LeakData
Check breach exposure for your verified email and check locally computed password hash prefixes.
Community: Submitted by a user or imported; check the owner before granting accessOnlineNo sign-inGlobalFreeRead-only
What it can do
What data it sees
Do you need an account
No: the server works without sign-in
Check breach exposure for your verified email and check locally computed password hash prefixes.
Server tool list (2)
Raw names from tools/list. Only developers need these.
| leakdata.search | Use this when the linked LeakData user asks to check their verified primary email. For a current check, call this tool and report only its returned results. Never present earlier conversation results as a new check; if the call fails, say the check could not be completed. For their own email without an address, set type to email and omit query: the server resolves the verified primary email from the linked account. If the user supplies an email address, preserve it in query for ownership validation. Never guess an email address or recover it from earlier conversations when query can be omitted. Domain checks are not available through this app; explain this without calling a tool. Arbitrary third-party identifiers, usernames, phone numbers, raw leak records, and credentials are not returned. |
| leakdata.password_prefix_check | Call this only when the current user message supplies a locally computed five-character SHA-1 hash prefix and asks to check it. Never invent a prefix or reuse one from an earlier message. For general questions about password checks, explain local SHA-1 computation and sharing only its first five hexadecimal characters without calling a tool. Never accept a plaintext password or complete hash. Report only the aggregate values actually returned by this call. Results describe a prefix group only. A matching prefix does not establish whether a particular password is exposed. Do not report confirmed password exposure or recommend changing a password based only on this result. An empty group does not prove that a password is safe. |