Have I Been Pwned ships a public v3 REST reference and self-serve API keys bought on published subscription tiers, so production access is a checkout away. Auth is a single API key header. Coverage stays narrow, with webhooks, exports, and official SDKs missing.
Have I Been Pwned scores B on Supergood's API Report Card. Have I Been Pwned ships a public v3 REST reference and self-serve API keys bought on published subscription tiers, so production access is a checkout away. Auth is a single API key header. Coverage stays narrow, with webhooks, exports, and official SDKs missing.
Have I Been Pwned has a workable official integration path. Most engineering teams can build against it directly. Solid API with minor gaps
Have I Been Pwned is a breach exposure service that lets businesses and developers check whether email addresses, domains, or passwords appear in known data breach corpora.
Security and compliance tooling is the vertical, and the target market is security engineers, identity and access teams, fraud and risk analysts, and product developers who need to know whether credentials or corporate domains have been exposed. Teams call the breached account endpoint to check an email address against the breach corpus during onboarding, support, or incident response, and call domain name search to enumerate breached addresses across a domain they have verified.
Public customer counts and named reference customers are not published in the sources reviewed, though the service runs published paid tiers, a support knowledge base, a demo library, and a free Pwned Passwords endpoint that any application can call without a key.
The valuable data behind the key is breach exposure intelligence: which breaches an email address appears in with breach metadata, paste appearances, the set of breached addresses across a verified corporate domain, stealer log entries tied to an address or domain, and compromised password hash prefixes.
The public surface is on version 3, reached at haveibeenpwned.com/api/v3/{service}/{parameter}, and the documentation is maintained with plan badges marking which endpoints belong to which subscription tier.
Common alternatives include SpyCloud, Enzoic, Constella Intelligence, DeHashed. Graded alternatives appear under "More from the report card" below.
Supergood's grades measure one thing: can a customer's engineering team get their own data out programmatically? Supergood checks six things (whether a real API exists, how access is gated, data coverage, auth quality, docs and developer experience, and stability) and rolls them into a letter grade. Supergood re-verifies grades, and they only move on evidence.
Not that we could find. There is no official Have I Been Pwned MCP server in any public registry, and no maintained community server we're aware of. We re-verify this periodically — report an inaccuracy below if we missed one.
Not natively. Have I Been Pwned doesn't publish an MCP server, so MCP clients like Claude, Cursor, and Codex have nothing to connect to out of the box. If that changes, this page will reflect it.