How to hit the Have I Been Pwned API

Have I Been Pwned at https://haveibeenpwned.com/api/v3 catalogs public data breaches. Breach listings are free; searching by email address needs a paid key.

Authentication

None for the calls below. Checking an email address needs a key sent as hibp-api-key.

Full reference: https://haveibeenpwned.com/API/v3

Breaches for a domain

curl "https://haveibeenpwned.com/api/v3/breaches?domain=adobe.com"
Run in PostTaco
Example response (trimmed)
[
  {
    "Name": "Adobe",
    "Title": "Adobe",
    "Domain": "adobe.com",
    "BreachDate": "2013-10-04",
    "AddedDate": "2013-12-04T00:00:00Z",
    "ModifiedDate": "2022-05-15T23:52:49Z",
    "PwnCount": 152445165,
    "LogoPath": "https://logos.haveibeenpwned.com/Adobe.png",
    "Attribution": null,
    "DisclosureUrl": null,
    "DataClasses": [
      "Email addresses",
      "Password hints"
    ],
    "IsVerified": true,
    "IsFabricated": false,
    "IsSensitive": false,
    "IsRetired": false
  }
]

One breach

curl https://haveibeenpwned.com/api/v3/breach/LinkedIn
Run in PostTaco
Example response (trimmed)
{
  "Name": "LinkedIn",
  "Title": "LinkedIn",
  "Domain": "linkedin.com",
  "BreachDate": "2012-05-05",
  "AddedDate": "2016-05-21T21:35:40Z",
  "ModifiedDate": "2016-05-21T21:35:40Z",
  "PwnCount": 164611595,
  "LogoPath": "https://logos.haveibeenpwned.com/LinkedIn.png",
  "Attribution": null,
  "DisclosureUrl": null,
  "DataClasses": [
    "Email addresses",
    "Passwords"
  ],
  "IsVerified": true,
  "IsFabricated": false,
  "IsSensitive": false,
  "IsRetired": false
}