MCP 服务器

Have I Been Pwned

io.github.troyhunt/hibp
安全 公开且可连接 MCP 2025-11-25

此 MCP 可以做什么

Queries Have I Been Pwned breach, paste, password, domain, and stealer-log intelligence.

hibp_generate_domain_verification_dns_token
Have I Been Pwned - Generate Domain Verification DNS Token
Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request. Requires an authenticated subscription with domain-verification access.
幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'The domain to generate a verification token for.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'domain': {'type': 'string'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'txtRecordValue': {'type': 'string'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_breach
Have I Been Pwned - Breach
Look up a single public HIBP breach by its canonical breach name, such as Adobe.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'The breach name to retrieve, for example Adobe.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'breach': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_breached_account
Have I Been Pwned - Breached Account
Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification filters to refine the result.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['account'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'Filter results to a specific breach domain.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'account': {'type': 'string', 'description': 'The email address to search for.'}, 'responseMode': {'enum': ['full', 'truncated', 'names'], 'type': 'string', 'default': 'full', 'description': 'Choose full breach objects, truncated objects, or breach names.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}, 'includeUnverified': {'type': 'boolean', 'default': True, 'description': 'Include unverified breaches. Defaults to true.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'account': {'type': 'string'}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'breaches': {'type': 'array', 'items': {'anyOf': [{'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, {'type': 'object', 'required': ['Name'], 'properties': {'Name': {'type': 'string'}}, 'additionalProperties': {}}, {'type': 'string'}]}}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'responseMode': {'enum': ['full', 'truncated', 'names'], 'type': 'string'}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_breached_account_range
Have I Been Pwned - Breached Account Range
Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anonymity access; compare each returned suffix with the remaining hash characters locally because a prefix alone cannot identify an account.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['prefix'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'prefix': {'type': 'string', 'pattern': '^[0-9A-Fa-f]{6}$', 'description': 'The first 6 hexadecimal characters of the SHA-1 hash of an email address. Compare each returned suffix with the remaining 34 characters locally; a prefix alone does not identify an account.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'prefix': {'type': 'string'}, 'hasMore': {'type': 'boolean'}, 'matches': {'type': 'array', 'items': {'type': 'object', 'required': ['hashSuffix', 'websites'], 'properties': {'websites': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Non-sensitive breach names associated with the matching hash suffix.'}, 'hashSuffix': {'type': 'string', 'description': 'Remaining 34 SHA-1 hash characters to compare locally with the account hash.'}}, 'additionalProperties': False}}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'matchCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_breached_domain
Have I Been Pwned - Breached Domain
Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'The verified domain to search.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'domain': {'type': 'string'}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'aliasCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'breachesByAlias': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'array', 'items': {'type': 'string'}}}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_latest_breach
Have I Been Pwned - Latest Breach
Return the most recently added public breach currently loaded into HIBP.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'breach': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_paste_account
Have I Been Pwned - Paste Account
Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from breached-account lookup.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['account'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'account': {'type': 'string', 'description': 'The email address to search for pastes.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'pastes': {'type': 'array', 'items': {'type': 'object', 'required': ['Source', 'Id', 'EmailCount'], 'properties': {'Id': {'type': 'string'}, 'Date': {'type': ['string', 'null']}, 'Title': {'type': ['string', 'null']}, 'Source': {'type': 'string'}, 'EmailCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}, 'additionalProperties': {}}}, 'account': {'type': 'string'}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_pwned_passwords_range
