Skip to main content
Glama
645,568 tools. Updated 2026-10-06 22:01

"Have I Been Pwned" matching MCP tools:

  • Has this password appeared in a dump? — Have I Been Pwned Pwned Passwords via k-anonymity: only a 5-char SHA-1 prefix leaves the server. Returns pwned + occurrence count and a GO/HOLD/STOP. Password is not stored. Email breach lookup not offered. Required input: password. Priced $0.005 per call over x402 on Base; send a prepaid x-credit-token header for unlimited calls, or get 1 free call/day per tool. No wallet or API key required.
    ConnectorNo auth
  • Checks whether a password appears in known data breaches (Have I Been Pwned) and how many times, using k-anonymity towards HIBP. Breach check only; password_check adds strength scoring and sends the password in a POST body.
    ConnectorNo auth
  • Check whether a domain appears in known public data breaches (via the Have I Been Pwned breach catalog). Returns matching breaches with dates, exposed data classes, and account counts. Domain-level only — no personal email is queried.
    ConnectorNo auth
  • Check whether an email address or domain appears in known credential-breach corpora (Have I Been Pwned), with the breaches and data classes exposed. Use when assessing account-takeover exposure. Costs $2 per call.
    ConnectorNo auth
  • List the cards on YOUR agency's CRM pipeline boards (Kanban), with each board's own stage names and card counts. Boards: lead, buyer, seller, tenant, nurture (each card is a contact) and property (each card is a listing). Stage names are whatever the agency renamed them to, so read them from the reply rather than assuming. Call with no pipeline for a summary of every board - use this to answer "what's in my pipeline?" or "how many buyers do I have?". Call with a pipeline for that board's cards, newest activity first. This is the board view. For enquiries that have just arrived and have not been worked yet, use my_leads instead. Returns the WHOLE agency's boards, not one agent's cards: CRM access belongs to the agency, not to a person. Requires a linked PropertyList account (or an agency API key); only ever returns the calling agency's own data.
    ConnectorNo auth

Matching MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    A Model Context Protocol (MCP) server that provides integration with the Have I Been Pwned API to check if your accounts or passwords have been compromised in data breaches.
    4
    2
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    面向 Codex、WorkBuddy 等 AI 工具的知你AI助手合并版 Skills,涵盖当前会话分诊、客户查询与画像、历史会话检索、客户分群和 API Key 用量查询,并连接个微、企微、视频号、微信小程序、公众号、服务号、微信客服、微信小店、抖音号、小红书、微博、网站及H5客服等渠道。
    MIT No Attribution

Matching MCP Connectors

  • could-have-been-email MCP — wraps StupidAPIs (keyless — no credential needed)

