XposedOrNot Breach Intelligence

com.xposedornotv2.0.0更新於 Oct 3, 2026

Real-time data-breach lookup and analytics for emails and domains from XposedOrNot.

已驗證Streamable HTTP可網頁執行Security & MonitoringData & Analytics

概覽

AI 產生的概覽

讓助理查詢某個電子郵件或網域是否出現在已知資料外洩事件中,並提供外洩分析與統計。

功能
透過 Streamable HTTP 連線 XposedOrNot 外洩情報 API。工具包括 check_email_breaches(快速查詢電子郵件)、get_breach_analytics(詳細外洩歷史、風險分數與貼文外洩情形)、list_breaches(依網域或外洩 ID 瀏覽外洩目錄)、domain_breach_summary(網域彙總統計)、get_breach_metrics(全系統統計)以及 get_recent_breaches(最新新增的外洩事件)。所有工具皆為唯讀,服務方聲明不會回傳密碼。
適用情境
適合助理需要查核電子郵件或網域是否外洩、彙整外洩歷史或回報近期外洩動態的情境。可用於安全意識、事件排查與研究類工作。
執行需求
遠端 MCP 端點;基本工具不需要本機執行環境、套件或 API 金鑰。網域外洩監控需要登入服務方網站、驗證網域所有權,並在 x-api-key 標頭中傳入 API 金鑰。需要能連線服務方 API 的網路。
安裝前請注意
查詢會把所檢查的電子郵件或網域傳送給第三方服務,請勿提交無權分享的敏感或個人識別資訊。網域層級外洩資料需要驗證網域所有權並提供 x-api-key 憑證。免費端點依 IP 與端點限流;更高吞吐量屬於付費方案。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 XposedOrNot Breach Intelligence,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "xposedornot": {
      "type": "http",
      "url": "https://api.xposedornot.com/mcp"
    }
  }
}

README

XposedOrNot API

🎉 Your free API for real-time data breach monitoring and analytics.
[圖片] [圖片] [Black] [Pylint] [CodeQL] [Bandit] [Dependency Audit] [Atheris Fuzzing] [OpenSSF Scorecard] [OpenSSF Best Practices]

XposedOrNot API Playground · XposedOrNot.com


[XposedOrNot demo]

What is XposedOrNot API?

Data breaches happen constantly, and most people only find out long after their email and passwords are already circulating. I built XposedOrNot so you don't have to wonder. Check an email or domain and know right away whether it's turned up in a known breach.

This repo is the API that powers it all: the breach lookups, the analytics, and the alerts. It's free to use, and it's open-source, so you can read exactly how every check works rather than taking my word for it.

Give it a try below, and if you find it useful, I'd love for you to build something with it.

Devanand Premkumar, creator of XposedOrNot [Twitter/X] [Mastodon]

Quick Example

Check if an email has been exposed in data breaches:

bash
curl https://api.xposedornot.com/v1/check-email/[email protected]

Response:

json
{  "breaches": [["Adobe", "LinkedIn"]],  "email": "[email protected]",  "status": "success"}

Get detailed breach analytics:

bash
curl "https://api.xposedornot.com/v1/[email protected]"

Rate Limits & API Access

  • No API key required for basic endpoints (/v1/check-email, /v1/breach-analytics, /v1/breaches)
  • API key required for domain breach monitoring — see Domain endpoints & API keys for how to get and use one

Rate limits are applied per IP, per endpoint:

EndpointPer secondPer hourPer day
GET /v1/check-email/{email}225100
GET /v1/breach-analytics225100
GET /v1/breaches250100
POST /v1/domain-breaches/22550

When a limit is exceeded the API returns 429 Too Many Requests with a Retry-After header (seconds) and a JSON body carrying retry_after and reset_time, so clients can back off precisely.

Commercial use & higher rate limits

The free API above is for personal and low-volume use, and it stays free. If you're building a product on breach data or need more throughput, xonAPI+ offers paid plans from $5/month with rate limits up to 25,000 requests/minute, API-key access, and commercial support. It's the same breach data, and it's what keeps the free tier free.

