{"uid":"cap_dX7neQnzG5q4MIL1PAM_g","slug":"saylor-innovations-password-breach-check-by-sha-1-43d89dae","name":"Saylor Innovations Password Breach Check by SHA-1","description":"Password Breach Check by SHA-1 (Have I Been Pwned) — Security","url":"https://saylorinnovations.com/api/breach/password?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","POST","PUT","PATCH","DELETE","HEAD"],"type":"string"},"queryParams":{"type":"object","properties":{"sha1":{"type":"string","description":"40-hex SHA-1 hash of the password; never send the password itself (query)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string","const":"json"},"example":{"type":"object","required":["pwned"],"properties":{"pwned":{"type":"boolean"},"times_seen":{"type":"number"}}}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_vn59fOuNh9zVcwHTkJl6b","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether a password appears in known data breaches using its SHA-1 hash prefix via the Have I Been Pwned k-anonymity range API, returning breach status and exposure count.","exampleAgentPrompt":"Can you check if the password 'Summer2024!' has ever shown up in a data breach — hash it to SHA-1 first and use the breach check API so the actual password is never sent?","exampleUseCases":[{"title":"Password safety check at signup","prompt":"Before I let a user register with this password, check if it's been seen in any data breaches — hash it to SHA-1 and run it through the breach checker so we never transmit the raw password."},{"title":"Security audit of stored credentials","prompt":"I have a list of hashed passwords from our database — can you check each SHA-1 hash against the breach API and flag any that have been exposed, along with how many times they've been seen?"},{"title":"Personal password hygiene check","prompt":"I'm updating my accounts — can you check if 'Fluffy$Cat99' has ever appeared in a known data breach by hashing it to SHA-1 and checking the HIBP breach database?"}],"resultDescription":"Returns a JSON object with a 'pwned' boolean indicating whether the password hash has appeared in known breach datasets, and a 'times_seen' number showing how many times it has been observed across all breaches. No raw password data is ever transmitted.","failureModes":["Invalid or malformed SHA-1 hash (not 40 hex characters) returns an error","Network timeout or upstream HIBP service unavailability","Missing 'sha1' query parameter causes bad request response","Hash provided is not lowercase/uppercase normalized as expected"],"whenToPreferThis":"Use this endpoint when you need a privacy-preserving breach check that never exposes the raw password — it uses the k-anonymity model so only a hash prefix is sent to the upstream HIBP service. Prefer this over full-password submission approaches or manual HIBP API integration when you need a simple, pay-per-call microservice with no API key management.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T12:51:03.429Z","isFirstParty":false,"canonicalSlug":"saylor-innovations-password-breach-check-by-sha-1-43d89dae"}