
XposedOrNot Breach Intelligence
com.xposedornotv2.0.0Updated Oct 3, 2026
Real-time data-breach lookup and analytics for emails and domains from XposedOrNot.
Overview
Lets an assistant look up whether an email or domain appears in known data breaches, with breach analytics and metrics.
- What it does
- Connects to the XposedOrNot breach-intelligence API over Streamable HTTP. Tools include check_email_breaches for a quick email lookup, get_breach_analytics for detailed breach history, risk score and paste exposure, list_breaches for browsing the breach catalog by domain or breach ID, domain_breach_summary for aggregate counts, get_breach_metrics for system-wide statistics, and get_recent_breaches for the newest additions. All tools are read-only and the service states it never returns passwords.
- When to use it
- Useful when an assistant needs to check exposure of an email address or domain, summarize breach history, or report recent breach activity. Suited to security awareness, incident triage and research tasks where breach data is relevant.
- Requirements
- A remote MCP endpoint; no local runtime, package or API key is needed for the basic tools. Domain breach monitoring requires signing in to the provider's site, verifying domain ownership and passing an API key in the x-api-key header. Network access to the provider's API is required.
Installation
In SourceWeft
- Open XposedOrNot Breach Intelligence in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"xposedornot": {
"type": "http",
"url": "https://api.xposedornot.com/mcp"
}
}
}README
XposedOrNot API
🎉 Your free API for real-time data breach monitoring and analytics.
[Image]
[Image]
[Black]
[Pylint]
[CodeQL]
[Bandit]
[Dependency Audit]
[Atheris Fuzzing]
[OpenSSF Scorecard]
[OpenSSF Best Practices]
XposedOrNot API Playground · XposedOrNot.com
What is XposedOrNot API?
Data breaches happen constantly, and most people only find out long after their email and passwords are already circulating. I built XposedOrNot so you don't have to wonder. Check an email or domain and know right away whether it's turned up in a known breach.
This repo is the API that powers it all: the breach lookups, the analytics, and the alerts. It's free to use, and it's open-source, so you can read exactly how every check works rather than taking my word for it.
Give it a try below, and if you find it useful, I'd love for you to build something with it.
Devanand Premkumar, creator of XposedOrNot [Twitter/X] [Mastodon]
Quick Example
Check if an email has been exposed in data breaches:
Response:
Get detailed breach analytics:
Rate Limits & API Access
- No API key required for basic endpoints (
/v1/check-email,/v1/breach-analytics,/v1/breaches) - API key required for domain breach monitoring — see Domain endpoints & API keys for how to get and use one
Rate limits are applied per IP, per endpoint:
When a limit is exceeded the API returns 429 Too Many Requests with a Retry-After
header (seconds) and a JSON body carrying retry_after and reset_time, so clients
can back off precisely.
Commercial use & higher rate limits
The free API above is for personal and low-volume use, and it stays free. If you're building a product on breach data or need more throughput, xonAPI+ offers paid plans from $5/month with rate limits up to 25,000 requests/minute, API-key access, and commercial support. It's the same breach data, and it's what keeps the free tier free.
For full documentation, see the API docs and the API playground.
API Endpoints
The full, always-current spec lives at /docs
(Swagger) and /openapi.json. The
endpoints you'll reach for most:
Breach lookups
Stats & feeds
Domain endpoints & API keys
Breach data for a domain is only available once you've verified ownership of that domain, and calls are authenticated with an API key tied to your account.
Getting an API key — keys are issued and managed from the web console, not via a public endpoint:
- Sign in at xposedornot.com.
- Open your CxO Dashboard and verify the domain(s) you want to monitor.
- Go to API Key Management (linked from the dashboard). Your key is shown there; use Reset API Key to rotate it.
Using the key — pass it in the x-api-key header. The domain-breaches
endpoint takes no body; it returns breaches across all the domains you've
verified:
An invalid key (or one with no verified domains) returns 401 Invalid or missing API key; omitting the x-api-key header entirely returns 422. See the
API docs for the full domain verification and
alert-subscription flows.
