# Have I Been Pwned API

> Have I Been Pwned returns recorded data breach details as a workflow and API.

Have I Been Pwned (HIBP) searches recorded breaches by company or website name, matching breach titles and website domains. Search breaches takes a company or website name and can take a maximum number of results; it returns matches ordered newest first.

- Page: https://fous.com/tools/have-i-been-pwned
- Handle: `@have-i-been-pwned`
- Category: [Security](https://fous.com/tools/category/security)
- Source website: https://haveibeenpwned.com
- Last verified: Sep 29, 2026

## Methods

### Search breaches

Operation `search_breaches`, version 1. 1 credit per completed call. Failed calls without a completed billing receipt are free; completed work can remain charged if delivery is interrupted.

Find recorded data breaches by company or website name, matching breach titles and website domains. Results are ordered by breach date, newest first; email-address checks are not included.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `company` | string | yes | `"Adobe"` | Company or website to search for, for example Adobe or adobe.com. |
| `max_results` | integer | no | `1` | Most breaches to return, for example 20 (maximum 100). |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "company"
  ],
  "properties": {
    "company": {
      "type": "string",
      "minLength": 1,
      "description": "Company or website to search for, for example Adobe or adobe.com.",
      "examples": [
        "Adobe",
        "adobe.com",
        "nonexistentcompanyxyz987654"
      ]
    },
    "max_results": {
      "type": "integer",
      "default": 20,
      "maximum": 100,
      "minimum": 1,
      "description": "Most breaches to return, for example 20 (maximum 100).",
      "x-fous-developer": true,
      "examples": [
        1,
        2
      ]
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "company": "Adobe"
    },
    {
      "company": "adobe.com",
      "max_results": 1
    },
    {
      "company": "nonexistentcompanyxyz987654"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `breaches` | array |  | Matching breaches, newest first. |
| `breaches[].website` | string or null | `"adobe.com"` | Affected website domain. |
| `breaches[].verified` | string | `"yes"` | Whether the breach was verified. |
| `breaches[].date_added` | string or null | `"2013-12-04"` | Date the breach was added. |
| `breaches[].breach_date` | string or null | `"2013-10-04"` | Date of the breach. |
| `breaches[].breach_name` | string | `"Adobe"` | Name of the breach. |
| `breaches[].description` | string | `"In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypt` | Plain-text summary of the breach. |
| `breaches[].data_exposed` | string | `"Email addresses, Password hints, Passwords, Usernames"` | Kinds of personal data exposed. |
| `breaches[].breach_page_link` | string | `"https://haveibeenpwned.com/Breach/Adobe"` | Breach page on Have I Been Pwned. |
| `breaches[].accounts_affected` | integer or null | `152445165` | Number of accounts affected. |

**Example input**

```json
{
  "company": "Adobe"
}
```

**Example output**

```json
{
  "breaches": [
    {
      "website": "adobe.com",
      "verified": "yes",
      "date_added": "2013-12-04",
      "breach_date": "2013-10-04",
      "breach_name": "Adobe",
      "description": "In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypted password and a password hint in plain text. The password cryptography was poor…",
      "data_exposed": "Email addresses, Password hints, Passwords, Usernames",
      "breach_page_link": "https://haveibeenpwned.com/Breach/Adobe",
      "accounts_affected": 152445165
    }
  ]
}
```

## Quick start

Replace `YOUR_API_KEY` with a Fous API key. To create one, open Developers at the bottom of Fous Studio, turn on Developer mode, then go to API keys (https://app.fous.com/keys). Change the values in `input` to run the same tool on new data.

```bash
curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 180 \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@have-i-been-pwned",
  "visibility": "public",
  "operation": "search_breaches",
  "version": 1,
  "input": {
    "company": "Adobe"
  },
  "response": {
    "format": "json"
  }
}'
```

```python
# Save as fous.py and run with python3 fous.py. No packages needed.
import json
import urllib.error
import urllib.request

api_key = "YOUR_API_KEY"

body = json.loads("{\n  \"api\": \"@have-i-been-pwned\",\n  \"visibility\": \"public\",\n  \"operation\": \"search_breaches\",\n  \"version\": 1,\n  \"input\": {\n    \"company\": \"Adobe\"\n  },\n  \"response\": {\n    \"format\": \"json\"\n  }\n}")
request = urllib.request.Request(
    "https://api.fous.com/v1/query",
    data=json.dumps(body).encode("utf-8"),
    headers={
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json",
    },
    method="POST",
)
try:
    with urllib.request.urlopen(request, timeout=180) as response:
        result = json.load(response)
except urllib.error.HTTPError as error:
    raise RuntimeError(f"HTTP {error.code}: {error.read().decode('utf-8', errors='replace')}") from error
if result.get("success") is False:
    raise RuntimeError(result.get("error", {}).get("message", "Request failed"))
print(json.dumps(result["data"]["output"], indent=2))
```

```typescript
// Save as fous.mts and run with npx tsx fous.mts.
const apiKey = "YOUR_API_KEY";

const response = await fetch("https://api.fous.com/v1/query", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${apiKey}`,
    "Content-Type": "application/json",
  },
  signal: AbortSignal.timeout(180_000),
  body: JSON.stringify({
  "api": "@have-i-been-pwned",
  "visibility": "public",
  "operation": "search_breaches",
  "version": 1,
  "input": {
    "company": "Adobe"
  },
  "response": {
    "format": "json"
  }
}),
});
type ApiResult = { success: boolean; data?: { output: unknown }; error?: { message: string } };
const result: ApiResult = await response.json();
if (!response.ok || result.success === false) {
  throw new Error(result.error?.message ?? `HTTP ${response.status}`);
}
if (!result.data) throw new Error("Missing API response data");
console.log(result.data.output);
```

