Return whether a password appears in known data breaches and how many times, using the Have I Been Pwned k-anonymity range API. Only the first 5 characters of the SHA-1 hash are sent upstream.
This page documents the MCP tool findutils:password_breach_checker. See the REST reference →
This tool fetches a fixed, hard-coded public upstream — never a private host. Results depend on that upstream.
Call it over MCP
Tool name findutils:password_breach_checker
· no API keys · 120 requests/min per IP
Claude Code
claude mcp add findutils --transport http https://mcp.findutils.com/ Claude Desktop — claude_desktop_config.json
{
"mcpServers": {
"findutils": {
"url": "https://mcp.findutils.com/"
}
}
} Raw JSON-RPC (any MCP client) — verified example
curl -X POST https://mcp.findutils.com/ \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "password_breach_checker",
"arguments": {
"password": "password"
}
}
}' Input schema
| Argument | Type | Required | Description |
|---|---|---|---|
| password | string | yes | The password to check. It is hashed locally and never transmitted. |
Example arguments (verified)
{
"password": "password"
} Also a REST endpoint
The same tool answers plain HTTP at
POST /api/tools/password-breach-checker/execute — no key, 60 requests/min.
More Security tools
Base32 Encode
Encode UTF-8 text to RFC 4648 base32 (uppercase, "=" padding).
Data Sanitizer
Sanitize untrusted text and return the cleaned output, a list of changes made, and a risk level.
Dnpm Configurator
Returns the five files of a hardened Docker-based npm wrapper (the ./dnpm bash script, .dnpm/Dockerfile, docker-compose.node.yml, .dnpm/secc
Email Header Analyzer
Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop delays,
Hash Comparison Tool
Hash text with SHA-1, SHA-256, SHA-384, or SHA-512 and compare the hex digest with an expected hash.
Jwt Decode
Decode a JWT header + payload.
Jwt Generator
Generate a signed JWT (HS256, HS384, or HS512 via HMAC) and return the token plus the decoded header and payload.
Jwt Security Validator
Decode a JWT and return a list of security checks (algorithm strength, expiration, not-before, issued-at, issuer, audience, subject, signatu