{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_c2s7m73h568x","handle":"have-i-been-pwned","url":"https://wellknown.network/agents/have-i-been-pwned","links":{"self":"https://wellknown.network/agents/have-i-been-pwned/record.json","html":"https://wellknown.network/agents/have-i-been-pwned","markdown":"https://wellknown.network/agents/have-i-been-pwned/record.md","api":"https://wellknown.network/api/v1/agents/have-i-been-pwned","status":"https://wellknown.network/api/v1/agents/have-i-been-pwned/status","claim":"https://wellknown.network/agents/have-i-been-pwned/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/have-i-been-pwned/claim.json","badge":"https://wellknown.network/agents/have-i-been-pwned/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air:haveibeenpwned.com:server:have-i-been-pwned","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"Have I Been Pwned","summary":"Breach intelligence API: email search, domain monitoring, passwords and stealer logs.","description":"Breach intelligence API: email search, domain monitoring, passwords and stealer logs.","publisher":{"name":"troyhunt","url":null},"homepage":null,"repository":null,"version":"1.0.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://haveibeenpwned.com/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-07-22T23:01:39.352464Z","publishedAt":"2026-07-22T23:01:39.352464Z","registryName":"io.github.troyhunt/hibp"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"dev.monitoring","name":"Monitoring & Observability","confidence":1,"provenance":"derived"},{"slug":"productivity.email","name":"Email","confidence":0.859,"provenance":"derived"}],"categories":["dev","productivity"]},"observed":{"status":"live","statusReason":"Responded 12h ago.","lastOkAt":"2026-09-08T09:25:59.852Z","lastProbedAt":"2026-09-08T09:25:59.852Z","statusComputedAt":"2026-09-08T09:35:46.509Z","reliability30d":{"probes":5,"successRate":1,"p50Ms":52},"latestObservations":[{"at":"2026-09-08T16:22:28.543Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":71,"error":null,"detail":{"tools":[{"name":"hibp_list_breaches","description":"List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status."},{"name":"hibp_get_breach","description":"Look up a single public HIBP breach by its canonical breach name, such as Adobe."},{"name":"hibp_get_latest_breach","description":"Return the most recently added public breach currently loaded into HIBP."},{"name":"hibp_list_data_classes","description":"List the data classes used across public HIBP breach models, such as email addresses or passwords."},{"name":"hibp_get_pwned_passwords_range","description":"Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts."},{"name":"hibp_get_breached_account","description":"Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification"},{"name":"hibp_get_breached_account_range","description":"Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anony"},{"name":"hibp_get_paste_account","description":"Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from b"},{"name":"hibp_get_breached_domain","description":"Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token."},{"name":"hibp_list_subscribed_domains","description":"List the domains associated with the authenticated HIBP subscription."},{"name":"hibp_get_subscription_status","description":"Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use i"},{"name":"hibp_get_stealer_logs_by_email","description":"Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_website_domain","description":"Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_email_domain","description":"Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with"},{"name":"hibp_generate_domain_verification_dns_token","description":"Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request"},{"name":"hibp_verify_domain_verification_dns_token","description":"Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification acce"},{"name":"hibp_send_domain_verification_email","description":"Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access."}],"toolCount":17,"serverName":"hibp-mcp-server","capabilities":["resources","completions","prompts","tools"],"serverVersion":"0.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-08T09:25:59.852Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":55,"error":null,"detail":{"tools":[{"name":"hibp_list_breaches","description":"List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status."},{"name":"hibp_get_breach","description":"Look up a single public HIBP breach by its canonical breach name, such as Adobe."},{"name":"hibp_get_latest_breach","description":"Return the most recently added public breach currently loaded into HIBP."},{"name":"hibp_list_data_classes","description":"List the data classes used across public HIBP breach models, such as email addresses or passwords."},{"name":"hibp_get_pwned_passwords_range","description":"Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts."},{"name":"hibp_get_breached_account","description":"Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification"},{"name":"hibp_get_breached_account_range","description":"Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anony"},{"name":"hibp_get_paste_account","description":"Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from b"},{"name":"hibp_get_breached_domain","description":"Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token."},{"name":"hibp_list_subscribed_domains","description":"List the domains associated with the authenticated HIBP subscription."},{"name":"hibp_get_subscription_status","description":"Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use i"},{"name":"hibp_get_stealer_logs_by_email","description":"Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_website_domain","description":"Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_email_domain","description":"Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with"},{"name":"hibp_generate_domain_verification_dns_token","description":"Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request"},{"name":"hibp_verify_domain_verification_dns_token","description":"Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification acce"},{"name":"hibp_send_domain_verification_email","description":"Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access."