What is Have I Been Pwned?

Search tens of billions of breached records, monitor corporate domains via API, and get alerted when credentials are exposed.

SubcategoryData breach notification / credential exposure monitoring
Price€4,00

What is Have I Been Pwned?

Introduction to Have I Been Pwned — what it does and who it is for.

Search tens of billions of breached records, monitor corporate domains via API, and get alerted when credentials are exposed.

What do you need to run Have I Been Pwned?

System requirements, OS support, and hardware needs for Have I Been Pwned.

Have I Been Pwned is a hosted web service accessed through a browser or API, so it has no memory, storage, processor, or install requirements.

Operating system
no OS restriction)Web-based (browser access
Devices
Any device with a web browser

Programming languages

  • C#
  • TypeScript

How much does Have I Been Pwned cost?

Pricing plans, license type, and availability for Have I Been Pwned.

HIBP's core breach search is free for anyone, while its API is a paid subscription with Core, Pro, and High RPM tiers starting at $4.39/month for Core 1.

Price summary€4,00 (Freemium)
License detailsFree for personal/public breach and password checks; paid tiered API subscriptions (Core, Pro, High RPM) required for domain monitoring, k-anonymity email search, and higher request volumes. The core breach-search platform itself is proprietary; only auxiliary tools are open-sourced under the HaveIBeenPwned GitHub organization.
AvailabilityAvailable
PlanDescriptionPrice
Core 110 requests/min, direct email search, monitor up to 1 domain€4,39
Core 3100 requests/min, direct email search, monitor up to 5 domains€36,99
Pro 11,000 email RPM, k-anonymity email search, customer domain monitoring for MSPs, stealer log data, up to 50 domains€4,55
High RPM 40004,000 email RPM, direct and k-anonymity email search, high-throughput API access, Pwned Passwords support€13,80

What is Have I Been Pwned used for?

Key features, use cases, and capabilities of Have I Been Pwned.

HIBP offers email breach search, domain monitoring, a free notification service, the Pwned Passwords k-anonymity check, and a tiered REST API.

Key features

  • Email breach search
  • Domain search and monitoring via API
  • Free breach notification service (email alerts)
  • Pwned Passwords (k-anonymity password check)
  • Public REST API with tiered subscriptions
  • "Who's been pwned" breach timeline
  • Stealer log search (Pro+ tiers)
  • Unified account dashboard

Use cases

  • Individuals checking whether their personal email has been exposed in a known data breach
  • Security teams monitoring corporate domains for compromised employee credentials
  • Developers integrating breach-checking or password-strength validation into signup/login flows via the API
  • Password managers and browsers offering built-in breach alerts to their users

Who should use Have I Been Pwned?

Target users, industries, and ideal use cases for Have I Been Pwned.

The service serves everyday consumers checking personal exposure as well as security teams, developers, and MSPs monitoring domains for breached credentials.

Industries
Cybersecurity / information security
Target audienceGeneral Consumers, Security Researchers, IT/security Teams, And Developers Building Breach-aware Applications

How is Have I Been Pwned deployed?

Deployment options, API, and hosting for Have I Been Pwned.

HIBP is entirely web-based and cloud-hosted by its operator; it is not self-hosted or installed locally, though the API can be integrated into other software.

API integration
Open source
Self-hosting

How do you get started with Have I Been Pwned?

Installation and onboarding steps for Have I Been Pwned.

Users can start immediately by searching an email address on haveibeenpwned.com for free, or sign up for an API key via the Subscription dashboard for programmatic and domain-search access.

What are the pros and cons of Have I Been Pwned?

Balanced review of strengths and weaknesses of Have I Been Pwned.

Reviewers on Trustpilot and elsewhere praise HIBP's free access and reliability, while noting it lacks specifics on which credentials were leaked and gates advanced features behind a paid API.

ProCon
Free to use for personal breach checks covering billions of compromised accounts (Trustpilot reviews)Breach notifications indicate exposure but do not reveal which specific password or data was leaked, leaving users unsure what to change (Trustpilot reviews)
Widely regarded as a highly reliable, accurate resource for identifying compromised accounts (WikipediaAdvanced features like domain monitoring, k-anonymity email search, and higher-volume lookups require a paid API subscription (haveibeenpwned.com/Subscription)
Trustpilot)A few users report suspicious account activity shortly after submitting their email, raising concern despite HIBP's stated no-logging policy (Trustpilot reviews)
Pioneered the k-anonymity Pwned Passwords protocol, later adopted by Google, protecting privacy during lookups (Wikipedia)
Integrates with major password managers and browsers such as 1Password and Firefox (Wikipedia)
Actively and independently maintained by a small trusted team with a track record since 2013 (troyhunt.com
Wikipedia)

Where can you learn more about Have I Been Pwned?

Documentation, support, and official links for Have I Been Pwned.

Official documentation is available at haveibeenpwned.com/API/v3, with supporting open-source tools published on the HaveIBeenPwned GitHub organization.

Frequently asked questions

What is Have I Been Pwned?

Have I Been Pwned — Search tens of billions of breached records, monitor corporate domains via API, and get alerted when credentials are exposed.

How much does Have I Been Pwned cost?

HIBP's core breach search is free for anyone, while its API is a paid subscription with Core, Pro, and High RPM tiers starting at $4.39/month for Core 1.

What is Have I Been Pwned used for?

HIBP offers email breach search, domain monitoring, a free notification service, the Pwned Passwords k-anonymity check, and a tiered REST API.

Where can I get Have I Been Pwned?

You can get Have I Been Pwned via the official website, GitHub and the product page. See the resources section on this page for direct links.

Who should use Have I Been Pwned?

The service serves everyday consumers checking personal exposure as well as security teams, developers, and MSPs monitoring domains for breached credentials.

What do you need to run Have I Been Pwned?

Have I Been Pwned is a hosted web service accessed through a browser or API, so it has no memory, storage, processor, or install requirements.

How do you get started with Have I Been Pwned?

Users can start immediately by searching an email address on haveibeenpwned.com for free, or sign up for an API key via the Subscription dashboard for programmatic and domain-search access.

How is Have I Been Pwned deployed?

HIBP is entirely web-based and cloud-hosted by its operator; it is not self-hosted or installed locally, though the API can be integrated into other software.

Who developed Have I Been Pwned?

Have I Been Pwned is developed by Troy Hunt.

What are the pros and cons of Have I Been Pwned?

Reviewers on Trustpilot and elsewhere praise HIBP's free access and reliability, while noting it lacks specifics on which credentials were leaked and gates advanced features behind a paid API.