Blooms
Security
Distribute keys once for serverless applications
Passwords which have previously been exposed in data breaches
Verified 4 days ago: 100% uptime
API key
Required
HTTPS
Supported
Browser calls
No, needs a proxy
Status
Live · 100/100
Last checked 2026-09-18. Measured independently, not self-reported by the provider.
A starting template for HaveIBeenPwned. Replace ENDPOINT with the path from the official documentation, which we link above rather than guess at.
# Requires an API key. Check the docs for whether it goes in a header or a query parameter.
curl -s "https://haveibeenpwned.com/ENDPOINT" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Accept: application/json"This API does not send CORS headers, so a browser will block a direct call from your front end. Call it from your server, or put a small proxy in front of it.
Aggregated from 2 public sources (public-api-lists, public-apis), then normalised and checked by us. If something here is wrong, tell us and we will correct it.
Security
Distribute keys once for serverless applications
Security
Ephemeral zero-knowledge encrypted data sharing
Security
Programmatic interfaces to engage with the Microsoft Security Response Center (MSRC)
Security
U.S. National Vulnerability Database
Security
Security and developer utility API -- malware, vulnerability, and domain checks, no signup
Security
FishFish is an automated service designed to quickly detect and mitigate phishing threats before they can be exploited for malicious purposes. It provides a streamlined solution for identifying harmful resources efficiently.
Answered from what our own scheduled checks found, not from the provider's marketing.
HaveIBeenPwned is listed in our free catalogue, but it requires an API key, so you will need to register before your first call. Providers frequently reserve higher limits and commercial use for paid plans.
Yes. HaveIBeenPwned authenticates with an API key. Keep it server-side rather than in browser code, because anything in your frontend bundle is readable by anyone who opens developer tools.
Not directly. HaveIBeenPwned did not return CORS headers when we checked, so the browser will block your page from reading the response even though the request itself succeeds. Call it from a server, or put a small proxy in front of it.
Yes, as of 2026-09-18. Our automated check reached HaveIBeenPwned and recorded a 100% reliability score with a median response time of 10385 ms. We re-check on a schedule, and this page updates with the result.
Yes. HaveIBeenPwned serves over HTTPS, so you can call it from a secure page without triggering a mixed-content block.