# Password Breach Checker — REST API endpoint `password-breach-checker`

Return whether a password appears in known data breaches and how many times, using the Have I Been Pwned k-anonymity range API. Send `password` and it travels to this API over TLS, is hashed here, and only the first 5 characters of its SHA-1 go on to HIBP; the request body is not logged. For end-to-end k-anonymity send `sha1_prefix` (the first 5 hex characters of the SHA-1 you computed) instead, and match your own suffix in the returned `range`.

- Category: security
- MCP server: https://mcp.findutils.com/ (Streamable HTTP, no API keys, 120 req/min per IP)
- REST endpoint: POST https://api.findutils.com/api/tools/password-breach-checker/execute (no API keys, 60 req/min per IP)
- Network tool: fetches a fixed, hard-coded public upstream (never a private host).
- Reference page: https://findutils.com/api/password-breach-checker/
- Same tool on the other surface: https://findutils.com/mcp/password-breach-checker/

## Call the endpoint (verified example)

```bash
curl -X POST https://api.findutils.com/api/tools/password-breach-checker/execute \
  -H "Content-Type: application/json" \
  -d '{
    "password": "password"
  }'

# Parameter schema
curl https://api.findutils.com/api/tools/password-breach-checker
```

## Input schema

| Argument | Type | Required | Description |
|---|---|---|---|
| `password` | string | no | The password to check. Over this API it is sent to FindUtils over TLS, hashed server-side, and only the 5-character SHA-1 prefix goes to Have I Been Pwned; it is not logged or returned. Use sha1_prefix instead to keep the password on your side. |
| `sha1_prefix` | string | no | The first 5 hex characters of the SHA-1 hash you computed yourself. Returns every breached suffix in that range; find yours in `range` to finish the check without sending the password or its full hash. |

Example arguments (verified):

```json
{
  "password": "password"
}
```

OpenAPI 3.1 spec: https://findutils.com/api/openapi.json · Interactive docs: https://findutils.com/api/docs/

## Also an MCP tool

```bash
claude mcp add findutils --transport http https://mcp.findutils.com/
```

Then ask the client to call `findutils:password_breach_checker`. Full MCP reference: https://findutils.com/mcp/password-breach-checker/

---
Full catalog: GET https://api.findutils.com/api/tools · https://findutils.com/api/ · https://findutils.com/llms.txt
