Servidor MCP

Have I Been Pwned

io.github.troyhunt/hibp
Seguridad Público y accesible MCP 2025-11-25

Qué hace este MCP

Queries Have I Been Pwned breach, paste, password, domain, and stealer-log intelligence.

hibp_generate_domain_verification_dns_token
Have I Been Pwned - Generate Domain Verification DNS Token
Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request. Requires an authenticated subscription with domain-verification access.
Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'The domain to generate a verification token for.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'domain': {'type': 'string'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'txtRecordValue': {'type': 'string'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_breach
Have I Been Pwned - Breach
Look up a single public HIBP breach by its canonical breach name, such as Adobe.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'The breach name to retrieve, for example Adobe.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'breach': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_breached_account
Have I Been Pwned - Breached Account
Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification filters to refine the result.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['account'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'Filter results to a specific breach domain.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'account': {'type': 'string', 'description': 'The email address to search for.'}, 'responseMode': {'enum': ['full', 'truncated', 'names'], 'type': 'string', 'default': 'full', 'description': 'Choose full breach objects, truncated objects, or breach names.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}, 'includeUnverified': {'type': 'boolean', 'default': True, 'description': 'Include unverified breaches. Defaults to true.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'account': {'type': 'string'}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'breaches': {'type': 'array', 'items': {'anyOf': [{'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, {'type': 'object', 'required': ['Name'], 'properties': {'Name': {'type': 'string'}}, 'additionalProperties': {}}, {'type': 'string'}]}}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'responseMode': {'enum': ['full', 'truncated', 'names'], 'type': 'string'}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_breached_account_range
Have I Been Pwned - Breached Account Range
Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anonymity access; compare each returned suffix with the remaining hash characters locally because a prefix alone cannot identify an account.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['prefix'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'prefix': {'type': 'string', 'pattern': '^[0-9A-Fa-f]{6}$', 'description': 'The first 6 hexadecimal characters of the SHA-1 hash of an email address. Compare each returned suffix with the remaining 34 characters locally; a prefix alone does not identify an account.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'prefix': {'type': 'string'}, 'hasMore': {'type': 'boolean'}, 'matches': {'type': 'array', 'items': {'type': 'object', 'required': ['hashSuffix', 'websites'], 'properties': {'websites': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Non-sensitive breach names associated with the matching hash suffix.'}, 'hashSuffix': {'type': 'string', 'description': 'Remaining 34 SHA-1 hash characters to compare locally with the account hash.'}}, 'additionalProperties': False}}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'matchCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_breached_domain
Have I Been Pwned - Breached Domain
Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'The verified domain to search.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'domain': {'type': 'string'}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'aliasCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'breachesByAlias': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'array', 'items': {'type': 'string'}}}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_latest_breach
Have I Been Pwned - Latest Breach
Return the most recently added public breach currently loaded into HIBP.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'breach': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_paste_account
Have I Been Pwned - Paste Account
Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from breached-account lookup.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['account'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'account': {'type': 'string', 'description': 'The email address to search for pastes.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'pastes': {'type': 'array', 'items': {'type': 'object', 'required': ['Source', 'Id', 'EmailCount'], 'properties': {'Id': {'type': 'string'}, 'Date': {'type': ['string', 'null']}, 'Title': {'type': ['string', 'null']}, 'Source': {'type': 'string'}, 'EmailCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': {}}}, 'account': {'type': 'string'}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_pwned_passwords_range
Pwned Passwords Range Search
Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['prefix'], 'properties': {'mode': {'enum': ['sha1', 'ntlm'], 'type': 'string', 'default': 'sha1', 'description': 'Use SHA-1 by default or NTLM when mode is set to ntlm.'}, 'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'prefix': {'type': 'string', 'pattern': '^[0-9A-Fa-f]{5}$', 'description': 'The first 5 hexadecimal characters of a SHA-1 or NTLM hash.'}, 'addPadding': {'type': 'boolean', 'default': False, 'description': 'Send the Add-Padding header and discard padded zero-count entries.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'mode': {'enum': ['sha1', 'ntlm'], 'type': 'string'}, 'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'prefix': {'type': 'string'}, 'hasMore': {'type': 'boolean'}, 'matches': {'type': 'array', 'items': {'type': 'object', 'required': ['hashSuffix', 'count'], 'properties': {'count': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hashSuffix': {'type': 'string'}}, 'additionalProperties': False}}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'addPadding': {'type': 'boolean'}, 'matchCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_stealer_logs_by_email
Have I Been Pwned - Stealer Logs by Email
Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['email'], 'properties': {'email': {'type': 'string', 'description': 'The email address to search for in stealer logs.'}, 'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'email': {'type': 'string'}, 'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'domains': {'type': 'array', 'items': {'type': 'string'}}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_stealer_logs_by_email_domain
Have I Been Pwned - Stealer Logs by Email Domain
Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'The email domain to search for in stealer logs.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'domain': {'type': 'string'}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'aliases': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'array', 'items': {'type': 'string'}}}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'aliasCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_stealer_logs_by_website_domain
Have I Been Pwned - Stealer Logs by Website Domain
Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'The website domain to search for in stealer logs.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'domain': {'type': 'string'}, 'emails': {'type': 'array', 'items': {'type': 'string'}}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_subscription_status
Have I Been Pwned - Subscription Status
Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use it to confirm access before feature-dependent lookups.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'subscription': {'type': 'object', 'required': ['SubscriptionName', 'Description', 'SubscribedUntil', 'Rpm', 'DomainSearchMaxBreachedAccounts', 'MaxBreachedDomains', 'IncludesStealerLogs', 'IncludesBulkDomainAdd', 'IncludesAutoSubdomainVerification', 'IncludesCustomerDomains', 'IncludesKAnon', 'KAnonRpm'], 'properties': {'Rpm': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Maximum API requests per minute for the subscription.'}, 'KAnonRpm': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Maximum breached-account k-anonymity range lookups per minute, when included.'}, 'Description': {'type': 'string', 'description': 'Current HIBP API subscription plan description.'}, 'IncludesKAnon': {'type': 'boolean', 'description': 'Whether the subscription includes breached-account k-anonymity range lookups.'}, 'SubscribedUntil': {'type': 'string', 'description': 'UTC timestamp when the current subscription expires.'}, 'SubscriptionName': {'type': 'string', 'description': 'Current HIBP API subscription plan name.'}, 'MaxBreachedDomains': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Maximum verified domains allowed by the subscription, when applicable.'}, 'IncludesStealerLogs': {'type': 'boolean', 'description': 'Whether the subscription includes stealer-log lookups.'}, 'IncludesBulkDomainAdd': {'type': 'boolean', 'description': 'Whether the subscription includes bulk domain addition.'}, 'IncludesCustomerDomains': {'type': 'boolean', 'description': 'Whether the subscription includes customer-domain support.'}, 'DomainSearchMaxBreachedAccounts': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Maximum breached accounts returned by a domain search, when applicable.'}, 'IncludesAutoSubdomainVerification': {'type': 'boolean', 'description': 'Whether the subscription includes automatic subdomain verification.'}}, 'additionalProperties': False}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_list_breaches
Have I Been Pwned - Breaches
List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'Filter to breaches for a specific domain.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'isSpamList': {'type': 'boolean', 'description': 'Filter to breaches that are or are not flagged as spam lists.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}, 'includeUnverified': {'type': 'boolean', 'default': True, 'description': 'Include unverified breaches. Defaults to true.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'breaches': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_list_data_classes
Have I Been Pwned - Data Classes
List the data classes used across public HIBP breach models, such as email addresses or passwords.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'dataClasses': {'type': 'array', 'items': {'type': 'string'}}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_list_subscribed_domains
Have I Been Pwned - Subscribed Domains
List the domains associated with the authenticated HIBP subscription.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}, 'subscribedDomains': {'type': 'array', 'items': {'type': 'object', 'required': ['DomainName', 'PwnCount', 'PwnCountExcludingSpamLists', 'PwnCountExcludingSpamListsAtLastSubscriptionRenewal', 'NextSubscriptionRenewal'], 'properties': {'PwnCount': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}, 'DomainName': {'type': 'string'}, 'NextSubscriptionRenewal': {'type': ['string', 'null']}, 'PwnCountExcludingSpamLists': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}, 'PwnCountExcludingSpamListsAtLastSubscriptionRenewal': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}}, 'additionalProperties': False}}}, 'additionalProperties': False}
hibp_send_domain_verification_email
Have I Been Pwned - Send Domain Verification Email
Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.
Acceso externo
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain', 'emailAlias'], 'properties': {'domain': {'type': 'string', 'description': 'The domain to verify by email.'}, 'emailAlias': {'type': 'string', 'description': 'The approval alias to send the verification email to, for example admin.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'domain': {'type': 'string'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'emailSent': {'type': 'boolean'}, 'emailAlias': {'type': 'string'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_verify_domain_verification_dns_token
Have I Been Pwned - Verify Domain Verification DNS Token
Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.
Acceso externo Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'The domain to verify by DNS.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'domain': {'type': 'string'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'verified': {'type': 'boolean'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
Modificado
hibp_send_domain_verification_email
23 de September de 2026 a las 02:50
Modificado
hibp_verify_domain_verification_dns_token
23 de September de 2026 a las 02:50
Modificado
hibp_generate_domain_verification_dns_token
23 de September de 2026 a las 02:50
Añadido
hibp_send_domain_verification_email
17 de September de 2026 a las 12:52
Añadido
hibp_verify_domain_verification_dns_token
17 de September de 2026 a las 12:52
Añadido
hibp_generate_domain_verification_dns_token
17 de September de 2026 a las 12:52
Añadido
hibp_get_stealer_logs_by_email_domain
17 de September de 2026 a las 12:52
Añadido
hibp_get_stealer_logs_by_website_domain
17 de September de 2026 a las 12:52
Añadido
hibp_get_stealer_logs_by_email
17 de September de 2026 a las 12:52
Añadido
hibp_get_subscription_status
17 de September de 2026 a las 12:52
Añadido
hibp_list_subscribed_domains
17 de September de 2026 a las 12:52
Añadido
hibp_get_breached_domain
17 de September de 2026 a las 12:52
Añadido
hibp_get_paste_account
17 de September de 2026 a las 12:52
Añadido
hibp_get_breached_account_range
17 de September de 2026 a las 12:52
Añadido
hibp_get_breached_account
17 de September de 2026 a las 12:52
Añadido
hibp_get_pwned_passwords_range
17 de September de 2026 a las 12:52
Añadido
hibp_list_data_classes
17 de September de 2026 a las 12:52
Añadido
hibp_get_latest_breach
17 de September de 2026 a las 12:52
Añadido
hibp_get_breach
17 de September de 2026 a las 12:52
Añadido
hibp_list_breaches
17 de September de 2026 a las 12:52