XposedOrNot API

MCP serverDatabases & data

Lets your agent check whether an email address or domain has appeared in known data breaches.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use XposedOrNot API to check email breaches

About this server

Real-time data-breach lookup and analytics for emails and domains from XposedOrNot.

Install XposedOrNot API

The server’s own address, for the clients that take one directly. Or connect ahel once and every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.

  • Claude Code

    claude mcp add --transport http --scope user xposedornot-api 'https://api.xposedornot.com/mcp'

    Run it once in your project, then open /mcp to approve any sign-in the server asks for.

  • Claude Desktop

    https://api.xposedornot.com/mcp

    Add a custom connector in Settings, paste this address, and approve the sign-in.

  • Cursor

    cursor://anysphere.cursor-deeplink/mcp/install?name=xposedornot-api&config=eyJ1cmwiOiJodHRwczovL2FwaS54cG9zZWRvcm5vdC5jb20vbWNwIn0=

    Open the link and Cursor adds the server at that address.

  • ChatGPT

    https://api.xposedornot.com/mcp

    In Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.

  • Codex

    codex mcp add xposedornot-api --url 'https://api.xposedornot.com/mcp'

    Run it once, then sign in with codex mcp login xposedornot-api if the server asks for an account.

From the project's README

As published by xposedornot/xposedornot-api in README.md.

What is XposedOrNot API?

Data breaches happen constantly, and most people only find out long after their email and passwords are already circulating. I built XposedOrNot so you don't have to wonder. Check an email or domain and know right away whether it's turned up in a known breach.

This repo is the API that powers it all: the breach lookups, the analytics, and the alerts. It's free to use, and it's open-source, so you can read exactly how every check works rather than taking my word for it.

Give it a try below, and if you find it useful, I'd love for you to build something with it.

Devanand Premkumar, creator of XposedOrNot

Quick Example

Check if an email has been exposed in data breaches:

curl https://api.xposedornot.com/v1/check-email/test@example.com

Response:

{
  "breaches": [["Adobe", "LinkedIn"]],
  "email": "test@example.com",
  "status": "success"
}

Get detailed breach analytics:

curl "https://api.xposedornot.com/v1/breach-analytics?email=test@example.com"

Rate Limits & API Access

  • No API key required for basic endpoints (/v1/check-email, /v1/breach-analytics, /v1/breaches)
  • API key required for domain breach monitoring — see Domain endpoints & API keys for how to get and use one

Rate limits are applied per IP, per endpoint:

EndpointPer secondPer hourPer day
GET /v1/check-email/{email}225100
GET /v1/breach-analytics225100
GET /v1/breaches250100
POST /v1/domain-breaches/22550

When a limit is exceeded the API returns 429 Too Many Requests with a Retry-After header (seconds) and a JSON body carrying retry_after and reset_time, so clients can back off precisely.

Commercial use & higher rate limits

The free API above is for personal and low-volume use, and it stays free. If you're building a product on breach data or need more throughput, xonAPI+ offers paid plans from $5/month with rate limits up to 25,000 requests/minute, API-key access, and commercial support. It's the same breach data, and it's what keeps the free tier free.

For full documentation, see the API docs and the API playground.

API Endpoints

The full, always-current spec lives at /docs (Swagger) and /openapi.json. The endpoints you'll reach for most:

Breach lookups

MethodPathWhat it does
GET/v1/check-email/{email}Quick check: is this email in a known breach?
GET/v1/breach-analytics?email=Detailed breach analytics for an email
GET/v1/breachesList all known breaches (optional ?domain=)
GET/v1/domain-breach-summarySummary of breaches for a domain

Stats & feeds

MethodPathWhat it does
GET/v1/metricsTop-level breach metrics
GET/v1/metrics/detailedExpanded metrics
GET/v1/metrics/domain/{domain}Metrics for a single domain
GET/v1/analytics/pulseRecent breach activity pulse
GET/v1/xon-pulseXposedOrNot activity feed
GET/v1/rssBreach updates as an RSS feed

Domain endpoints & API keys

Breach data for a domain is only available once you've verified ownership of that domain, and calls are authenticated with an API key tied to your account.

