Skip to content

HaveIBeenPwned

Passwords which have previously been exposed in data breaches

Open documentation ↗
API keyHTTPSNo CORSSecurity

Verified 4 days ago: 100% uptime

API key

Required

HTTPS

Supported

Browser calls

No, needs a proxy

Status

Live · 100/100

What our checks found

Health score
100/100
Reliability
100%
Average latency
10385ms

Last checked 2026-09-18. Measured independently, not self-reported by the provider.

How to call it

A starting template for HaveIBeenPwned. Replace ENDPOINT with the path from the official documentation, which we link above rather than guess at.

# Requires an API key. Check the docs for whether it goes in a header or a query parameter.
curl -s "https://haveibeenpwned.com/ENDPOINT" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"

This API does not send CORS headers, so a browser will block a direct call from your front end. Call it from your server, or put a small proxy in front of it.

Where this listing comes from

Aggregated from 2 public sources (public-api-lists, public-apis), then normalised and checked by us. If something here is wrong, tell us and we will correct it.

Other Security APIs

See all 71

Blooms

Security

Distribute keys once for serverless applications

No keyCORSHTTPS

Verified 4 days ago: 100% uptime

View Details

dead-drop

Security

Ephemeral zero-knowledge encrypted data sharing

No keyCORSHTTPS

Verified 4 days ago: 100% uptime

View Details

Presend

Security

Security and developer utility API -- malware, vulnerability, and domain checks, no signup

No keyCORSHTTPS

Verified 4 days ago: 100% uptime

View Details

FishFish

Security

FishFish is an automated service designed to quickly detect and mitigate phishing threats before they can be exploited for malicious purposes. It provides a streamlined solution for identifying harmful resources efficiently.

No keyCORSHTTPS

Verified 4 days ago: 100% uptime

View Details

HaveIBeenPwned — common questions

Answered from what our own scheduled checks found, not from the provider's marketing.

Is HaveIBeenPwned free to use?

HaveIBeenPwned is listed in our free catalogue, but it requires an API key, so you will need to register before your first call. Providers frequently reserve higher limits and commercial use for paid plans.

Does HaveIBeenPwned need an API key?

Yes. HaveIBeenPwned authenticates with an API key. Keep it server-side rather than in browser code, because anything in your frontend bundle is readable by anyone who opens developer tools.

Can I call HaveIBeenPwned from browser JavaScript?

Not directly. HaveIBeenPwned did not return CORS headers when we checked, so the browser will block your page from reading the response even though the request itself succeeds. Call it from a server, or put a small proxy in front of it.

Is HaveIBeenPwned still working?

Yes, as of 2026-09-18. Our automated check reached HaveIBeenPwned and recorded a 100% reliability score with a median response time of 10385 ms. We re-check on a schedule, and this page updates with the result.

Is HaveIBeenPwned available over HTTPS?

Yes. HaveIBeenPwned serves over HTTPS, so you can call it from a secure page without triggering a mixed-content block.