# Have I Been Pwned API

> Have I Been Pwned returns recorded data breach details as a workflow and API.

Have I Been Pwned (HIBP) searches recorded breaches by company or website name, matching breach titles and website domains. Search breaches takes a company or website name and can take a maximum number of results; it returns matches ordered newest first.

- Page: https://fous.com/workflows/have-i-been-pwned
- Handle: `@have-i-been-pwned`
- Category: [Security](https://fous.com/workflows/category/security)
- Source website: https://haveibeenpwned.com
- Last verified: Sep 29, 2026
- Fous is not affiliated with Have I Been Pwned.

## Methods

### Search breaches

Operation `search_breaches`, version 1. 1 credit per call.

Find recorded data breaches by company or website name, matching breach titles and website domains. Results are ordered by breach date, newest first; email-address checks are not included.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `company` | string | yes | `"Adobe"` | Company or website to search for, for example Adobe or adobe.com. |
| `max_results` | integer | no | `1` | Most breaches to return, for example 20 (maximum 100). |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "company"
  ],
  "properties": {
    "company": {
      "type": "string",
      "minLength": 1,
      "description": "Company or website to search for, for example Adobe or adobe.com.",
      "examples": [
        "Adobe",
        "adobe.com",
        "nonexistentcompanyxyz987654"
      ]
    },
    "max_results": {
      "type": "integer",
      "default": 20,
      "maximum": 100,
      "minimum": 1,
      "description": "Most breaches to return, for example 20 (maximum 100).",
      "x-fous-developer": true,
      "examples": [
        1,
        2
      ]
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "company": "Adobe"
    },
    {
      "company": "adobe.com",
      "max_results": 1
    },
    {
      "company": "nonexistentcompanyxyz987654"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `breaches` | array |  | Matching breaches, newest first. |
| `breaches[].website` | string or null | `"adobe.com"` | Affected website domain. |
| `breaches[].verified` | string | `"yes"` | Whether the breach was verified. |
| `breaches[].date_added` | string or null | `"2013-12-04"` | Date the breach was added. |
| `breaches[].breach_date` | string or null | `"2013-10-04"` | Date of the breach. |
| `breaches[].breach_name` | string | `"Adobe"` | Name of the breach. |
| `breaches[].description` | string | `"In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypt` | Plain-text summary of the breach. |
| `breaches[].data_exposed` | string | `"Email addresses, Password hints, Passwords, Usernames"` | Kinds of personal data exposed. |
| `breaches[].breach_page_link` | string | `"https://haveibeenpwned.com/Breach/Adobe"` | Breach page on Have I Been Pwned. |
| `breaches[].accounts_affected` | integer or null | `152445165` | Number of accounts affected. |

**Example input**

```json
{
  "company": "Adobe"
}
```

**Example output**

```json
{
  "breaches": [
    {
      "website": "adobe.com",
      "verified": "yes",
      "date_added": "2013-12-04",
      "breach_date": "2013-10-04",
      "breach_name": "Adobe",
      "description": "In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypted password and a password hint in plain text. The password cryptography was poor…",
      "data_exposed": "Email addresses, Password hints, Passwords, Usernames",
      "breach_page_link": "https://haveibeenpwned.com/Breach/Adobe",
      "accounts_affected": 152445165
    }
  ]
}
```

