xonPlus Logo
Used by Verosint, BlackDice & production apps worldwide

The Data Breach API You Can Ship in Hours

REST API with <100ms response. Official SDKs in 8 languages included. Plans from $5/mo.

curl -H "x-api-key: YOUR_KEY" https://plus-api.xposedornot.com/v3/check-email/[email protected]
11.5B+ breach records<100ms response99.99% uptime

Want to test the data first? Try a free domain check

The Breach Data Behind the API

11.5B+
Breach records indexed
Daily
New breach data indexed
Zero
PII stored or logged
3-6 Months

Typical time to build breach detection from scratch

The Engineering Burden

Your users expect you to detect compromised accounts. But sourcing breach data is legally complex, parsing breach dumps requires specialized infrastructure, and maintaining a real-time index of 11.5B+ records is a full-time engineering project.

The Opportunity Cost

Building it in-house takes 3-6 months and a dedicated team. Buying from legacy vendors means $5K+/mo and a sales cycle longer than your sprint. Meanwhile, account takeover attacks hit your users every day you wait.

xonPlus API gives you a single endpoint, <100ms response, and full breach coverage. Ship breach detection in hours, not months.

Your Devs Will Love It. Your Legal Team Will Approve It.

Production-ready breach detection: fast to integrate, safe to deploy, priced to scale

Deploy in Under 5 Minutes

One endpoint, one header, plug-and-play SDKs for Python and Node.js. No SDK quirks, no proprietary protocols. Just HTTPS and JSON.

Privacy by Design

Stateless lookups. We never store or log submitted emails. TLS 1.3, US-based infrastructure on SOC 2-certified Google Cloud.

Complete Breach Data

Each match returns the breach source, date, exposed fields, record count, and password-risk classification. Not just a yes/no.

Built for Scale

From 50 requests/min prototypes to 25,000 requests/min production workloads, with flat monthly pricing and no surprise overage fees.

See the API in Action

Live request examples, response formats, and your usage dashboard

API Usage Dashboard

API Documentation

cURL Request

curl -X GET "https://plus-api.xposedornot.com/v3/check-email/[email protected]?detailed=true" \
  -H "x-api-key: APIKEY" \
  -H "Content-Type: application/json"

Python Request

import requests

url = "https://plus-api.xposedornot.com/v3/check-email/[email protected]"
headers = {
    "x-api-key": "APIKEY",
    "Content-Type": "application/json"
}
params = {
    "detailed": "true"
}

response = requests.get(url, headers=headers, params=params)
result = response.json()
print(result)

What customers are saying

Verified reviews from G2

4.9on G2
S

Sundar Kumar

IT and Product Head, Corent Technology

"Xposedornot is a useful tool for data breach alerting system. Every organization requires this tool to receive timely alerts of their exposed breaches. Its user-friendly design and seamless integration make it a valuable asset for proactive data security."

M

Miguel Mendes

IT Security Lead, Bluecom

"Indispensable to monitor the exposure of your personal data. What I like most about ExposedOrNot is its real-time dashboard alerts, as well as integration with Slack and Teams, are very practical features to be informed immediately in the event of a compromise."

B

Bertold Kolics

VP Engineering, Verosint

"I have been working with XposedOrNot from the early days. My experience could not have been better. The service scales well, performs well under high load and it has a large set of breach data dating back to several years."

S

Senthil K

Information Security Officer, Invicara

"I love how XposedOrNot makes protecting our data so simple and effective from ATO. The alerts are timely, and the CXO dashboard gives a clear picture of breach trends and risks. It's more than just a tool, it's like having a personal assistant for your security."

Three Lines of Code. That's It.

Get your API key, make a request, use the data

const res = await fetch('https://plus-api.xposedornot.com/v3/check-email/[email protected]?detailed=true', { headers: { 'x-api-key': 'YOUR_API_KEY' } });
const { breaches } = await res.json();
// breaches: [{ breach_id: 'Wanelo', breached_date: '2018-12-01...', xposed_data: 'Emails;Passwords', ... }]
<100ms response

Pick a Plan & Get Your API Key

Subscribe to any plan from $5/mo. Your API key is provisioned instantly in the console.

Make a Request

Query by email, domain, or phone. Get results in under 100ms from any region.

Use the Data

Receive structured JSON with breach names, dates, exposed fields, and risk scores.

Works With Every Stack

Python, Node.js, Go, Java. If it speaks HTTP, it works with xonAPI+

Developer-First Integration

One API key. One endpoint. Full breach data in a single GET request. Python and Node.js SDKs included.

5minsetup time with
our quick start guide

What makes integration simple

  • Multiple Language Support

    JavaScript, Python, Go, Java, and more

  • Complete Documentation

    Detailed Swagger docs, and interactive examples

  • Production Ready

    Per-key rate limits, key rotation, and request-level audit logging

Start Free. Upgrade for Production.

The free community API checks your own exposure. xonAPI+ powers your product.

