Is io.github.troyhunt/hibp up? Live MCP status
Yes, it is up. It answered an MCP server/discover with no credential and negotiated protocol 2026-07-28.
A stock client connected with no credential and negotiated 2026-07-28. Use it.
| Outcome | usable |
|---|---|
| HTTP status | 200 |
| Protocol version | 2026-07-28 |
| Server says it is | hibp-mcp-server 0.0.0 |
| Answered in | 104 ms |
| Endpoint checked | https://haveibeenpwned.com/mcp |
| Checked |
One MCP handshake with the listed endpoint (server/discover at 2026-07-28, then initialize for a server on the older revision), with no credential and no retry, identifying itself as agentwares-mcp-liveness/0.1 (+https://agentwares-agentcheck.vercel.app/bot). It runs when this page is requested and the result is reused for 10 minutes, so the time above is when it was taken.
Live status every few hours: Wellknown
Email me when this server changes
That was one look. To hear when it stops answering or its tools change, leave an address.
Free, no password or GitHub: one confirmation email first, then a check every hour and an email when it stops answering or its tools change. Every email has a link to stop. More about it.
Monthly census, 6 October 2026
The census sends the same request to every remote listing in the official registry once a month. On 6 October 2026 this one answered a stock client with no credential. Every listing’s result: index.ndjson (what the files hold: index.meta.json).
Agent discovery documents at this origin
| A2A agent card | Not published (HTTP 404)./.well-known/agent-card.json |
|---|---|
| MCP server card (SEP-2127) | Not published (HTTP 404).https://haveibeenpwned.com/mcp/server-card |
| MCP server card (SEP-1649 location) | Published, does not validate: `$schema` is required (and 3 more). SEP-1649 shape; Have I Been Pwned MCP 0.0.0; streamable-http./.well-known/mcp/server-card.json — SEP-1649, a draft superseded by SEP-2127 on 21 January 2026 |
| Web Bot Auth key directory | Not published (HTTP 404)./.well-known/http-message-signatures-directory |
Read at https://haveibeenpwned.com with the monthly census on 9 October 2026: one GET each, no credential, never a signed request. A2A against v1.0.1, the server card against the MCP Server Card schema (SEP-2127), the card at SEP-1649’s location against the shape it has, the key directory against the Web Bot Auth draft of 1 September 2026. Who publishes them.
Tool changes between snapshots
In the 2026-10 snapshot it listed 17 tools: hibp_generate_domain_verification_dns_token, hibp_get_breach, hibp_get_breached_account, hibp_get_breached_account_range, hibp_get_breached_domain, hibp_get_latest_breach, hibp_get_paste_account, hibp_get_pwned_passwords_range, hibp_get_stealer_logs_by_email, hibp_get_stealer_logs_by_email_domain, hibp_get_stealer_logs_by_website_domain, hibp_get_subscription_status, hibp_list_breaches, hibp_list_data_classes, hibp_list_subscribed_domains, hibp_send_domain_verification_email, hibp_verify_domain_verification_dns_token.
Its tools changed between 2026-09 and 2026-10:
- The tool list as a whole hashes differently.
Which tools were added or removed, and whose description or schemas changed, from content hashes in the monthly snapshots. Per tool, as JSON: /v1/drift.
The listing
| Registry name | io.github.troyhunt/hibp |
|---|---|
| Title | Have I Been Pwned |
| Description | Breach intelligence API: email search, domain monitoring, passwords and stealer logs. |
| Endpoint | https://haveibeenpwned.com/mcp |
| Publisher repository | none listed |
| Version | 1.0.0 |
| Listing updated |
Also
The full check by name, as JSON (on a 401 it also follows the OAuth discovery chain) · Watch it · Check another server · llms.txt