POST /api/haveibeenpwned/breaches/search
Price: 20 credits
Search the data breach catalog by domain, exposed data class and breach status flags
Search the Have I Been Pwned breach catalog. Filter by affected domain, by the class of data a breach exposed (e.g. 'Passwords', 'Credit cards'), and by breach status flags — verified, fabricated, sensitive, retired, spam list, malware, subscription-free, stealer log. Each result is a full breach record (same shape as the breaches endpoint). Returns every matching breach up to the requested count.
access-token string requiredtimeout integer — Max scrapping execution timeout (in seconds) (default: 300; min: 20; max: 1500)domain string nullable — Only breaches associated with this domain (examples: "adobe.com")data_class string nullable — Only breaches that exposed this class of data (see the data_classes endpoint for values) (examples: "Passwords", "Credit cards")is_verified boolean — Only breaches confirmed to be legitimate (default: false)is_fabricated boolean — Only breaches likely to be fabricated / not genuine (default: false)is_sensitive boolean — Only breaches marked sensitive (not publicly searchable) (default: false)is_retired boolean — Only breaches that have been retired from the system (default: false)is_spam_list boolean — Only breaches sourced from spam / marketing lists (default: false)is_malware boolean — Only breaches sourced from malware (default: false)is_subscription_free boolean — Only breaches searchable without a domain subscription (default: false)is_stealer_log boolean — Only breaches sourced from stealer logs (default: false)count integer required — Number of breach records to return (min: 1)@type string (default: "HaveibeenpwnedBreach")name string requiredbreach_title string nullabledomain string nullablebreach_date string nullableadded_at string nullablemodified_at string nullablepwn_count integer nullabledescription string nullableimage string nullableattribution string nullabledisclosure_url string nullabledata_classes array (default: [])is_verified boolean (default: false)is_fabricated boolean (default: false)is_sensitive boolean (default: false)is_retired boolean (default: false)is_spam_list boolean (default: false)is_malware boolean (default: false)is_subscription_free boolean (default: false)is_stealer_log boolean (default: false)web_url string (default: "")422 — The request body did not validate Check the fields against this schema. A URN with the wrong prefix is the most common cause.408 — The request ran past its time limit Raise `timeout` in the request body, up to the maximum this endpoint documents. Lowering `count` or turning off the `with_*` flags also helps, because less work finishes sooner.412 — The entity was not found, or a precondition failed Retrying will not help: either the entity does not exist, or the input points at a different one.429 — Too many requests: a rate limit or a usage window is exhausted When the response carries an X-Retry-After header, wait that many seconds and retry: the same number is in the body as `detail.retry_after`, and the limit clears once that window passes. The message in the body names the limit that was hit.500 — Something broke on our side Retrying will not help. If it keeps happening, send us the X-Request-ID from the response headers.529 — Rate limit reached, or the endpoint is overloaded Wait at least 30 seconds, then retry.X-Error — Error message text (present only on error)X-Request-ID — Unique request identifierX-Execution-Time — Execution time in secondsX-Result-Count — How many records the body carries. 0 means an empty result, which is a normal answer and not by itself an error. A non-zero count can come back together with X-Error when the failure happened partway through — read this header and X-Error independently.X-Total-Available-Results — How many records exist for this query, when the endpoint can say. On a `dry_run` request this is the answer and the body is empty. It saturates: the endpoint's documented maximum means 'at least that many', any smaller number is exact.X-Warning — Present when the request body carried keys this endpoint does not document. They were ignored, so any filter you meant to apply through them did not apply. Check the spelling against this schema and retry.X-Retry-After — Seconds to wait before retrying. Present only on 429.