  • Have I Been Pwned MCP

  • Internal Coderbuds staff only. Record that a message was sent to a prospect — after it has actually been sent. **Only call this when you have been told it went out.** Recording a send is what moves a prospect from Sourced to Contacted, and a row that says "contacted" with nothing behind it is worse than one that says nothing: the next session skips it. Sending is not something you can do. If you have written an opener, save it with `save-prospect-draft` and wait to be told it was sent. A draft waiting on the row is folded into the record and cleared, so the same opener cannot go out twice.
    ConnectorOAuth
  • Check if SHA-1 hash appears in Have I Been Pwned (HIBP) breach dataset using k-anonymity (5-char prefix only, full hash never leaves tool). Use for password breach audits; read-only, no data stored. Companion OSINT investigation tools: hash_lookup (file-hash malware family lookup, different namespace), email_disposable (throwaway-mail signal on associated accounts), username_lookup (social-platform exposure on associated handles). Free: 30/hr, Pro: 500/hr. Returns {found, count}.
    ConnectorNo auth
  • Lists the Slack workspaces (teams) the user has connected in Slack Desktop. Start here for Slack — the workspace id it returns is what slack_list_channels / slack_read_channel_messages / slack_search_messages need. Reads from the local IndexedDB cache — no token needed. Only workspaces that have been synced to disk are returned.
    ConnectorOAuth
  • Rolodex overview: how many contacts the subscriber has, how many have a phone or email, and the top industries and tags. Answers "how many contacts do I have?" and "what industries are my contacts in?" Use get_contact_history to look up specific people.
    ConnectorNo auth
  • List invitations to the organization that have been sent but not yet accepted. Use it to confirm an invite_member call landed, or to find an `inviteId` for revoke_invite. Accepted invitations become members — see list_members. Returns [{ id, orgId, email, role, invitedById, createdAt }].
    ConnectorNo auth
  • Summarize the caller's unpaid invoices by how long they have been past due. This owner-scoped, read-only report is computed live; an invoice is overdue only when its status is sent and its due_date is before today. Balances are separated by currency, with no conversion or combined money total.
    ConnectorNo auth
  • Relay a signed Ethereum transaction to the Arbitrum network. The transaction must have been pre-signed by the caller using prepare_gmx_order output. This endpoint does NOT sign — it only broadcasts an already-signed transaction.
    Connector
    Destructive
    No auth
  • One-call snapshot of everything the account has "open": equity & freeCollateral, every open POSITION (with notional, unrealized PnL and estimated liquidation price), every active ORDER (resting + untriggered TP/SL), and account margin risk. Use this to answer "what do I have open?" or "how am I doing?" without worrying whether the user means orders or positions — it returns both.
    ConnectorNo auth
  • One-call snapshot of everything the account has "open": equity & freeCollateral, every open POSITION (with notional, unrealized PnL and estimated liquidation price), every active ORDER (resting + untriggered TP/SL), and account margin risk. Use this to answer "what do I have open?" or "how am I doing?" without worrying whether the user means orders or positions — it returns both.
    ConnectorNo auth
  • Look up everything the user has done for ONE exercise: all-time PR plus recent performance, across many sessions. USE FOR: - PR lookups — "what's my bench PR?", "have I ever squatted 315?". Returns the est. 1RM PR and the exact set it came from (date, weight, reps, RPE, banded vs unbanded, superset siblings, notes), plus rep-range bests (1RM/3RM/5RM/10RM). Banded and unbanded PRs are shown side-by-side when both exists. - Recent-activity questions — "how has my squat been lately?", "when did I last deadlift?". Returns the most recent N sessions containing the exercise, formatted like get_workout. - Trend questions — "am I getting stronger on incline DB press?". Includes a one-line delta of current best vs ~30-90 days ago. NOT for a full session (every exercise in one workout — use get_workout) or a date-window list regardless of exercise (use list_workouts). INFER — do not ask: exercise_name (take the user's words; resolves to canonical, or says so if never logged), recent_limit (default 10 sessions), since_date (optional — narrows only the Recent block; the PR is always all-time).
    ConnectorOAuth
  • Scores a password's strength (length, character variety, entropy as an upper bound, repeated patterns; passphrases are estimated per word) and, with check_breach=true, also looks it up in Have I Been Pwned breach data via k-anonymity (only a hash prefix is sent); a password found in breaches is always rated very_weak. Use it to evaluate a password someone is choosing; use password_breach when you only need the breach count, and password to generate a new one. The password travels in a POST body, never in a URL.
    ConnectorNo auth
  • Everything on file about one person, in sections: what they have done, who they work with, how they are spoken about, what they have written or said in public, and what has been in the news about them lately. Broader than a short brief and not written for any one purpose — this is the file, not the verdict. Use it for "tell me everything about her", "what am I walking into with this person", "is this creator worth working with", "background on him before the call". If you only need an email, ask for their contact details instead — that is far cheaper. If a short written assessment is what you want, ask for a brief. If the name matches more than one person you get the candidates and nothing is charged; nothing is charged when nobody matches.Costs 30 credits the first time, and nothing at all if you have looked this person up before.
    ConnectorNo auth
  • Pull the authenticated user's XP marketplace account card — profile, wallet, email, name, order history, and referral stats. Use when the user asks 'what have I bought from XP', 'my account', 'my tickets to past games', 'my orders', 'my referral link', or 'how much have I spent'. Returns the profile shown on the XP account page. Read-only; requires auth. Do not use for tickets currently delivered to the account; `get_my_tickets` is more direct.
    ConnectorOAuth
  • USE THIS TOOL WHEN you have a committee_id and want the metadata + current membership. Fetches committee detail and member list in parallel. AFTER calling, pass committee_id into committees_search_evidence to see what evidence has been submitted to this committee on what topics.
    ConnectorNo auth