Community API — freexonAPI+ — from $5/mo
check-email throughput2/sec burst · capped at 5/hour, 100/day per IP50 to 25,000 req/min sustained, no daily cap
AccessKeyless, per-IP, fair-use enforcedAPI keys with IP scoping, rotation, audit logs
Response detailBasic breach checkBreach source, dates, exposed fields, password-risk
ReliabilityBest effort99.99% independently monitored, credit-backed tiers
Webhooks, batch & domain endpointsIncluded by tier
SupportCommunityNext-business-day to 4-business-hour response

Checking your own exposure? Use the free community API — no key, no signup. Building a product? Every paid plan is production-ready from day one, backed by a measured uptime SLA.

Pay for What You Use, Starting at $5/mo

No query surprises. No overage fees. Upgrade or cancel anytime.

Basic

$5.00/mo
$5.00 billed every month
Up to 50 requests/min
JSON + structured responses
Official SDKs in 8 languages
Perfect for testing & prototypes
Cancel anytime

Growth

$21.00/mo
$21.00 billed every month
Up to 250 requests/min
JSON + structured responses
Official SDKs in 8 languages
Cancel anytime
MOST POPULAR

Ultimate

$73.00/mo
$73.00 billed every month
Up to 1,250 requests/min
Priority support (same-business-day response)
Webhook notifications
Batch endpoint access
Official SDKs in 8 languages

Scale

From $147/mo
Five volume tiers, up to 25,000 req/min
Five volume tiers: 2,500 to 25,000 requests/min
Priority support — first response within 4 business hours
Direct engineering support channel
Webhook notifications + batch endpoint access
TLS 1.3 in transit US-based infra Zero PII stored SOC 2-certified cloud infra

All plans include a 30-day money-back guarantee

Need custom volume?

Questions Developers Ask Before Integrating

Authentication, rate limits, data formats, and privacy

The xonAPI+ searches across 11.5B+ breach records from thousands of data breaches. New breach data lands daily and becomes searchable within 15 minutes of ingestion, giving you one of the largest and freshest breach databases available via a simple REST endpoint.

The API is stateless — we never log or store submitted email addresses. All requests are encrypted in transit via TLS 1.3. Infrastructure is hosted in US data centers with strict access controls, audit logging, and regular penetration testing. Our infrastructure runs on Google Cloud (SOC 2 and ISO 27001 certified); security documentation is available on request for procurement reviews.

Only from breaches already in the public domain — public disclosures, paste sites, and dumps that have surfaced on public channels — verified before indexing and never purchased from threat actors. Responses return exposure facts (breach name, date, exposed data categories, risk), never raw stolen records. Full sourcing and verification policy: plus.xposedornot.com/our-data.

Our API delivers responses in under 100ms globally, with edge distribution ensuring minimal latency. High-volume requests use our optimized batch endpoints for even greater efficiency.

The API returns standardized JSON responses with options for hierarchical or flattened data structures. Responses include breach details, timestamps, and severity indicators for easy integration.

We use API keys with optional IP restrictions, environment-specific access, and request rate limiting. Keys can be rotated, revoked, and managed through our developer dashboard.

We don't offer a free trial, but every plan ships with a 30-day money-back guarantee. Subscribe to any tier, start building against the live API immediately, and if it's not the right fit within 30 days, request a full refund — no questions asked. For a feel of the data before subscribing, the free community API covers personal exposure checks.

The free community API is built for individuals checking their own exposure: it allows short bursts (2 requests/second) but is capped at 5 checks per hour and 100 per day per IP. xonAPI+ is built for production use — sustained throughput from 50 to 25,000 requests per minute, API keys with IP scoping and audit logs, detailed responses with breach source and password-risk, webhooks and batch endpoints, a 99.99% independently monitored uptime SLA, and a support response ladder.

Yes, no long-term contracts required. All plans are month-to-month, and you can cancel anytime from your dashboard. You won't be charged for the next billing cycle.

Yes! Higher-tier plans offer better per-request rates. Enterprise customers can contact us for custom volume pricing with significant discounts for high-volume implementations.

Plans are priced by peak request rate, not monthly volume. Tiers start at 50 requests/min ($5/mo) and scale to 25,000 requests/min, with custom pricing above that. Pick based on your peak burst, not your monthly total.

Our RESTful API works with any programming language using standard HTTPS and JSON. Official SDKs are available in 8 languages — JavaScript (npm), Python (PyPI), Go, Ruby, PHP, Rust, C#/.NET, and Java — all supporting API-key auth for detailed paid-tier responses. Our documentation provides clear request and response examples for quick integration.

If you exceed your plan's rate limit, the API returns a 429 (Too Many Requests) status code. You can retry after a brief cooldown period. Check our documentation for rate limit headers and best practices for handling limits gracefully in your application.

Our API infrastructure is hosted in the United States with edge caching for global performance. All data processing and storage occurs in US-based data centers.

Your First API Call Is 15 Minutes Away

Live in 15 minutes. 30-day money-back guarantee.