For full documentation, see the API docs and the API playground.

API Endpoints

The full, always-current spec lives at /docs (Swagger) and /openapi.json. The endpoints you'll reach for most:

Breach lookups

MethodPathWhat it does
GET/v1/check-email/{email}Quick check: is this email in a known breach?
GET/v1/breach-analytics?email=Detailed breach analytics for an email
GET/v1/breachesList all known breaches (optional ?domain=)
GET/v1/domain-breach-summarySummary of breaches for a domain

Stats & feeds

MethodPathWhat it does
GET/v1/metricsTop-level breach metrics
GET/v1/metrics/detailedExpanded metrics
GET/v1/metrics/domain/{domain}Metrics for a single domain
GET/v1/analytics/pulseRecent breach activity pulse
GET/v1/xon-pulseXposedOrNot activity feed
GET/v1/rssBreach updates as an RSS feed

Domain endpoints & API keys

Breach data for a domain is only available once you've verified ownership of that domain, and calls are authenticated with an API key tied to your account.

Getting an API key — keys are issued and managed from the web console, not via a public endpoint:

  1. Sign in at xposedornot.com.
  2. Open your CxO Dashboard and verify the domain(s) you want to monitor.
  3. Go to API Key Management (linked from the dashboard). Your key is shown there; use Reset API Key to rotate it.

Using the key — pass it in the x-api-key header. The domain-breaches endpoint takes no body; it returns breaches across all the domains you've verified:

bash
curl -L -X POST \  -H "x-api-key: <YOUR_API_KEY>" \  -H "Content-Length: 0" \  https://api.xposedornot.com/v1/domain-breaches/

An invalid key (or one with no verified domains) returns 401 Invalid or missing API key; omitting the x-api-key header entirely returns 422. See the API docs for the full domain verification and alert-subscription flows.

Use it from your AI tools (MCP)

XposedOrNot ships a built-in Model Context Protocol server, so AI assistants can check breaches directly. Point your MCP client at https://api.xposedornot.com/mcp (Streamable HTTP, JSON-RPC 2.0 over POST). No API key or authentication is needed; all tools are read-only and never return passwords.

Tools exposed:

  • check_email_breaches: check if an email appears in any known breach
  • get_breach_analytics: detailed breach history, risk score and paste exposure for an email
  • list_breaches: browse the breach catalog, filter by domain or breach ID
  • domain_breach_summary: aggregate breach counts for a domain
  • get_breach_metrics: system-wide breach statistics
  • get_recent_breaches: most recently added breaches, newest first

Quick connect:

bash
claude mcp add --transport http xposedornot https://api.xposedornot.com/mcp

For Cline, Cursor, Gemini CLI and other clients, see llms-install.md. A machine-readable server card is at https://api.xposedornot.com/.well-known/mcp/server-card.json.

A quick tools/list call:

bash
curl -X POST https://api.xposedornot.com/mcp \  -H "Content-Type: application/json" \  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Why use XposedOrNot API?

XposedOrNot was the first open-source tool to monitor and alert on data breaches, and this API gives you direct access to everything it has collected and keeps current. With it you can:

  • Check whether an email has appeared in a known data breach, with stats on where and when
  • See if an email shows up in public pastes
  • Run a single combined search across both breaches and pastes
  • Check whether a password has been exposed without ever revealing your identity

Prefer to just look something up without writing code? You can do all of this on the website too: https://xposedornot.com.

Security

This project is fully open-source and uses automated security tooling (Black, Pylint, CodeQL, OpenSSF Scorecard). For security details, see SECURITY.md.

Please do not report security vulnerabilities through public GitHub issues. Instead, refer to our Responsible Disclosure Guidelines for reporting these issues in a secure manner.

Prerequisites

  • Docker (recommended): Docker 20.10+ and Docker Compose V2
  • Local install: Python 3.11+, Google Cloud SDK

Quick Start for Local Development

Using Docker Compose (Recommended)

  1. Clone the Repository:

    shell
    git clone https://github.com/XposedOrNot/XposedOrNot-API
  2. Update the necessary environment variables in the docker-compose.yml file if needed, then run:

    shell
    docker compose up

    This command will build API and Datastore Docker images. Note that the project source directory is mapped in the Docker container, so any changes in the source code won't require rebuilding the Docker image.

