- Home
- Resources
- Integrations
- Have I Been Pwned
Claude Have I Been Pwned connectorWhat Claude can do in your Have I Been Pwned account.
The Claude Have I Been Pwned connector exposes 17 tools. 14 read, 3 write, 0 left undocumented. Below: which breach checks Claude can run, which ones need you signed in to HIBP, and the domain verification steps that change your account and send an email.
Verified Trustpilot reviews · AI, automation & growth agency
What changes for your security checks
You stop pasting addresses into a search box one by one. With the connector on, Claude can query HIBP while you talk: which breaches an address appears in, what a given breach exposed, what turned up for your verified domain, and what stealer logs recorded. Public breach data even works before you sign in.
Answer a worried colleague. Someone asks whether their work address leaked. hibp_get_breached_account returns the breaches tied to it, and hibp_get_breach details any one of them.
Audit your own domain. For a domain already verified in HIBP, hibp_get_breached_domain lists exposure across its addresses, and the stealer log tools show which sites were seen alongside them.
Prove you own a domain. Three tools handle verification: hibp_generate_domain_verification_dns_token prepares a DNS record value, hibp_verify_domain_verification_dns_token checks it, and hibp_send_domain_verification_email mails an authorised address. These are the steps that change your account.
What Claude cannot do here: reach subscriber data your HIBP subscription does not include, search a domain before it is verified, or recall a verification email once sent. Stealer log hits are historical and do not show current access. And nothing runs on its own: no tool alerts you when a new breach is loaded. Background monitoring belongs to an automation tool, a different job; the Integrations hub covers it.
The vocabulary in one minute
Five words you will meet while connecting HIBP.
- Connector
- The link you set up once between Claude and an account you already have, so Claude can work in it while answering you.
- Tool
- One named thing a connector lets Claude do. Claude picks the ones it needs by itself, and the directory lists each by name.
- Authorization
- The sign-in screen of the service itself, where you hand Claude its access. Granted once per person, and you can take it back.
- Approval
- The confirmation Claude waits for before it goes through with something that changes your account, shown right in the conversation.
- MCP
- The shared standard connectors are built on: it is what lets an assistant like Claude talk to an outside service.
Connect HIBP to Claude in three steps
- 01
Find HIBP in Claude
In Claude's settings, open Customize, then Connectors, and look for the HIBP connector in the list. On a Team or Enterprise workspace, an Owner or Primary Owner has to enable the connector first, before each member can sign in.
- 02
Start the connection
Click Connect on its row, then sign in to HIBP in the window HIBP opens itself. The access granted there is yours alone, given once per person. If the link breaks later, use Disconnect and connect again.
- 03
Read the authorization screen
Check the authorization screen before you accept. It belongs to HIBP, not to Claude, and it decides what the access covers. You can also withdraw that access later from your HIBP account.
The 17 tools, sorted by what they do
Have I Been Pwned gives Claude 17 tools: 14 that read your account, 3 that change something in it.
Two groups: what Claude reads, and what changes your HIBP account. Names stay as Claude shows them, in English.
- 14 read
- 3 write
Tools index
- hibp_list_breaches
- hibp_get_breach
- hibp_get_latest_breach
- hibp_list_data_classes
- hibp_get_pwned_passwords_range
- hibp_get_breached_account
- hibp_get_breached_account_range
- hibp_get_paste_account
- hibp_get_breached_domain
- hibp_list_subscribed_domains
- hibp_get_subscription_status
- hibp_get_stealer_logs_by_email
- hibp_get_stealer_logs_by_website_domain
- hibp_get_stealer_logs_by_email_domain
What Claude reads (14)
14 toolsFourteen lookups. HIBP flags each one as read-only with no side effects.
hibp_list_breaches
Fetches the public metadata of the breaches loaded in HIBP, so Claude can browse the catalogue without you signing in. HIBP states the lookup leaves its data untouched and acts on nothing for you.
