The API Report CardAPI Index
Have I Been Pwned

Have I Been Pwned API

Data breach exposure and credential checking · haveibeenpwned.com

Have I Been Pwned ships a public v3 REST reference and self-serve API keys bought on published subscription tiers, so production access is a checkout away. Auth is a single API key header. Coverage stays narrow, with webhooks, exports, and official SDKs missing.

Last verified: August 2026Security & ComplianceNO MCP
API GRADE
B
VERIFIED AUG 2026

SCORECARD

ExistenceGOODA public v3 REST reference is live at haveibeenpwned.com/API/v3 and api.haveibeenpwned.com answers on probe.
AccessGOODKeys are bought self-serve through Stripe checkout on published subscription tiers, with no sales call required.
CoverageMIXEDBreach, paste, stealer log, domain search, and subscription lookups are reachable, but webhooks and bulk export are absent.
AuthGOODAuthorised calls use a single hibp-api-key request header; oauth grants are not offered, and Pwned Passwords needs no key.
Docs & DXGOODThe v3 reference, demo videos, and a support knowledge base are public, though official SDK languages are not listed.
StabilityGOODThe surface has held on the versioned /api/v3 path with plan badges marking which endpoints each tier reaches.
MCPNONENo official or community MCP server found for this platform.
MORE FROM THE REPORT CARD
Supergood turns hard-to-integrate enterprise software into clean REST APIs and MCP tools: stable endpoints, normalized JSON, managed auth.

Frequently asked questions

Have I Been Pwned scores B on Supergood's API Report Card. Have I Been Pwned ships a public v3 REST reference and self-serve API keys bought on published subscription tiers, so production access is a checkout away. Auth is a single API key header. Coverage stays narrow, with webhooks, exports, and official SDKs missing.

Tried to integrate with Have I Been Pwned?