Pwned Passwords Range Search
Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['prefix'], 'properties': {'mode': {'enum': ['sha1', 'ntlm'], 'type': 'string', 'default': 'sha1', 'description': 'Use SHA-1 by default or NTLM when mode is set to ntlm.'}, 'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'prefix': {'type': 'string', 'pattern': '^[0-9A-Fa-f]{5}$', 'description': 'The first 5 hexadecimal characters of a SHA-1 or NTLM hash.'}, 'addPadding': {'type': 'boolean', 'default': False, 'description': 'Send the Add-Padding header and discard padded zero-count entries.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'mode': {'enum': ['sha1', 'ntlm'], 'type': 'string'}, 'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'prefix': {'type': 'string'}, 'hasMore': {'type': 'boolean'}, 'matches': {'type': 'array', 'items': {'type': 'object', 'required': ['hashSuffix', 'count'], 'properties': {'count': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hashSuffix': {'type': 'string'}}, 'additionalProperties': False}}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'addPadding': {'type': 'boolean'}, 'matchCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_stealer_logs_by_email
Have I Been Pwned - Stealer Logs by Email
Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['email'], 'properties': {'email': {'type': 'string', 'description': 'The email address to search for in stealer logs.'}, 'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'email': {'type': 'string'}, 'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'domains': {'type': 'array', 'items': {'type': 'string'}}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_stealer_logs_by_email_domain
Have I Been Pwned - Stealer Logs by Email Domain
Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'The email domain to search for in stealer logs.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'domain': {'type': 'string'}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'aliases': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'array', 'items': {'type': 'string'}}}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'aliasCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_stealer_logs_by_website_domain
Have I Been Pwned - Stealer Logs by Website Domain
Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'The website domain to search for in stealer logs.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'domain': {'type': 'string'}, 'emails': {'type': 'array', 'items': {'type': 'string'}}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_get_subscription_status
Have I Been Pwned - Subscription Status
Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use it to confirm access before feature-dependent lookups.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'subscription': {'type': 'object', 'required': ['SubscriptionName', 'Description', 'SubscribedUntil', 'Rpm', 'DomainSearchMaxBreachedAccounts', 'MaxBreachedDomains', 'IncludesStealerLogs', 'IncludesBulkDomainAdd', 'IncludesAutoSubdomainVerification', 'IncludesCustomerDomains', 'IncludesKAnon', 'KAnonRpm'], 'properties': {'Rpm': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Maximum API requests per minute for the subscription.'}, 'KAnonRpm': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Maximum breached-account k-anonymity range lookups per minute, when included.'}, 'Description': {'type': 'string', 'description': 'Current HIBP API subscription plan description.'}, 'IncludesKAnon': {'type': 'boolean', 'description': 'Whether the subscription includes breached-account k-anonymity range lookups.'}, 'SubscribedUntil': {'type': 'string', 'description': 'UTC timestamp when the current subscription expires.'}, 'SubscriptionName': {'type': 'string', 'description': 'Current HIBP API subscription plan name.'}, 'MaxBreachedDomains': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Maximum verified domains allowed by the subscription, when applicable.'}, 'IncludesStealerLogs': {'type': 'boolean', 'description': 'Whether the subscription includes stealer-log lookups.'}, 'IncludesBulkDomainAdd': {'type': 'boolean', 'description': 'Whether the subscription includes bulk domain addition.'}, 'IncludesCustomerDomains': {'type': 'boolean', 'description': 'Whether the subscription includes customer-domain support.'}, 'DomainSearchMaxBreachedAccounts': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Maximum breached accounts returned by a domain search, when applicable.'}, 'IncludesAutoSubdomainVerification': {'type': 'boolean', 'description': 'Whether the subscription includes automatic subdomain verification.'}}, 'additionalProperties': False}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_list_breaches
Have I Been Pwned - Breaches