Getting an API key — keys are issued and managed from the web console, not via a public endpoint:

  1. Sign in at xposedornot.com.
  2. Open your CxO Dashboard and verify the domain(s) you want to monitor.
  3. Go to API Key Management (linked from the dashboard). Your key is shown there; use Reset API Key to rotate it.

Using the key — pass it in the x-api-key header. The domain-breaches endpoint takes no body; it returns breaches across all the domains you've verified:

curl -L -X POST \
  -H "x-api-key: <YOUR_API_KEY>" \
  -H "Content-Length: 0" \
  https://api.xposedornot.com/v1/domain-breaches/

An invalid key (or one with no verified domains) returns 401 Invalid or missing API key; omitting the x-api-key header entirely returns 422. See the API docs for the full domain verification and alert-subscription flows.

Use it from your AI tools (MCP)

XposedOrNot ships a built-in Model Context Protocol server, so AI assistants can check breaches directly. Point your MCP client at https://api.xposedornot.com/mcp (Streamable HTTP, JSON-RPC 2.0 over POST). No API key or authentication is needed; all tools are read-only and never return passwords.

Tools exposed:

  • check_email_breaches: check if an email appears in any known breach
  • get_breach_analytics: detailed breach history, risk score and paste exposure for an email
  • list_breaches: browse the breach catalog, filter by domain or breach ID
  • domain_breach_summary: aggregate breach counts for a domain
  • get_breach_metrics: system-wide breach statistics
  • get_recent_breaches: most recently added breaches, newest first

Quick connect:

claude mcp add --transport http xposedornot https://api.xposedornot.com/mcp

For Cline, Cursor, Gemini CLI and other clients, see llms-install.md. A machine-readable server card is at https://api.xposedornot.com/.well-known/mcp/server-card.json.

A quick tools/list call:

curl -X POST https://api.xposedornot.com/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Why use XposedOrNot API?

XposedOrNot was the first open-source tool to monitor and alert on data breaches, and this API gives you direct access to everything it has collected and keeps current. With it you can:

  • Check whether an email has appeared in a known data breach, with stats on where and when
  • See if an email shows up in public pastes
  • Run a single combined search across both breaches and pastes
  • Check whether a password has been exposed without ever revealing your identity

Prefer to just look something up without writing code? You can do all of this on the website too: https://xposedornot.com.

Security

This project is fully open-source and uses automated security tooling (Black, Pylint, CodeQL, OpenSSF Scorecard). For security details, see SECURITY.md.

Please do not report security vulnerabilities through public GitHub issues. Instead, refer to our Responsible Disclosure Guidelines for reporting these issues in a secure manner.

Prerequisites

  • Docker (recommended): Docker 20.10+ and Docker Compose V2
  • Local install: Python 3.11+, Google Cloud SDK

Quick Start for Local Development

Using Docker Compose (Recommended)

  1. Clone the Repository:

    git clone https://github.com/XposedOrNot/XposedOrNot-API
    
  2. Update the necessary environment variables in the docker-compose.yml file if needed, then run:

    docker compose up
    

    This command will build API and Datastore Docker images. Note that the project source directory is mapped in the Docker container, so any changes in the source code won't require rebuilding the Docker image.

Local Installation

  1. Clone the Repository:

    git clone https://github.com/XposedOrNot/XposedOrNot-API
    
  2. Install Required Packages

    sudo apt-get install -y python3-pip build-essential libffi-dev python3-dev
    

    Then install the gcloud CLI — it's not in the stock Debian/Ubuntu repositories and is needed for step 4 (Datastore authentication or the local emulator).

