XposedOrNot API
MCP serverDatabases & dataLets your agent check whether an email address or domain has appeared in known data breaches.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use XposedOrNot API to check email breaches
About this server
Real-time data-breach lookup and analytics for emails and domains from XposedOrNot.
Install XposedOrNot API
The server’s own address, for the clients that take one directly. Or connect ahel once and every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.
Claude Code
claude mcp add --transport http --scope user xposedornot-api 'https://api.xposedornot.com/mcp'Run it once in your project, then open /mcp to approve any sign-in the server asks for.
Claude Desktop
https://api.xposedornot.com/mcpAdd a custom connector in Settings, paste this address, and approve the sign-in.
Cursor
cursor://anysphere.cursor-deeplink/mcp/install?name=xposedornot-api&config=eyJ1cmwiOiJodHRwczovL2FwaS54cG9zZWRvcm5vdC5jb20vbWNwIn0=Open the link and Cursor adds the server at that address.
ChatGPT
https://api.xposedornot.com/mcpIn Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.
Codex
codex mcp add xposedornot-api --url 'https://api.xposedornot.com/mcp'Run it once, then sign in with codex mcp login xposedornot-api if the server asks for an account.
From the project's README
As published by xposedornot/xposedornot-api in README.md.
What is XposedOrNot API?
Data breaches happen constantly, and most people only find out long after their email and passwords are already circulating. I built XposedOrNot so you don't have to wonder. Check an email or domain and know right away whether it's turned up in a known breach.
This repo is the API that powers it all: the breach lookups, the analytics, and the alerts. It's free to use, and it's open-source, so you can read exactly how every check works rather than taking my word for it.
Give it a try below, and if you find it useful, I'd love for you to build something with it.
Devanand Premkumar, creator of XposedOrNot
Quick Example
Check if an email has been exposed in data breaches:
curl https://api.xposedornot.com/v1/check-email/test@example.com
Response:
{
"breaches": [["Adobe", "LinkedIn"]],
"email": "test@example.com",
"status": "success"
}
Get detailed breach analytics:
curl "https://api.xposedornot.com/v1/breach-analytics?email=test@example.com"
Rate Limits & API Access
- No API key required for basic endpoints (
/v1/check-email,/v1/breach-analytics,/v1/breaches) - API key required for domain breach monitoring — see Domain endpoints & API keys for how to get and use one
Rate limits are applied per IP, per endpoint:
| Endpoint | Per second | Per hour | Per day |
|---|---|---|---|
GET /v1/check-email/{email} | 2 | 25 | 100 |
GET /v1/breach-analytics | 2 | 25 | 100 |
GET /v1/breaches | 2 | 50 | 100 |
POST /v1/domain-breaches/ | 2 | 25 | 50 |
When a limit is exceeded the API returns 429 Too Many Requests with a Retry-After
header (seconds) and a JSON body carrying retry_after and reset_time, so clients
can back off precisely.
Commercial use & higher rate limits
The free API above is for personal and low-volume use, and it stays free. If you're building a product on breach data or need more throughput, xonAPI+ offers paid plans from $5/month with rate limits up to 25,000 requests/minute, API-key access, and commercial support. It's the same breach data, and it's what keeps the free tier free.
For full documentation, see the API docs and the API playground.
API Endpoints
The full, always-current spec lives at /docs
(Swagger) and /openapi.json. The
endpoints you'll reach for most:
Breach lookups
| Method | Path | What it does |
|---|---|---|
| GET | /v1/check-email/{email} | Quick check: is this email in a known breach? |
| GET | /v1/breach-analytics?email= | Detailed breach analytics for an email |
| GET | /v1/breaches | List all known breaches (optional ?domain=) |
| GET | /v1/domain-breach-summary | Summary of breaches for a domain |
Stats & feeds
| Method | Path | What it does |
|---|---|---|
| GET | /v1/metrics | Top-level breach metrics |
| GET | /v1/metrics/detailed | Expanded metrics |
| GET | /v1/metrics/domain/{domain} | Metrics for a single domain |
| GET | /v1/analytics/pulse | Recent breach activity pulse |
| GET | /v1/xon-pulse | XposedOrNot activity feed |
| GET | /v1/rss | Breach updates as an RSS feed |
Domain endpoints & API keys
Breach data for a domain is only available once you've verified ownership of that domain, and calls are authenticated with an API key tied to your account.