## Quick start

Call the API with a Fous API key (`FOUS_API_KEY`). To create one, turn on Developer mode in Fous Studio, then open Keys & connections → API keys (https://app.fous.com/keys).

```bash
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
: "${FOUS_API_KEY:?Set FOUS_API_KEY before running this example}"

curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 120 \
  -H "Authorization: Bearer $FOUS_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@have-i-been-pwned",
  "visibility": "public",
  "operation": "search_breaches",
  "version": 1,
  "input": {
    "company": "Adobe"
  },
  "response": {
    "format": "json"
  }
}'
```

```python
# Save as fous.py and run with python3 fous.py. No packages needed.
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
import json
import os
import urllib.error
import urllib.request

api_key = os.environ.get("FOUS_API_KEY")
if not api_key:
    raise RuntimeError("Set FOUS_API_KEY before running this example")

body = json.loads("{\n  \"api\": \"@have-i-been-pwned\",\n  \"visibility\": \"public\",\n  \"operation\": \"search_breaches\",\n  \"version\": 1,\n  \"input\": {\n    \"company\": \"Adobe\"\n  },\n  \"response\": {\n    \"format\": \"json\"\n  }\n}")
request = urllib.request.Request(
    "https://api.fous.com/v1/query",
    data=json.dumps(body).encode("utf-8"),
    headers={
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json",
    },
    method="POST",
)
try:
    with urllib.request.urlopen(request, timeout=120) as response:
        result = json.load(response)
except urllib.error.HTTPError as error:
    raise RuntimeError(f"HTTP {error.code}: {error.read().decode('utf-8', errors='replace')}") from error
if result.get("success") is False:
    raise RuntimeError(result.get("error", {}).get("message", "Request failed"))
print(json.dumps(result["data"]["output"], indent=2))
```

```typescript
// Save as fous.mts and run with npx tsx fous.mts.
// First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
const apiKey = process.env.FOUS_API_KEY;
if (!apiKey) throw new Error("Set FOUS_API_KEY before running this example");

const response = await fetch("https://api.fous.com/v1/query", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${apiKey}`,
    "Content-Type": "application/json",
  },
  signal: AbortSignal.timeout(120_000),
  body: JSON.stringify({
  "api": "@have-i-been-pwned",
  "visibility": "public",
  "operation": "search_breaches",
  "version": 1,
  "input": {
    "company": "Adobe"
  },
  "response": {
    "format": "json"
  }
}),
});
type ApiResult = { success: boolean; data?: { output: unknown }; error?: { message: string } };
const result: ApiResult = await response.json();
if (!response.ok || result.success === false) {
  throw new Error(result.error?.message ?? `HTTP ${response.status}`);
}
if (!result.data) throw new Error("Missing API response data");
console.log(result.data.output);
```

Or describe the data in plain language: send `{"api":"@have-i-been-pwned","prompt":"Describe the data you need, with every detail"}` to the same URL. Fous fills in the input, runs the method that fits and returns only the fields you asked for; `data.route.calls[].request` is the exact call it made. Routing is free; the run costs the same.

## Use cases

- Find recorded breaches associated with a company or website.
- Review breach dates and affected website domains.
- See what kinds of personal data a breach exposed.
- Check whether a breach was verified.
- Compare the number of accounts affected by matching breaches.

## FAQ

### Is Fous affiliated with Have I Been Pwned?

No. Fous is not affiliated with Have I Been Pwned. This workflow reads the public haveibeenpwned.com website and returns its data.

### How much does it cost?

Each run costs 1 credit. With pay-as-you-go, a credit costs 1¢; monthly plans cost less per credit.

### Do I need a Have I Been Pwned account?

No. You only need a Fous account.

### How current is the data?

Fous gets the data from haveibeenpwned.com when you run it; repeating the same request within a day may return the saved result. Fous checks this workflow automatically; it last passed a check on Sep 29, 2026.

### Which breaches are associated with a company or website?

Search breaches finds recorded breaches matching the company or website name and returns them newest first.

### What personal data did a breach expose?

Search breaches returns the kinds of personal data exposed for each matching breach.

### How many accounts were affected by a breach?

Search breaches returns the number of accounts affected for each matching breach.

## Related

- [National Vulnerability Database API](https://fous.com/workflows/national-vulnerability-database.md): The U.S. National Vulnerability Database provides publicly reported security vulnerabilities, with recent product matches and CVE details, including CISA catalog status and affected versions when reported.
- [Trustpilot API](https://fous.com/workflows/trustpilot.md): Trustpilot provides company ratings, reply and location details when available, recent public reviews, and company search results with ratings, review counts, categories, locations, and links.
- [Companies House API](https://fous.com/workflows/companies-house.md): Companies House returns UK public-register company details, officers, people with significant control and recent filings; records may be incomplete, and ceased entries are optional.
- [ICANN Lookup API](https://fous.com/workflows/icann-lookup.md): Public domain registration lookup using ICANN registration data.
- [OSHA API](https://fous.com/workflows/osha.md): Public workplace safety inspection and enforcement records.
- [ABN Lookup API](https://fous.com/workflows/abn-lookup.md): Search Australian businesses by name or ABN and check public registration details.
- [crt.sh API](https://fous.com/workflows/crt-sh.md): Public certificate transparency search for issued certificates and names they cover.
- [PyPI API](https://fous.com/workflows/pypi.md): PyPI provides package metadata, links, and current/latest plus 10 recent versions; release dates reflect first file uploads, and keyword searches return up to 100 packages.
- [All Security workflows](https://fous.com/workflows/category/security)