  3. Install Python Libraries

    pip3 install -r requirements.txt
    
  4. Setup Google Cloud Datastore

    Before running XposedOrNot-API, choose one of the following options:

  1. Run the application

    python3 main.py
    

Configuration

Configuration is read from environment variables. For Docker Compose these are already set in docker-compose.yml; for a local install, copy .env.example to .env and fill in the values (or export them in your shell).

Required (the app won't start without these)

VariableWhat it's for
SECRET_APIKEYSecret used to sign issued API keys
SECURITY_SALTSalt for signing verification tokens
WTF_CSRF_SECRET_KEYCSRF protection secret
ENCRYPTION_KEYFernet key for encrypting stored data
AUTH_EMAILCloudflare account email
AUTHKEYCloudflare API key
CF_MAGICCloudflare integration token
CF_UNBLOCK_MAGICCloudflare unblock token
MJ_API_KEYMailjet API key, for sending alert emails (mailjet.com)
MJ_API_SECRETMailjet API secret

For local development you can set these to any placeholder value; the defaults in docker-compose.yml show the expected format.

Redis (rate limiting & state)

VariableDefaultNotes
REDIS_HOSTlocalhostRedis host
REDIS_PORT6379Redis port
REDIS_DB0Redis database number
REDIS_PASSWORD(none)Set if your Redis requires auth

Google Cloud (Datastore & Pub/Sub)

VariableDefaultNotes
PROJECT_ID(none)GCP project ID
DATASTORE_EMULATOR_HOST(none)Point at the local emulator, e.g. localhost:8000
TOPIC_ID(none)Pub/Sub topic for the live-visitor globe feed

Optional

VariableDefaultNotes
ENVIRONMENTproductionproduction or development
BASE_URLhttps://api.xposedornot.comPublic base URL used in links
PORT8080Port the server listens on
ENABLE_SCHEDULERfalseRun the background digest scheduler
DEBUG_EMAIL(none)Override recipient for debug emails
SENIORITY_ENRICH_URL / SENIORITY_ENRICH_SECRET(none)External seniority-enrichment service
DOMAIN_EMAIL_LIMITS_ENABLEDtrueKill switch for domain email verification anti-bombing limits
DOMAIN_EMAIL_RECIPIENT_COOLDOWN_SECONDS900Cooldown between challenges to the same role address
DOMAIN_EMAIL_DOMAIN_MAX_PER_HOUR5Max verification emails per domain per hour
DOMAIN_EMAIL_IP_MAX_PER_HOUR10Max verification emails per client IP per hour
DOMAIN_EMAIL_GLOBAL_DAILY_BUDGET2000Global daily cap on verification emails

Contributing

Please read CONTRIBUTING.md for details on our code of conduct, and the process for submitting pull requests to us.

Authors

License

This project is licensed under the MIT License - see the LICENSE file for details

Acknowledgments

  • Thanks to the Python community and the maintainers of every library this project leans on. XposedOrNot stands on your work.

  • And to everyone who has reviewed the code and reported issues: thank you. A second set of eyes catches what I can't.

Show Your Support

If this saved you some trouble, a few things genuinely help:

  • ⭐ Star the repo so others can find it
  • Fork it and send a pull request; contributions are welcome
  • Share it with someone who'd find it useful

Tools it offers (6)

What this server listed when ahel dialed its public endpoint in Oct 2026, with no key and no account of yours. The names are the server’s own.

  • check_email_breaches
  • get_breach_analytics
  • list_breaches
  • domain_breach_summary
  • get_breach_metrics
  • get_recent_breaches

Signals

GitHub stars
98
Forks
9
Last commit
Oct 2026
Advanced
Delivery
xposedornot MCP server → your ahel connector (mcp.ahel.ai) → your AI.
Item type
mcp-server
Key
com-xposedornot-xposedornot
Source
github.com/xposedornot/xposedornot-api
Hosted endpoint
https://api.xposedornot.com/mcp