4,500+ servers built on MCP Fusion
Vinkius
Have I Been Pwned logo
Vinkius
Claude Desktop logo

How to Use the Have I Been Pwned MCP in Claude

Claude Desktop connects to this MCP Server to check your credentials against known breaches before you deploy.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Have I Been Pwned MCP on Cursor AI Code Editor MCP Client Have I Been Pwned MCP on Claude Desktop App MCP Integration Have I Been Pwned MCP on OpenAI Agents SDK MCP Compatible Have I Been Pwned MCP on Visual Studio Code MCP Extension Client Have I Been Pwned MCP on GitHub Copilot AI Agent MCP Integration Have I Been Pwned MCP on Google Gemini AI MCP Integration Have I Been Pwned MCP on Lovable AI Development MCP Client Have I Been Pwned MCP on Mistral AI Agents MCP Compatible Have I Been Pwned MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Claude Desktop

Connect Have I Been Pwned MCP to Claude Desktop

Create your Vinkius account to connect Have I Been Pwned to Claude Desktop and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Safe password verification in Claude Desktop

The `check_password_safety` tool verifies if a specific hash exists in known breach dumps. It uses k-anonymity. Your actual password never leaves your machine. Claude just sends the first five characters of the SHA-1 hash to the API and compares the results locally. You don't want to find out about a compromised admin credential after a breach happens. Ask your agent to run the check directly in your chat interface. It pulls the match count and tells you exactly how many times that hash appeared in the wild.

Map out exposed account footprints

The `search_account_breaches` tool finds every recorded data breach tied to a specific email address. You hand Claude an email, and it returns the exact list of compromised services. It cuts through the noise and shows you the raw exposure data. Attackers don't just use structured breach dumps — they scrape Pastebin. That is why the `search_account_pastes` tool exists. It hunts down public text dumps containing your target email. You get the paste titles and dates so you can see exactly when the exposure occurred.

Analyze global MCP Server breach data

The `list_all_breaches` tool dumps the entire catalog of recorded security incidents. You can ask Claude to filter this list by year or data type. It gives you a clear view of historical targets and the specific classes of data lost. When you need the specifics of a single incident, the `get_breach_details` tool pulls the exact record by name. It outputs the breach date, the total number of compromised accounts, and the exact data fields exposed. This is how you decide if a specific breach actually threatens your current infrastructure.

Setup guide

Set up Have I Been Pwned MCP in Claude Web or Desktop

  1. 1

    Open Claude Settings

    Go to claude.ai, click your profile icon, then navigate to Customize → Connectors.

  2. 2

    Add Custom Connector

    Click the "+" button and select Add custom connector. Paste your Vinkius endpoint URL: https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp Replace [YOUR_TOKEN_HERE] with your token from cloud.vinkius.com. For OAuth-protected servers, expand Advanced settings to add credentials.

  3. 3

    Start a conversation

    Open a new chat. The Have I Been Pwned MCP tools are available immediately — no restart needed.

Endpoint URL

https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp

No configuration file needed — paste the URL directly in the Claude web interface.

Available on Free (1 connector), Pro, Max, Team, and Enterprise plans.

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about Have I Been Pwned MCP in Claude Desktop

You edit your claude_desktop_config.json file. Add the server command under the mcpServers key. Restart the app, and the tools will appear in your chat interface.
Yes, if you host the server remotely. Go to Settings, click Integrations, and paste the public HTTPS URL. You don't need to install anything locally.
The server itself is free. You will need a commercial API key from the HIBP service if you hit their rate limits.
Just ask Claude to check the email. It runs the search tools and outputs the exact breach history. If nothing comes back, the email isn't in their current database.
The check_password_safety tool uses k-anonymity. It only transmits the first five characters of a SHA-1 password hash to the external API. The remaining 35 characters stay completely local to your machine, ensuring the full hash is never exposed over the network.

Start using the Have I Been Pwned MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 5 tools

We've already built the connector for Have I Been Pwned. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 5 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.