Breached Password Hash Check

Check whether a password hash appears in the Have I Been Pwned breach corpus using k-anonymity: the caller sends only the first five hex characters of a SHA-1 hash, so no password or full hash ever leaves the caller. Returns the matching hash range, or a breach count when an optional suffix is supplied.

0.005 USDC / request GET live_source Base mainnet x402 v2

Preview request

The preview path is rate-limited and does not charge. Production requests use the same parameters and return a standard x402 challenge when no payment signature is present.

curl --request GET \
  "https://ai-data-marketplace-1042299154756.us-central1.run.app/api/v1/pwned_check?preview=true&prefix=21BD1"

Input contract

ParameterTypeRequiredDescription
prefixstringYesFirst 5 hex characters of the SHA-1 hash of the password to check. Only this prefix is sent upstream.
suffixstringNoOptional remaining 35 hex characters of the SHA-1 hash. When supplied, the response reports a direct breach count instead of the full range.

Example deliverable

This is the documented response shape, not a promise that live values will match the example. The paid request returns current or declared-source results using the same contract.

{
  "email": "john.doe@example.com",
  "breached": true,
  "breach_count": 2,
  "breaches": [
    {
      "name": "Collection #1",
      "date": "2019-01-17",
      "data_classes": [
        "Email addresses",
        "Passwords"
      ]
    },
    {
      "name": "LinkedIn",
      "date": "2012-05-05",
      "data_classes": [
        "Email addresses",
        "Passwords"
      ]
    }
  ]
}

Purchase decision

Buy when: the active task needs this product's structured result, its declared source and freshness are sufficient, and 0.005 USDC is within the buyer's authorized per-request limit.

Skip when: a cached result is sufficient, the source or fields do not satisfy the task, or the buyer has not authorized payment. Do not bypass wallet, budget, or user-approval policy.

Guaranteed response metadata

Every successful product response identifies how the result was produced. Product-specific output fields are documented in the paid OpenAPI contract and can be inspected through the preview request where available.

{
  "marketplace_metadata": {
    "data_mode": "live_source",
    "billable": true,
    "availability": "operational",
    "source": "Have I Been Pwned Pwned Passwords range API"
  }
}

Agent payment flow

Fast path: install the public MCP package, configure a dedicated low-balance Base buyer wallet and a maximum per-request spend, then call this tool with auto_pay: true. The client handles the challenge, local signature, settlement, and retry in one tool call.

npx -y dopaminedesk-ai-data-marketplace-mcp

X402_AUTO_PAY=true
X402_EVM_PRIVATE_KEY=<dedicated buyer wallet key>
X402_MAX_PAYMENT_USDC=0.25

tool input: { "auto_pay": true }

Manual path: request the product, read the base64 PAYMENT-REQUIRED challenge, sign with any compatible x402 v2 client, and retry with PAYMENT-SIGNATURE. A successful response includes PAYMENT-RESPONSE.