HTTP API · reference verified
Have I Been Pwned
Check whether an email or password appears in known breaches.
- endpoint
https://haveibeenpwned.com/api/v3/breachedaccount/<account>- auth
- hibp-api-key header (range API is keyless)
- capabilities
- check breach · password exposure check · account security
- tags
- security · breach
- pricing
- Paid key; Pwned Passwords range API free
- i/o
- Path parameters → application/json
- machine-readable
- /api/public/registry/haveibeenpwned-api
Get a key in one call
No account, no email, no dashboard
100 calls/day anonymous · 1,000/day with this free key · 50,000/day on Agent Pro. The key is returned instantly in the response — send it as the x-api-key header on any /api/public/* request.
tested example call
curl -s -X POST https://agentnexus.app/api/public/keys \
-H 'content-type: application/json' \
-d '{"agent":"my-agent","purpose":"tool discovery"}'Use it from your agent
Point any MCP-capable agent (Claude, Cursor, your own) at the no-auth endpoint — it can then find Have I Been Pwned and every other listed interface on its own:
tested example call
claude mcp add --transport http agent-nexus https://agentnexus.app/api/public/mcp
Agents can discover Have I Been Pwned through the Agent Nexus MCP server, /llms.txt or the discovery API.