Getting an API key — keys are issued and managed from the web console, not via a public endpoint:
- Sign in at xposedornot.com.
- Open your CxO Dashboard and verify the domain(s) you want to monitor.
- Go to API Key Management (linked from the dashboard). Your key is shown there; use Reset API Key to rotate it.
Using the key — pass it in the x-api-key header. The domain-breaches
endpoint takes no body; it returns breaches across all the domains you've
verified:
curl -L -X POST \
-H "x-api-key: <YOUR_API_KEY>" \
-H "Content-Length: 0" \
https://api.xposedornot.com/v1/domain-breaches/
An invalid key (or one with no verified domains) returns 401 Invalid or missing API key; omitting the x-api-key header entirely returns 422. See the
API docs for the full domain verification and
alert-subscription flows.
Use it from your AI tools (MCP)
XposedOrNot ships a built-in Model Context Protocol
server, so AI assistants can check breaches directly. Point your MCP client at
https://api.xposedornot.com/mcp (Streamable HTTP, JSON-RPC 2.0 over POST).
No API key or authentication is needed; all tools are read-only and never
return passwords.
Tools exposed:
check_email_breaches: check if an email appears in any known breachget_breach_analytics: detailed breach history, risk score and paste exposure for an emaillist_breaches: browse the breach catalog, filter by domain or breach IDdomain_breach_summary: aggregate breach counts for a domainget_breach_metrics: system-wide breach statisticsget_recent_breaches: most recently added breaches, newest first
Quick connect:
claude mcp add --transport http xposedornot https://api.xposedornot.com/mcp
For Cline, Cursor, Gemini CLI and other clients, see
llms-install.md. A machine-readable server card is at
https://api.xposedornot.com/.well-known/mcp/server-card.json.
A quick tools/list call:
curl -X POST https://api.xposedornot.com/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
Why use XposedOrNot API?
XposedOrNot was the first open-source tool to monitor and alert on data breaches, and this API gives you direct access to everything it has collected and keeps current. With it you can:
- Check whether an email has appeared in a known data breach, with stats on where and when
- See if an email shows up in public pastes
- Run a single combined search across both breaches and pastes
- Check whether a password has been exposed without ever revealing your identity
Prefer to just look something up without writing code? You can do all of this on the website too: https://xposedornot.com.
Security
This project is fully open-source and uses automated security tooling (Black, Pylint, CodeQL, OpenSSF Scorecard). For security details, see SECURITY.md.
Please do not report security vulnerabilities through public GitHub issues. Instead, refer to our Responsible Disclosure Guidelines for reporting these issues in a secure manner.
Prerequisites
- Docker (recommended): Docker 20.10+ and Docker Compose V2
- Local install: Python 3.11+, Google Cloud SDK
Quick Start for Local Development
Using Docker Compose (Recommended)
-
Clone the Repository:
git clone https://github.com/XposedOrNot/XposedOrNot-API -
Update the necessary environment variables in the docker-compose.yml file if needed, then run:
docker compose upThis command will build API and Datastore Docker images. Note that the project source directory is mapped in the Docker container, so any changes in the source code won't require rebuilding the Docker image.
Local Installation
-
Clone the Repository:
git clone https://github.com/XposedOrNot/XposedOrNot-API -
Install Required Packages
sudo apt-get install -y python3-pip build-essential libffi-dev python3-devThen install the gcloud CLI — it's not in the stock Debian/Ubuntu repositories and is needed for step 4 (Datastore authentication or the local emulator).
-
Install Python Libraries
pip3 install -r requirements.txt -
Setup Google Cloud Datastore
Before running XposedOrNot-API, choose one of the following options:
-
Run local Google DataStore emulator and debug using the local emulator rather than directly connect to Google DataStore.
# For posix platforms, e.g. linux, mac: gcloud beta emulators datastore start -
Authenticate to Google DataStore and directly debug using Google DataStore.
-
Run the application
python3 main.py
Configuration
Configuration is read from environment variables. For Docker Compose these are
already set in docker-compose.yml; for a local install, copy .env.example to
.env and fill in the values (or export them in your shell).
