Security — entry 016 of 30
HaveIBeenPwned
HaveIBeenPwned aggregates hundreds of data breaches and public paste dumps so anyone can check whether an email address, domain, or password has been exposed. Pwned Passwords answers password checks anonymously via a k-anonymity hash-range query and needs no key, while the breach- and paste-search endpoints sit behind a paid subscription API key. Troy Hunt's service has become a de facto industry check, feeding into browsers, password managers, and countless other security tools.
AuthenticationAPI KeySign up with the provider to obtain credentials.
HTTPSSupportedTraffic is encrypted in transit.
CORSEnabledCallable directly from browser JavaScript.
PricingFreemiumA usable free tier exists, with paid plans for more volume.
FormatsJSONResponses can be requested as JSON.
GreatAPIs Score
Score61
Authentication15/25API key required
Pricing17/20Freemium tier available
Docs0/20No docs or spec available
Formats9/15Single response format
Freshness20/20Verified within 6 months
Auth quickstart
- Sign up with the provider to get an API key.
- Send it on every request as a header
Authorization: <key> - The exact header isn't documented — Authorization is a common default; confirm in the provider's docs.
Stored keyNo key stored
Your key is stored only in this browser (localStorage) and sent directly to the API — never to greatapis.