification →Tools
- hibp_generate_domain_verification_dns_tokenshallow
Generate the TXT record value required to verify domain control via DNS. Requires an authenticated subscription with domain-verification access.
- hibp_get_breachshallow
Look up a single public HIBP breach by its canonical breach name, such as Adobe.
- hibp_get_breached_accountshallow
Search HIBP for breaches affecting a single email address. This tool requires an OAuth bearer token.
- hibp_get_breached_account_rangeshallow
Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash.
- hibp_get_breached_domainshallow
Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.
- hibp_get_latest_breachshallow
Return the most recently added public breach currently loaded into HIBP.
- hibp_get_paste_accountshallow
Search for public pastes containing an email address. This tool requires an OAuth bearer token.
- hibp_get_pwned_passwords_rangeshallow
Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.
- hibp_get_stealer_logs_by_emailshallow
Return website domains observed in stealer logs for an email address. Requires an authenticated subscription with stealer-log access.
- hibp_get_stealer_logs_by_email_domainshallow
Return email aliases and associated website domains observed in stealer logs for an email domain. Requires an authenticated subscription with stealer-log access.
- hibp_get_stealer_logs_by_website_domainshallow
Return email addresses observed in stealer logs for a website domain. Requires an authenticated subscription with stealer-log access.
- hibp_get_subscription_statusshallow
Return the current subscription details and feature flags for the authenticated OAuth-linked HIBP subscription.
- hibp_list_breachesshallow
List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.
- hibp_list_data_classesshallow
List the data classes used across public HIBP breach models, such as email addresses or passwords.
- hibp_list_subscribed_domainsshallow
List the domains associated with the authenticated HIBP subscription.
- hibp_send_domain_verification_emailshallow
Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.
- hibp_verify_domain_verification_dns_tokenshallow
Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.
Embed this server’s score
Tool count and median score across every tool in this server’s corpus — honest in a way a single cherry-picked tool’s badge wouldn’t be.
[](https://vouch.tools/servers/79f6ccb5-544a-4eee-8b87-88094212c7b7)