Use it from your AI tools (MCP)
XposedOrNot ships a built-in Model Context Protocol
server, so AI assistants can check breaches directly. Point your MCP client at
https://api.xposedornot.com/mcp (Streamable HTTP, JSON-RPC 2.0 over POST).
No API key or authentication is needed; all tools are read-only and never
return passwords.
Tools exposed:
check_email_breaches: check if an email appears in any known breachget_breach_analytics: detailed breach history, risk score and paste exposure for an emaillist_breaches: browse the breach catalog, filter by domain or breach IDdomain_breach_summary: aggregate breach counts for a domainget_breach_metrics: system-wide breach statisticsget_recent_breaches: most recently added breaches, newest first
Quick connect:
For Cline, Cursor, Gemini CLI and other clients, see
llms-install.md. A machine-readable server card is at
https://api.xposedornot.com/.well-known/mcp/server-card.json.
A quick tools/list call:
Why use XposedOrNot API?
XposedOrNot was the first open-source tool to monitor and alert on data breaches, and this API gives you direct access to everything it has collected and keeps current. With it you can:
- Check whether an email has appeared in a known data breach, with stats on where and when
- See if an email shows up in public pastes
- Run a single combined search across both breaches and pastes
- Check whether a password has been exposed without ever revealing your identity
Prefer to just look something up without writing code? You can do all of this on the website too: https://xposedornot.com.
Security
This project is fully open-source and uses automated security tooling (Black, Pylint, CodeQL, OpenSSF Scorecard). For security details, see SECURITY.md.
Please do not report security vulnerabilities through public GitHub issues. Instead, refer to our Responsible Disclosure Guidelines for reporting these issues in a secure manner.
Prerequisites
- Docker (recommended): Docker 20.10+ and Docker Compose V2
- Local install: Python 3.11+, Google Cloud SDK
Quick Start for Local Development
Using Docker Compose (Recommended)
-
Clone the Repository:
-
Update the necessary environment variables in the docker-compose.yml file if needed, then run:
This command will build API and Datastore Docker images. Note that the project source directory is mapped in the Docker container, so any changes in the source code won't require rebuilding the Docker image.
Local Installation
-
Clone the Repository:
-
Install Required Packages
Then install the gcloud CLI — it's not in the stock Debian/Ubuntu repositories and is needed for step 4 (Datastore authentication or the local emulator).
-
Install Python Libraries
-
Setup Google Cloud Datastore
Before running XposedOrNot-API, choose one of the following options:
-
Run local Google DataStore emulator and debug using the local emulator rather than directly connect to Google DataStore.
-
Authenticate to Google DataStore and directly debug using Google DataStore.
-
Run the application
Configuration
Configuration is read from environment variables. For Docker Compose these are
already set in docker-compose.yml; for a local install, copy .env.example to
.env and fill in the values (or export them in your shell).
Required (the app won't start without these)
For local development you can set these to any placeholder value; the defaults in
docker-compose.ymlshow the expected format.
Redis (rate limiting & state)
Google Cloud (Datastore & Pub/Sub)
Optional
Contributing
Please read CONTRIBUTING.md for details on our code of conduct, and the process for submitting pull requests to us.
Authors
- Devanand Premkumar - Initial work - DevaOnBreaches
License
This project is licensed under the MIT License - see the LICENSE file for details
Acknowledgments
-
Thanks to the Python community and the maintainers of every library this project leans on. XposedOrNot stands on your work.
-
And to everyone who has reviewed the code and reported issues: thank you. A second set of eyes catches what I can't.
Show Your Support
If this saved you some trouble, a few things genuinely help:
- ⭐ Star the repo so others can find it
- Fork it and send a pull request; contributions are welcome
- Share it with someone who'd find it useful
Source: README.md at commit 0c7f747
Tools
0Version history
1- v2.0.0LatestOct 3, 2026

