Security — entry 016 of 30

HaveIBeenPwned

Verified Jul 2026

HaveIBeenPwned aggregates hundreds of data breaches and public paste dumps so anyone can check whether an email address, domain, or password has been exposed. Pwned Passwords answers password checks anonymously via a k-anonymity hash-range query and needs no key, while the breach- and paste-search endpoints sit behind a paid subscription API key. Troy Hunt's service has become a de facto industry check, feeding into browsers, password managers, and countless other security tools.

breach-lookuppassword-securityemail-securitythreat-intelligence
AuthenticationAPI KeySign up with the provider to obtain credentials.
HTTPSSupportedTraffic is encrypted in transit.
CORSEnabledCallable directly from browser JavaScript.
PricingFreemiumA usable free tier exists, with paid plans for more volume.
FormatsJSONResponses can be requested as JSON.

GreatAPIs Score

Score61out of 100
Authentication15/25API key required
Pricing17/20Freemium tier available
Docs0/20No docs or spec available
Formats9/15Single response format
Freshness20/20Verified within 6 months

Embed this badge

Scored 61 on greatapis.com
<a href="https://greatapis.com/api/haveibeenpwned/"><img src="https://greatapis.com/badge/haveibeenpwned.svg" alt="Scored 61 on greatapis.com"></a>

Auth quickstart

  1. Sign up with the provider to get an API key.
  2. Send it on every request as a headerAuthorization: <key>
  3. The exact header isn't documented — Authorization is a common default; confirm in the provider's docs.
Stored keyNo key stored

Your key is stored only in this browser (localStorage) and sent directly to the API — never to greatapis.