List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'domain': {'type': 'string', 'description': 'Filter to breaches for a specific domain.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'isSpamList': {'type': 'boolean', 'description': 'Filter to breaches that are or are not flagged as spam lists.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}, 'includeUnverified': {'type': 'boolean', 'default': True, 'description': 'Include unverified breaches. Defaults to true.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'breaches': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_list_data_classes
Have I Been Pwned - Data Classes
List the data classes used across public HIBP breach models, such as email addresses or passwords.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'dataClasses': {'type': 'array', 'items': {'type': 'string'}}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_list_subscribed_domains
Have I Been Pwned - Subscribed Domains
List the domains associated with the authenticated HIBP subscription.
只读 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of items to include in the response. Defaults to 25.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Number of items to skip before returning results. Defaults to 0.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'hasMore': {'type': 'boolean'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'nextOffset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'returnedCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}, 'subscribedDomains': {'type': 'array', 'items': {'type': 'object', 'required': ['DomainName', 'PwnCount', 'PwnCountExcludingSpamLists', 'PwnCountExcludingSpamListsAtLastSubscriptionRenewal', 'NextSubscriptionRenewal'], 'properties': {'PwnCount': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}, 'DomainName': {'type': 'string'}, 'NextSubscriptionRenewal': {'type': ['string', 'null']}, 'PwnCountExcludingSpamLists': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}, 'PwnCountExcludingSpamListsAtLastSubscriptionRenewal': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}}, 'additionalProperties': False}}}, 'additionalProperties': False}
hibp_send_domain_verification_email
Have I Been Pwned - Send Domain Verification Email
Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.
可访问外部资源
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain', 'emailAlias'], 'properties': {'domain': {'type': 'string', 'description': 'The domain to verify by email.'}, 'emailAlias': {'type': 'string', 'description': 'The approval alias to send the verification email to, for example admin.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'domain': {'type': 'string'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'emailSent': {'type': 'boolean'}, 'emailAlias': {'type': 'string'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
hibp_verify_domain_verification_dns_token
Have I Been Pwned - Verify Domain Verification DNS Token
Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.
可访问外部资源 幂等
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'The domain to verify by DNS.'}, 'response_format': {'enum': ['markdown', 'json'], 'type': 'string', 'default': 'markdown', 'description': 'Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'domain': {'type': 'string'}, 'message': {'type': 'string', 'description': 'Present when the tool returns an error.'}, 'guidance': {'type': 'string', 'description': 'Additional guidance for resolving the tool error.'}, 'verified': {'type': 'boolean'}, 'statusCode': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Present when the tool returns an error.'}, 'rateLimitResetAt': {'type': 'string', 'description': 'UTC timestamp indicating when the current rate limit window should have reset.'}, 'retryAfterHeaders': {'type': 'object', 'description': 'Retry headers that mirror the standard HTTP rate-limit response when applicable.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}, 'retryAfterSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How long to wait before retrying, when the tool is rate limited.'}}, 'additionalProperties': False}
已更改
hibp_send_domain_verification_email
2026年9月23日 02:50
已更改
hibp_verify_domain_verification_dns_token
2026年9月23日 02:50
已更改
hibp_generate_domain_verification_dns_token
2026年9月23日 02:50
已添加
hibp_send_domain_verification_email
2026年9月17日 12:52
已添加
hibp_verify_domain_verification_dns_token
2026年9月17日 12:52
已添加
hibp_generate_domain_verification_dns_token
2026年9月17日 12:52
已添加
hibp_get_stealer_logs_by_email_domain
2026年9月17日 12:52
已添加
hibp_get_stealer_logs_by_website_domain
2026年9月17日 12:52
已添加
hibp_get_stealer_logs_by_email
2026年9月17日 12:52
已添加
hibp_get_subscription_status
2026年9月17日 12:52
已添加
hibp_list_subscribed_domains
2026年9月17日 12:52
已添加
hibp_get_breached_domain
2026年9月17日 12:52
已添加
hibp_get_paste_account
2026年9月17日 12:52
已添加
hibp_get_breached_account_range
2026年9月17日 12:52
已添加
hibp_get_breached_account
2026年9月17日 12:52
已添加
hibp_get_pwned_passwords_range
2026年9月17日 12:52
已添加
hibp_list_data_classes
2026年9月17日 12:52
已添加
hibp_get_latest_breach
2026年9月17日 12:52
已添加
hibp_get_breach
2026年9月17日 12:52
已添加
hibp_list_breaches
2026年9月17日 12:52