Have I Been Pwned

io.github.troyhunt/hibp

Breach intelligence API: email search, domain monitoring, passwords and stealer logs.

Description as published in the official MCP registry.

Answers the MCP handshake and lists its tools. Checked 2026-10-04.

What we measured

Endpointhttps://haveibeenpwned.com/mcpregistry
HandshakeAnswers the MCP handshake and lists its tools (669 ms)our check, 2026-10-04
Protocol version2026-07-28our check, 2026-10-04
Tools (17)hibp_list_breaches, hibp_get_breach, hibp_get_latest_breach, hibp_list_data_classes, hibp_get_pwned_passwords_range, hibp_get_breached_account, hibp_get_breached_account_range, hibp_get_paste_account, hibp_get_breached_domain, hibp_list_subscribed_domains, hibp_get_subscription_status, hibp_get_stealer_logs_by_email, hibp_get_stealer_logs_by_website_domain, hibp_get_stealer_logs_by_email_domain, hibp_generate_domain_verification_dns_token, hibp_verify_domain_verification_dns_token, hibp_send_domain_verification_emailtools/list, 2026-10-04
Registry version1.0.0 · active · updated 2026-07-22registry

Signed reports

No signed reports yet. A report carries a signed decision record from the reporter's gate, so it shows a real call went through, not just an opinion. How to file one.

Connect

claude mcp add --transport http hibp https://haveibeenpwned.com/mcp

Commands are built from the registry entry. Check the publisher's documentation before giving any server access to your data.

Related servers

Agents can read this page as data: MCP endpoint https://openforallofus.com/api/mcp, tool get_tool with name io.github.troyhunt/hibp.