Breach Database
Have I Been Pwned · Security · 1 endpoint
Every known data breach — when, where, how many accounts, and exactly what leaked, biggest first.
Base URL
Endpoint
Snippet
Request — cURL
v1
curl https://api.diraz.ae/v1/security/breaches \
-H "Authorization: Bearer drz_live_…"Query parameters
- domainstring · optional
- Only breaches at this domain, e.g. `adobe.com`.
- max_ageinteger (seconds) · optional
- Ask for data no older than this. Clamped to the product's own floor, so it can narrow the window but never force a refresh on every call.Default: 300
Example response
200 OK
v1
{
"data": {
"total": 1029,
"breaches": [
{
"name": "Adobe",
"title": "Adobe",
"domain": "adobe.com",
"breachDate": "2013-10-04",
"addedDate": "2013-12-04",
"pwnCount": 152445165,
"dataClasses": ["Email addresses", "Password hints", "Passwords", "Usernames"],
"verified": true,
"sensitive": false,
"url": "https://haveibeenpwned.com/breach/Adobe"
}
]
},
"meta": {
"request_id": "req_7Q2fK4mZ",
"as_of": "2026-08-22T04:05:00.000Z",
"age_seconds": 42,
"next_update_at": "2026-08-23T04:05:00.000Z"
}
}- breaches[].name / breachDate / pwnCount
- The breach, when it happened, and how many accounts it took.
- breaches[].dataClasses[]
- Exactly what leaked — email addresses, passwords, credit cards — in the breach's own words.
- breaches[].verified / sensitive
- Whether HIBP has verified the breach, and whether it involves sensitive material.
Errors
401 Unauthorized
v1
{
"error": {
"code": "UNAUTHORIZED",
"message": "The API key is invalid, expired, or revoked."
},
"meta": {
"request_id": "req_7Q2fK4mZ"
}
}Every failure carries a stable machine-readable code before the human message, and the same meta.request_id the successful responses carry. Quote it and we can find your exact request.
Errors are free
Nothing on this page is billed. You are charged for a 2xx and nothing else — a rejected key, a bad parameter, a rate limit, or an outage on our side all cost you zero. Retry without watching the meter.
- UNAUTHORIZEDHTTP 401
- Missing, malformed, expired, or revoked API key.
- FORBIDDENHTTP 403
- The key is valid but lacks the scope this product needs.
- VALIDATION_ERRORHTTP 422
- A query parameter is the wrong type or out of range.
- RATE_LIMITEDHTTP 429
- Rate limit exhausted. `Retry-After` says how long to wait.
- SERVICE_UNAVAILABLEHTTP 503
- No data recent enough to serve. Carries `Retry-After`, and is never billed.
- Status
- Operational
- Category
- Security
- Scope
- market:read
- Rate limit
- 120 requests / 60s per key
- Pricing
- 1 credit / request
- Breach Database
1/1 passing
Every response is timestamped. as_of is when the data was published, age_seconds how old that is now, and next_update_at when newer data is expected.
Three shapes to handle:
- Up to date200
The data is inside its published window. The overwhelming majority of requests.
- Delayeddelayed: true
Newer data is late. You still get the most recent there is, flagged so you can decide whether to use it.
- Unavailable503
Nothing recent enough to serve. Carries Retry-After, and is never billed.