hibp_get_breach
Brings up the details of a single breach by its name, from the existing record only. Claude can then explain what that incident exposed.
hibp_get_latest_breach
Returns the single breach most recently loaded into the HIBP corpus, with its published metadata, ready for Claude to summarise its impact and the kinds of data involved.
hibp_list_data_classes
Lists the categories HIBP uses to label exposed information in a breach, such as the kinds of personal data a leak contained.
hibp_get_pwned_passwords_range
Looks up anonymised password hash suffixes and their occurrence counts for a hash prefix, using the k-anonymity model. HIBP says it keeps no information about you, and the lookup is open before any sign-in.
hibp_get_breached_account
Gives the breaches associated with one email address, read from existing records. This is the classic HIBP check, run from the chat.
hibp_get_breached_account_range
Matches the first six characters of an email's SHA-1 hash and returns suffixes with non-sensitive breach names; the comparison then happens on the caller's side.
hibp_get_paste_account
Retrieves paste records tied to an email address, the metadata of public text dumps where it appeared, without altering anything.
hibp_get_breached_domain
Reports breach exposure for the addresses on a domain you have verified in HIBP, as an authorised domain search.
hibp_list_subscribed_domains
Shows which domains are attached to your signed-in HIBP account, from subscription information only; nothing is added or removed from that list.
hibp_get_subscription_status
Reads the current subscription status of your HIBP account, without touching billing or account settings, so Claude can tell you what the account currently holds.
hibp_get_stealer_logs_by_email
Lists the website domains historically observed in stealer logs for a given email address.
hibp_get_stealer_logs_by_website_domain
Returns email addresses historically seen in stealer logs for a given website domain, read from existing records, which helps you see which of your users were caught.
hibp_get_stealer_logs_by_email_domain
Surfaces aliases and their associated website domains historically observed in stealer logs for an email domain, so you see which addresses of yours were caught and where.
What Claude changes (3)
3 toolsThree domain verification steps. No source describes a confirmation of their own: the general rule below applies.
hibp_generate_domain_verification_dns_token
Approval: see the ruleCreates, or reuses, the private HIBP records for a domain verification request and returns the DNS TXT value to publish. It changes account-related state, which is why HIBP does not treat it as read-only.
hibp_verify_domain_verification_dns_token
Approval: see the ruleChecks a previously generated token against live DNS and may mark the domain as verified in your HIBP account.
hibp_send_domain_verification_email
Approval: see the ruleEmails an authorised recipient as part of proving you own the domain. HIBP flags it as destructive because the message cannot be recalled once delivered, and the recipient still has to act.
What Claude asks before acting
By default, Claude stops and asks for your go-ahead before each action it takes on an account for you. The request shows up in the conversation, when it matters.
On a Team or Enterprise workspace, owners decide whether a member may let some actions through without being asked every time. They can also cap what a connector may do for the whole organization, keeping lookups open and closing the verification steps, and nobody overrides that from their own account. Claude works with your rights and nothing more: domain searches stay limited to domains your HIBP account has verified.
Which plans include it
None of the 819 sheets in the official directory shows availability by plan. That answer is published nowhere, connector by connector: a real gap in the catalogue.
The general rule is published: remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile. On Team and Enterprise, an Owner or Primary Owner enables the connector for the organization before members can connect. For the current state, check the connector's sheet in the official directory, the only place that shows it.
Where this connector stops
A connector is not an automation. Claude calls these tools while it answers you: nothing starts when HIBP loads a new breach or a domain shows up in one.
The tool list is an observed floor, not a promise: an administrator can open actions that appear on no public sheet. The partner badge is not a security audit either, and Anthropic says so on every sheet: it does not choose the tools a publisher exposes and does not guarantee they behave as announced. Only HIBP's own documentation covers this connector, though it describes each tool unusually precisely.
Need help connecting Have I Been Pwned to Claude?
A person reads every message.