}],"toolCount":17,"serverName":"hibp-mcp-server","capabilities":["resources","completions","prompts","tools"],"serverVersion":"0.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-08T02:22:00.097Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":22,"error":null,"detail":{"tools":[{"name":"hibp_list_breaches","description":"List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status."},{"name":"hibp_get_breach","description":"Look up a single public HIBP breach by its canonical breach name, such as Adobe."},{"name":"hibp_get_latest_breach","description":"Return the most recently added public breach currently loaded into HIBP."},{"name":"hibp_list_data_classes","description":"List the data classes used across public HIBP breach models, such as email addresses or passwords."},{"name":"hibp_get_pwned_passwords_range","description":"Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts."},{"name":"hibp_get_breached_account","description":"Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification"},{"name":"hibp_get_breached_account_range","description":"Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anony"},{"name":"hibp_get_paste_account","description":"Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from b"},{"name":"hibp_get_breached_domain","description":"Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token."},{"name":"hibp_list_subscribed_domains","description":"List the domains associated with the authenticated HIBP subscription."},{"name":"hibp_get_subscription_status","description":"Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use i"},{"name":"hibp_get_stealer_logs_by_email","description":"Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_website_domain","description":"Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_email_domain","description":"Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with"},{"name":"hibp_generate_domain_verification_dns_token","description":"Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request"},{"name":"hibp_verify_domain_verification_dns_token","description":"Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification acce"},{"name":"hibp_send_domain_verification_email","description":"Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access."}],"toolCount":17,"serverName":"hibp-mcp-server","capabilities":["resources","completions","prompts","tools"],"serverVersion":"0.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-07T19:21:19.446Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":117,"error":null,"detail":{"tools":[{"name":"hibp_list_breaches","description":"List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status."},{"name":"hibp_get_breach","description":"Look up a single public HIBP breach by its canonical breach name, such as Adobe."},{"name":"hibp_get_latest_breach","description":"Return the most recently added public breach currently loaded into HIBP."},{"name":"hibp_list_data_classes","description":"List the data classes used across public HIBP breach models, such as email addresses or passwords."},{"name":"hibp_get_pwned_passwords_range","description":"Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts."},{"name":"hibp_get_breached_account","description":"Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification"},{"name":"hibp_get_breached_account_range","description":"Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anony"},{"name":"hibp_get_paste_account","description":"Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from b"},{"name":"hibp_get_breached_domain","description":"Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token."},{"name":"hibp_list_subscribed_domains","description":"List the domains associated with the authenticated HIBP subscription."},{"name":"hibp_get_subscription_status","description":"Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use i"},{"name":"hibp_get_stealer_logs_by_email","description":"Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_website_domain","description":"Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_email_domain","description":"Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with"},{"name":"hibp_generate_domain_verification_dns_token","description":"Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request"},{"name":"hibp_verify_domain_verification_dns_token","description":"Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification acce"},{"name":"hibp_send_domain_verification_email","description":"Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access."}],"toolCount":17,"serverName":"hibp-mcp-server","capabilities":["resources","completions","prompts","tools"],"serverVersion":"0.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-07T12:25:03.271Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":66,"error":null,"detail":{"tools":[{"name":"hibp_list_breaches","description":"List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status."},{"name":"hibp_get_breach","description":"Look up a single public HIBP breach by its canonical breach name, such as Adobe."},{"name":"hibp_get_latest_breach","description":"Return the most recently added public breach currently loaded into HIBP."},{"name":"hibp_list_data_classes","description":"List the data classes used across public HIBP breach models, such as email addresses or passwords."},{"name":"hibp_get_pwned_passwords_range","description":"Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts."},{"name":"hibp_get_breached_account","description":"Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification"},{"name":"hibp_get_breached_account_range","description":"Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anony"},{"name":"hibp_get_paste_account","description":"Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from b"},{"name":"hibp_get_breached_domain","description":"Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token."},{"name":"hibp_list_subscribed_domains","description":"List the domains associated with the authenticated HIBP subscription."},{"name":"hibp_get_subscription_status","description":"Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use i"},{"name":"hibp_get_stealer_logs_by_email","description":"Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_website_domain","description":"Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_email_domain","description":"Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with"},{"name":"hibp_generate_domain_verification_dns_token","description":"Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request"},{"name":"hibp_verify_domain_verification_dns_token","description":"Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification acce"},{"name":"hibp_send_domain_verification_email","description":"Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access."}],"toolCount":17,"serverName":"hibp-mcp-server","capabilities":["resources","completions","prompts","tools"],"serverVersion":"0.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-07T05:23:20.193Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":57,"error":null,"detail":{"tools":[{"name":"hibp_list_breaches","description":"List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status."},{"name":"hibp_get_breach","description":"Look up a single public HIBP breach by its canonical breach name, such as Adobe."},{"name":"hibp_get_latest_breach","description":"Return the most recently added public breach currently loaded into HIBP."},{"name":"hibp_list_data_classes","description":"List the data classes used across public HIBP breach models, such as email addresses or passwords."},{"name":"hibp_get_pwned_passwords_range","description":"Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts."},{"name":"hibp_get_breached_account","description":"Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification"},{"name":"hibp_get_breached_account_range","description":"Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anony"},{"name":"hibp_get_paste_account","description":"Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from b"},{"name":"hibp_get_breached_domain","description":"Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token."},{"name":"hibp_list_subscribed_domains","description":"List the domains associated with the authenticated HIBP subscription."},{"name":"hibp_get_subscription_status","description":"Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use i"},{"name":"hibp_get_stealer_logs_by_email","description":"Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_website_domain","description":"Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_email_domain","description":"Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with"},{"name":"hibp_generate_domain_verification_dns_token","description":"Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request"},{"name":"hibp_verify_domain_verification_dns_token","description":"Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification acce"},{"name":"hibp_send_domain_verification_email","description":"Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access."}],"toolCount":17,"serverName":"hibp-mcp-server","capabilities":["resources","completions","prompts","tools"],"serverVersion":"0.0.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"hibp_list_breaches","description":"List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status."},{"name":"hibp_get_breach","description":"Look up a single public HIBP breach by its canonical breach name, such as Adobe."},{"name":"hibp_get_latest_breach","description":"Return the most recently added public breach currently loaded into HIBP."},{"name":"hibp_list_data_classes","description":"List the data classes used across public HIBP breach models, such as email addresses or passwords."},{"name":"hibp_get_pwned_passwords_range","description":"Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts."},{"name":"hibp_get_breached_account","description":"Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification"},{"name":"hibp_get_breached_account_range","description":"Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anony"},{"name":"hibp_get_paste_account","description":"Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from b"},{"name":"hibp_get_breached_domain","description":"Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token."},{"name":"hibp_list_subscribed_domains","description":"List the domains associated with the authenticated HIBP subscription."},{"name":"hibp_get_subscription_status","description":"Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use i"},{"name":"hibp_get_stealer_logs_by_email","description":"Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_website_domain","description":"Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; re"},{"name":"hibp_get_stealer_logs_by_email_domain","description":"Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with"},{"name":"hibp_generate_domain_verification_dns_token","description":"Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request"},{"name":"hibp_verify_domain_verification_dns_token","description":"Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification acce"},{"name":"hibp_send_domain_verification_email","description":"Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access."}],"package":null},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"io.github.troyhunt/hibp","url":"https://registry.modelcontextprotocol.io/v0/servers/io.github.troyhunt%2Fhibp","firstSeenAt":"2026-09-07T05:18:15.872Z","fetchedAt":"2026-09-07T05:18:15.872Z","normalizedAt":"2026-09-07T05:18:15.872Z"}]},"firstSeenAt":"2026-09-07T05:18:15.872Z","updatedAt":"2026-09-08T09:36:16.147Z"}