Required (the app won't start without these)
| Variable | What it's for |
|---|---|
SECRET_APIKEY | Secret used to sign issued API keys |
SECURITY_SALT | Salt for signing verification tokens |
WTF_CSRF_SECRET_KEY | CSRF protection secret |
ENCRYPTION_KEY | Fernet key for encrypting stored data |
AUTH_EMAIL | Cloudflare account email |
AUTHKEY | Cloudflare API key |
CF_MAGIC | Cloudflare integration token |
CF_UNBLOCK_MAGIC | Cloudflare unblock token |
MJ_API_KEY | Mailjet API key, for sending alert emails (mailjet.com) |
MJ_API_SECRET | Mailjet API secret |
For local development you can set these to any placeholder value; the defaults in
docker-compose.ymlshow the expected format.
Redis (rate limiting & state)
| Variable | Default | Notes |
|---|---|---|
REDIS_HOST | localhost | Redis host |
REDIS_PORT | 6379 | Redis port |
REDIS_DB | 0 | Redis database number |
REDIS_PASSWORD | (none) | Set if your Redis requires auth |
Google Cloud (Datastore & Pub/Sub)
| Variable | Default | Notes |
|---|---|---|
PROJECT_ID | (none) | GCP project ID |
DATASTORE_EMULATOR_HOST | (none) | Point at the local emulator, e.g. localhost:8000 |
TOPIC_ID | (none) | Pub/Sub topic for the live-visitor globe feed |
Optional
| Variable | Default | Notes |
|---|---|---|
ENVIRONMENT | production | production or development |
BASE_URL | https://api.xposedornot.com | Public base URL used in links |
PORT | 8080 | Port the server listens on |
ENABLE_SCHEDULER | false | Run the background digest scheduler |
DEBUG_EMAIL | (none) | Override recipient for debug emails |
SENIORITY_ENRICH_URL / SENIORITY_ENRICH_SECRET | (none) | External seniority-enrichment service |
DOMAIN_EMAIL_LIMITS_ENABLED | true | Kill switch for domain email verification anti-bombing limits |
DOMAIN_EMAIL_RECIPIENT_COOLDOWN_SECONDS | 900 | Cooldown between challenges to the same role address |
DOMAIN_EMAIL_DOMAIN_MAX_PER_HOUR | 5 | Max verification emails per domain per hour |
DOMAIN_EMAIL_IP_MAX_PER_HOUR | 10 | Max verification emails per client IP per hour |
DOMAIN_EMAIL_GLOBAL_DAILY_BUDGET | 2000 | Global daily cap on verification emails |
Contributing
Please read CONTRIBUTING.md for details on our code of conduct, and the process for submitting pull requests to us.
Authors
- Devanand Premkumar - Initial work - DevaOnBreaches
License
This project is licensed under the MIT License - see the LICENSE file for details
Acknowledgments
-
Thanks to the Python community and the maintainers of every library this project leans on. XposedOrNot stands on your work.
-
And to everyone who has reviewed the code and reported issues: thank you. A second set of eyes catches what I can't.
Show Your Support
If this saved you some trouble, a few things genuinely help:
- ⭐ Star the repo so others can find it
- Fork it and send a pull request; contributions are welcome
- Share it with someone who'd find it useful
Tools it offers (6)
What this server listed when ahel dialed its public endpoint in Oct 2026, with no key and no account of yours. The names are the server’s own.
check_email_breachesget_breach_analyticslist_breachesdomain_breach_summaryget_breach_metricsget_recent_breaches
Signals
- GitHub stars
- 98
- Forks
- 9
- Last commit
- Oct 2026
Advanced
- Delivery
- xposedornot MCP server → your ahel connector (mcp.ahel.ai) → your AI.
- Item type
- mcp-server
- Key
com-xposedornot-xposedornot- Source
- github.com/xposedornot/xposedornot-api
- Hosted endpoint
https://api.xposedornot.com/mcp
github.com/xposedornot/xposedornot-api
More in Databases & data
MCP server
More in Databases & dataAIOProductOS MCP
MCP server · aioproductos
More in Databases & dataQuantRisk
MCP server · 78degrees
More in Databases & dataPostHog MCP Server
MCP server · posthog
More in Databases & dataRun402
MCP server · kychee-com
More in Databases & dataagent-native-analytics
MCP server · builderio
More in Databases & data