Have I Been Pwned MCP Server
Check if your accounts or passwords have been compromised in data breaches using the HIBP service.
Ask AI about this MCP Server
Vinkius supports streamable HTTP and SSE.

* Every MCP server runs on Vinkius-managed infrastructure inside AWS - a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts optimized for native MCP execution. See our infrastructure
What is the Have I Been Pwned MCP Server?
The Have I Been Pwned MCP Server gives AI agents like Claude, ChatGPT, and Cursor direct access to Have I Been Pwned via 5 tools. Check if your accounts or passwords have been compromised in data breaches using the HIBP service. Powered by the Vinkius - no API keys, no infrastructure, connect in under 2 minutes.
Built-in capabilities (5)
Tools for your AI Agents to operate Have I Been Pwned
Ask your AI agent "Has my email 'test@example.com' been involved in any breaches?" and get the answer without opening a single dashboard. With 5 tools connected to real Have I Been Pwned data, your agents reason over live information, cross-reference it with other MCP servers, and deliver insights you would spend hours assembling manually.
Works with Claude, ChatGPT, Cursor, and any MCP-compatible client. Powered by the Vinkius - your credentials never touch the AI model, every request is auditable. Connect in under two minutes.
Why teams choose Vinkius
One subscription gives you access to thousands of MCP servers - and you can deploy your own to the Vinkius Edge. Your AI agents only access the data you authorize, with DLP that blocks sensitive information from ever reaching the model, kill switch for instant shutdown, and up to 60% token savings. Enterprise-grade infrastructure and security, zero maintenance.
Build your own MCP Server with our secure development framework →Vinkius works with every AI agent you already use
…and any MCP-compatible client


















Have I Been Pwned MCP Server capabilities
5 toolsUses k-anonymity; your full password is never sent to the server. Check if a password has ever appeared in a data breach (safe, k-anonymity search)
Get details for a specific data breach by name
List all data breaches currently recorded in the system
Search for all data breaches an email or account has been involved in
Search for all public pastes (like Pastebin) containing the email or account
What the Have I Been Pwned MCP Server unlocks
Connect your AI agent to Have I Been Pwned, the internet's most trusted resource for tracking data breaches. Protect yourself by staying informed about where your sensitive information may have been leaked.
What you can do
- Account Search — Instantly check if an email or username has been involved in any of the thousands of tracked data breaches
- Paste Search — Discover if your information is circulating on public paste sites (like Pastebin)
- Password Safety — Safely verify if a password has ever appeared in a breach using the secure K-Anonymity model (your full password is never sent to the server)
- Breach Catalog — Explore the full history of major internet data breaches, including what types of data were stolen (passwords, emails, phone numbers, etc.)
How it works
1. Subscribe to this server
2. Enter your HIBP API Key (available at haveibeenpwned.com/API/Key)
3. Start auditing your digital safety through chat
Who is this for?
- Security-Conscious Users — monitor personal or family accounts for leaks
- IT Professionals — check for corporate domain or account compromises
- Researchers — analyze trends and impact of major data breaches
Frequently asked questions about the Have I Been Pwned MCP Server
Is it safe to check my password using this tool?
Yes. This agent uses the K-Anonymity model. Only the first 5 characters of your password's SHA-1 hash are sent to the HIBP server. The full password or full hash never leaves your local environment, making it cryptographically safe.
Where can I get an API Key?
You can purchase an API key directly from the HIBP website. It requires a small monthly subscription to prevent mass scraping and abuse.
More in this category
You might also like
Connect Have I Been Pwned with your favorite client
Step-by-step setup guides for every MCP-compatible client and framework:
Anthropic's native desktop app for Claude with built-in MCP support.
AI-first code editor with integrated LLM-powered coding assistance.
GitHub Copilot in VS Code with Agent mode and MCP support.
Purpose-built IDE for agentic AI coding workflows.
Autonomous AI coding agent that runs inside VS Code.
Anthropic's agentic CLI for terminal-first development.
Python SDK for building production-grade OpenAI agent workflows.
Google's framework for building production AI agents.
Type-safe agent development for Python with first-class MCP support.
TypeScript toolkit for building AI-powered web applications.
TypeScript-native agent framework for modern web stacks.
Python framework for orchestrating collaborative AI agent crews.
Leading Python framework for composable LLM applications.
Data-aware AI agent framework for structured and unstructured sources.
Microsoft's framework for multi-agent collaborative conversations.
Give your AI agents the power of Have I Been Pwned MCP Server
Production-grade Have I Been Pwned MCP Server. Verified, monitored, and maintained by Vinkius. Ready for your AI agents — connect and start using immediately.






