---
title: "List unlocked combolist credentials with advanced filters"
method: POST
path: "/profile/unlocked/combolists/advanced"
tags: ["Unlocked Combolists"]
---

# List unlocked combolist credentials with advanced filters

`POST /profile/unlocked/combolists/advanced`

Same listing as `GET /profile/unlocked/combolists`, with the advanced filter set applied on top.

**Filters**
- `filters` takes the same contract as `POST /search/combolist/advanced`: `username`, `password`, `email_domain` with their `_not` and `_match_type` variants, the hash prefixes, `is_email`, `password_strength`, `added_from`, `added_to` and `force_and`. There is no `url` filter, combolist records carry no URL.
- The unlocked-specific filters (`search`, `is_email`, `list_id`, `list_none`, `status`, `unlocked_at_min`) still apply and combine with AND.
- `filters` is optional: an empty set behaves exactly like the global listing.

**Why POST**
The body reuses the advanced search contract verbatim rather than a second query-string parser that could drift from it.

**Export**
`POST /profile/unlocked/combolists/export` takes the same `filters`, so the file holds exactly the rows this listing shows.

## Query parameters

- `page` integer — Page number (starts at 1).
- `page_size` integer — Items per page (1-1000, default 100).

## Request body

- CombolistUnlockedAdvancedRequest — Advanced listing over your unlocked combolist credentials. Same fields as the export request minus the output format, so the listing and the export of a given advanced view select rigorously the same rows. `filters` stays optional: the front toggles into advanced mode before the user has filled anything, and an empty set must behave like the global listing rather than error.
  - `search` string, nullable
  - `is_email` boolean, nullable
  - `list_id` integer, nullable
  - `list_none` boolean
  - `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk', nullable
  - `unlocked_at_min` string, date-time, nullable
  - `filters` CombolistAdvancedSearchRequest — Combolist filters. Text is literal; only match_type adds operators. Characters such as *, ? and backslash are searched as written.
    - `username` string[], nullable
    - `username_not` string[], nullable
    - `username_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `username_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `password` string[], nullable
    - `password_not` string[], nullable
    - `password_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `password_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `email_domain` string[], nullable
    - `email_domain_not` string[], nullable
    - `email_domain_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `email_domain_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `username_hash` string[], nullable
    - `password_hash` string[], nullable
    - `is_email` boolean, nullable
    - `password_strength` 'too_weak' | 'weak' | 'medium' | 'strong'
    - `added_from` string, date-time, nullable
    - `added_to` string, date-time, nullable
    - `force_and` boolean

## Response `200`

Unlocked credentials returned.

- PaginatedUnlockedCombolistsResponse
  - `items` CombolistUnlockedDetails[], required
    - `id` string, required
    - `username` string, required
    - `password` string, nullable
    - `password_strength` integer
    - `is_email` boolean, required
    - `email_domain` string, nullable
    - `added_at` string, date-time, required
    - `unlocked_at` string, date-time, required
    - `auto_unlocked` boolean
    - `auto_unlocked_by` integer, nullable
    - `list_id` integer, nullable
    - `comment` string, nullable
    - `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk'
    - `dataset` 'combolist'
    - `unlocked` true
  - `total` integer, required — Records matching the filters.
  - `total_unlocked` integer, required — Records you have unlocked in total, filters ignored.
  - `page` integer, required
  - `page_size` integer, required

## Other responses

- `401` — Authentication required, or invalid/expired API key.
- `404` — Combolist search is not enabled on this deployment, the list does not exist, or the page is out of range.
- `422` — Validation error, including a filter field absent from the combolist mapping.
- `429` — Rate limit exceeded. See Retry-After / X-RateLimit-* headers.

## Changes

- **2026-09-04** `eb219e94d077` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/leakradar/apis/leakradar-io-api/changes/profile/unlocked/combolists/advanced/post.md)

---

[API](https://skmtc.dev/leakradar/apis/leakradar-io-api.md) · [All operations](https://skmtc.dev/leakradar/apis/leakradar-io-api/llms.txt) · [OpenAPI document](https://skmtc.dev/leakradar/apis/leakradar-io-api/revisions/99aaaa4fbeb1?raw)