Local Installation

  1. Clone the Repository:

    shell
    git clone https://github.com/XposedOrNot/XposedOrNot-API
  2. Install Required Packages

    shell
    sudo apt-get install -y python3-pip build-essential libffi-dev python3-dev

    Then install the gcloud CLI — it's not in the stock Debian/Ubuntu repositories and is needed for step 4 (Datastore authentication or the local emulator).

  3. Install Python Libraries

    shell
    pip3 install -r requirements.txt
  4. Setup Google Cloud Datastore

    Before running XposedOrNot-API, choose one of the following options:

  1. Run the application

    shell
    python3 main.py

Configuration

Configuration is read from environment variables. For Docker Compose these are already set in docker-compose.yml; for a local install, copy .env.example to .env and fill in the values (or export them in your shell).

Required (the app won't start without these)

VariableWhat it's for
SECRET_APIKEYSecret used to sign issued API keys
SECURITY_SALTSalt for signing verification tokens
WTF_CSRF_SECRET_KEYCSRF protection secret
ENCRYPTION_KEYFernet key for encrypting stored data
AUTH_EMAILCloudflare account email
AUTHKEYCloudflare API key
CF_MAGICCloudflare integration token
CF_UNBLOCK_MAGICCloudflare unblock token
MJ_API_KEYMailjet API key, for sending alert emails (mailjet.com)
MJ_API_SECRETMailjet API secret

For local development you can set these to any placeholder value; the defaults in docker-compose.yml show the expected format.

Redis (rate limiting & state)

VariableDefaultNotes
REDIS_HOSTlocalhostRedis host
REDIS_PORT6379Redis port
REDIS_DB0Redis database number
REDIS_PASSWORD(none)Set if your Redis requires auth

Google Cloud (Datastore & Pub/Sub)

VariableDefaultNotes
PROJECT_ID(none)GCP project ID
DATASTORE_EMULATOR_HOST(none)Point at the local emulator, e.g. localhost:8000
TOPIC_ID(none)Pub/Sub topic for the live-visitor globe feed

Optional

VariableDefaultNotes
ENVIRONMENTproductionproduction or development
BASE_URLhttps://api.xposedornot.comPublic base URL used in links
PORT8080Port the server listens on
ENABLE_SCHEDULERfalseRun the background digest scheduler
DEBUG_EMAIL(none)Override recipient for debug emails
SENIORITY_ENRICH_URL / SENIORITY_ENRICH_SECRET(none)External seniority-enrichment service
DOMAIN_EMAIL_LIMITS_ENABLEDtrueKill switch for domain email verification anti-bombing limits
DOMAIN_EMAIL_RECIPIENT_COOLDOWN_SECONDS900Cooldown between challenges to the same role address
DOMAIN_EMAIL_DOMAIN_MAX_PER_HOUR5Max verification emails per domain per hour
DOMAIN_EMAIL_IP_MAX_PER_HOUR10Max verification emails per client IP per hour
DOMAIN_EMAIL_GLOBAL_DAILY_BUDGET2000Global daily cap on verification emails

Contributing

Please read CONTRIBUTING.md for details on our code of conduct, and the process for submitting pull requests to us.

Authors

License

This project is licensed under the MIT License - see the LICENSE file for details

Acknowledgments

  • Thanks to the Python community and the maintainers of every library this project leans on. XposedOrNot stands on your work.

  • And to everyone who has reviewed the code and reported issues: thank you. A second set of eyes catches what I can't.

Show Your Support

If this saved you some trouble, a few things genuinely help:

  • ⭐ Star the repo so others can find it
  • Fork it and send a pull request; contributions are welcome
  • Share it with someone who'd find it useful

來源:README.md,提交 0c7f747

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v2.0.0最新Oct 3, 2026