Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,070Paid calls: 1,524Letters: 13Defects: 1,322counted 3 min ago
teppi

MCP serverio.github.troyhunt/hibp

Breach intelligence API: email search, domain monitoring, passwords and stealer logs.
UNRATEDActivestreamable-httphaveibeenpwned.com

Overview

Score?
UNRATED 0.750
of what a free look can see, on 31 looks
Looks
35
last 13 hr ago
Tools
17

More info

URL
haveibeenpwned.com/mcp
streamable-http
Says it is
hibp-mcp-server 0.0.0
protocol 2025-06-18
In the record since
32 days ago

Among servers18,413 with a card

0median 0.606 · this server 0.750 · highest on record 0.8561

Toolsfrom sha256:e4200dec00…a44575

The tools this server lists, read out of the definition it returned
ToolSchema
hibp_generate_domain_verification_dns_token
Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request. Requires an authen
input · output
hibp_get_breach
Look up a single public HIBP breach by its canonical breach name, such as Adobe.
input · output
hibp_get_breached_account
Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification filters to refine t
input · output
hibp_get_breached_account_range
Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anonymity access; compare
input · output
hibp_get_breached_domain
Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.
input · output
hibp_get_latest_breach
Return the most recently added public breach currently loaded into HIBP.
input · output
hibp_get_paste_account
Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from breached-account look
input · output
hibp_get_pwned_passwords_range
Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.
input · output
hibp_get_stealer_logs_by_email
Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establi
input · output
hibp_get_stealer_logs_by_email_domain
Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with the stealer-log fea
input · output
hibp_get_stealer_logs_by_website_domain
Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establi
input · output
hibp_get_subscription_status
Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use it to confirm access
input · output
hibp_list_breaches
List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.
input · output
hibp_list_data_classes
List the data classes used across public HIBP breach models, such as email addresses or passwords.
input · output
hibp_list_subscribed_domains
List the domains associated with the authenticated HIBP subscription.
input · output
hibp_send_domain_verification_email
Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.
input · output
hibp_verify_domain_verification_dns_token
Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.
input · output
Verify it yourselfnpx teppi-check https://haveibeenpwned.com/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2NMPR8AAW8KFME4Z6XG0