## Use from an AI assistant

Connect this tool to Claude Code, Claude Desktop, Cursor, VS Code, Codex and any MCP client as its own MCP server. Each method is a typed tool whose arguments are the method’s input.

- Server URL: `https://api.fous.com/mcp/tools/have-i-been-pwned`
- Authorization: `Authorization: Bearer <Fous API key>`

**Tools**

- `search_breaches`: Search breaches. 1 credit per completed call. Failed calls without a completed billing receipt are free; completed work can remain charged if delivery is interrupted.
- `fous_get_run`: the result of a run that was still going, by its `request_id`. Free.

Claude Code:

```bash
claude mcp add --scope user --transport http fous-have-i-been-pwned https://api.fous.com/mcp/tools/have-i-been-pwned --header "Authorization: Bearer ${FOUS_API_KEY:?Set FOUS_API_KEY to your Fous API key}"
```

To give the assistant every tool, connect `https://api.fous.com/mcp`: it finds one with `fous_search_tools` and runs it with `fous_run_tool`. Setup for other clients: https://fous.com/llms-full.txt.

## Use cases

- Find recorded breaches associated with a company or website.
- Review breach dates and affected website domains.
- See what kinds of personal data a breach exposed.
- Check whether a breach was verified.
- Compare the number of accounts affected by matching breaches.

## FAQ

### Can I run it with my own inputs?

Yes. Change the inputs in Studio and press Run, or send new inputs from your code, or ask a connected AI assistant.

### Can I call this Have I Been Pwned tool as an API?

Yes. Send a POST request to /v1/query with your Fous API key and the inputs, and get JSON back.

### How much does it cost?

Each completed run costs 1 credit. Failed runs without a completed receipt are free; completed work can remain charged if delivery is interrupted. With pay as you go, a credit costs 1¢. Monthly plans cost less per credit.

### Do I need a Have I Been Pwned account?

No. You only need a Fous account.

### How current is the data?

Fous gets the data from haveibeenpwned.com when you run it. Some results are reused for up to 24 hours, and results that use your account or key are never reused. It was last verified on Sep 29, 2026.

### Which breaches are associated with a company or website?

Search breaches finds recorded breaches matching the company or website name and returns them newest first.

### What personal data did a breach expose?

Search breaches returns the kinds of personal data exposed for each matching breach.

### How many accounts were affected by a breach?

Search breaches returns the number of accounts affected for each matching breach.

## Related

- [National Vulnerability Database API](https://fous.com/tools/national-vulnerability-database.md): The U.S. National Vulnerability Database provides publicly reported security vulnerabilities, with recent product matches and CVE details, including CISA catalog status and affected versions when reported.
- [Trustpilot API](https://fous.com/tools/trustpilot.md): Trustpilot provides company ratings, reply and location details when available, recent public reviews, and company search results with ratings, review counts, categories, locations, and links.
- [Companies House API](https://fous.com/tools/companies-house.md): Companies House returns UK public-register company details, officers, people with significant control and recent filings; records may be incomplete, and ceased entries are optional.
- [ICANN Lookup API](https://fous.com/tools/icann-lookup.md): Public domain registration lookup using ICANN registration data.
- [BuiltWith API](https://fous.com/tools/builtwith.md): Discover technologies used by websites.
- [OSHA API](https://fous.com/tools/osha.md): Public workplace safety inspection and enforcement records.
- [ABN Lookup API](https://fous.com/tools/abn-lookup.md): Search Australian businesses by name or ABN and check public registration details.
- [crt.sh API](https://fous.com/tools/crt-sh.md): Public certificate transparency search for issued certificates and names they cover.
- [All Security tools](https://fous.com/tools/category/security)
