MCP server
HomeHave I Been Pwned
Breach intelligence API: email search, domain monitoring, passwords and stealer logs.
- Endpoint
- Answering
- Works in
- 20 of 21 clients
- Tools
- 17
- Last checked
- Sep 20, 2026
Does Have I Been Pwned work in your MCP client?
Registry name io.github.troyhunt/hibp, endpoint https://haveibeenpwned.com/mcp.
- Claude Codeworks
- Claude Desktopworks
- Claude.aiworks
- Claude API MCP connectorworks
- ChatGPTworks
- OpenAI Responses APIworks
- Codexworks
- Gemini CLIworks
- Cursorworks
- VS Code (GitHub Copilot)works
- Windsurf (Devin Desktop)works
- Zedworks
- JetBrains AI Assistantworks
- Junieunknownno source confirms Junie supports Streamable HTTP
- Clineworks
- Continueworks
- Gooseworks
- Lovableworks
- Replit Agentworks
- Bolt.newworks
- v0works
How clients sign in
No credentials: it answered lurq's probe without any.
Tools
hibp_list_breacheshibp_get_breachhibp_get_latest_breachhibp_list_data_classeshibp_get_pwned_passwords_rangehibp_get_breached_accounthibp_get_breached_account_rangehibp_get_paste_accounthibp_get_breached_domainhibp_list_subscribed_domainshibp_get_subscription_statushibp_get_stealer_logs_by_emailhibp_get_stealer_logs_by_website_domainhibp_get_stealer_logs_by_email_domainhibp_generate_domain_verification_dns_tokenhibp_verify_domain_verification_dns_tokenhibp_send_domain_verification_email
Get the setup for your client from your agent
This page is a daily snapshot. lurq's connect_check answers for the client you are wiring this server into, with the exact steps and the config to paste in that client's own format, and lurq mcp-pin tells you when the server changes. One command connects Claude Code, Cursor, VS Code and other agents:
npx lurqrun
Free to start. How connect_check works
From lurq's credential-free probe of this server's endpoint on Sep 20, 2026, and each client's own documentation. This page refreshes every 168 hours. How the probe works, and how maintainers opt out.