Archivarix

paste-leak-index

Have I Been Pwned (pwned passwords)

An index of accounts and credentials that have appeared in known data breaches. The Pwned-Passwords range endpoint is keyless, so our search can query it directly, while the fuller breach-lookup API is paid and individual account checks happen on the website itself. Use it to confirm whether a credential has surfaced in a leak. The service is flagged as degraded in our latest checks, so the website may be inconsistent to reach.

API degraded

Por qué es útil y cómo funciona

Have I Been Pwned is the standard reference for checking whether an email address or password has appeared in a known data breach or credential-stuffing leak. The Pwned Passwords service lets you check a specific password without ever sending it in full: you submit the first five characters of its SHA-1 hash and the service returns all matching hashes, so the check is private. Echo links you to the website where you can look up email addresses; the password-hash range check runs without a key.

Qué contiene

The site tracks over 1,000 breached services and more than 15 billion compromised accounts. The separate Pwned Passwords dataset holds billions of unique plaintext-equivalent password hashes drawn from breach data, with major additions made regularly as new leaks are processed.

Acceso por API

https://api.pwnedpasswords.com/range/ <prefix> (keyless); breach API paid

Acceso

Programmatic API access (a key may be required, see the API tag).

Página principal

https://haveibeenpwned.com/