{"uid":"cap_NCtViy2HwS6ztXXVBt7kd","slug":"breach-account-d78e0ce1","name":"breach-account","description":"Look up the known breaches an email address appears in, returning breach METADATA only (name, date, data classes) and never passwords or leaked personal data. Uses the keyed Have I Been Pwned account API; when no API key is configured the route returns available false and the keyless password and domain routes still work. Breach indicators, not a guarantee.","url":"https://payai.agentstools.dev/breach/account","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["email"],"properties":{"email":{"type":"string","description":"Email address to check against known breaches"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_5rT9nP_QhEfwsL_xmcrrC","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Look up which known data breaches a given email address has appeared in, returning breach metadata (name, date, data classes) without exposing actual leaked credentials or personal data.","exampleAgentPrompt":"Can you check if the email address john.smith@example.com has shown up in any known data breaches and tell me which ones and what kind of data was exposed?","exampleUseCases":[{"title":"Personal email security audit","prompt":"Has my email address sarah.jones@gmail.com ever been part of a data breach? I want to know which breaches it appeared in and what types of data were compromised."},{"title":"Employee credential exposure check","prompt":"I need to know if our company email michael.chen@acmecorp.com has been exposed in any known data breaches — pull the breach names and what data classes were leaked."},{"title":"New user onboarding risk screening","prompt":"Before onboarding this new user, can you check whether newuser@startup.io appears in any known data breaches so I can flag it if their credentials may have been leaked?"}],"resultDescription":"Returns a list of known breaches the email address appears in, each with the breach name, the date it occurred, and the categories of data that were exposed (e.g. passwords, email addresses, phone numbers). Does not return actual leaked data. If the API key is not configured, returns available: false.","failureModes":["No API key configured — returns available: false and account lookups are unavailable","Email address not found in any breach — returns empty list or equivalent negative result","Invalid or malformed email address — may return validation error","Rate limiting from upstream HIBP API — may result in 429 or similar error","Email address not in HIBP database — treated as clean, not a guarantee of safety"],"whenToPreferThis":"Choose this endpoint when you need to check a specific email address against the Have I Been Pwned breach database and get structured breach metadata (name, date, data classes). Prefer this over password-hash checking endpoints when the goal is breach history awareness rather than credential verification. Use when you need safe, metadata-only breach indicators without any exposure of actual leaked data.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T19:06:53.489Z","isFirstParty":false}