---
title: "Export unlocked combolist credentials"
method: POST
path: "/profile/unlocked/combolists/export"
tags: ["Unlocked Combolists"]
---

# Export unlocked combolist credentials

`POST /profile/unlocked/combolists/export`

Export the Combolist credentials you have already unlocked, as a background job.

**Scope**
- Only your unlocked pairs, never the locked ones. To widen the set, unlock first with `POST /search/combolist/unlock/task`.
- The body takes the same filters as `GET /profile/unlocked/combolists` (`search`, `is_email`, `list_id`, `list_none`, `status`, `unlocked_at_min`), so what you see in the list is what the file contains.
- `unlocked_at_min` is the incremental hook: pass the timestamp of your last successful export to get only what came after. It must carry a timezone.
- `filters` takes the advanced set of `POST /profile/unlocked/combolists/advanced`. Send it to export exactly the rows that advanced listing shows.

**Separate from unlocked leaks**
This export never contains a stealer-log record. Its counterpart is `POST /profile/unlocked/export`.

**Limits**
- Formats: `csv`, `txt`, `json`.
- At most 5 exports pending or in progress per account, all types combined.
- An identical export already queued is refused rather than duplicated.

**Retrieval**
The response carries an `export_id`. Follow it and download the file from the Exports endpoints.

## Query parameters

- `format` 'csv' | 'txt' | 'json'

## Request body

- CombolistUnlockedExportRequest
  - `search` string, nullable
  - `is_email` boolean, nullable
  - `list_id` integer, nullable
  - `list_none` boolean
  - `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk', nullable
  - `unlocked_at_min` string, date-time, nullable
  - `filters` CombolistAdvancedSearchRequest — Combolist filters. Text is literal; only match_type adds operators. Characters such as *, ? and backslash are searched as written.
    - `username` string[], nullable
    - `username_not` string[], nullable
    - `username_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `username_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `password` string[], nullable
    - `password_not` string[], nullable
    - `password_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `password_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `email_domain` string[], nullable
    - `email_domain_not` string[], nullable
    - `email_domain_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `email_domain_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `username_hash` string[], nullable
    - `password_hash` string[], nullable
    - `is_email` boolean, nullable
    - `password_strength` 'too_weak' | 'weak' | 'medium' | 'strong'
    - `added_from` string, date-time, nullable
    - `added_to` string, date-time, nullable
    - `force_and` boolean

## Response `200`

Export queued.

- ExportResponse
  - `status` string, required — Export job status: 'queued', 'processing', 'completed', or 'failed'.
  - `message` string, required — Human-readable status message.
  - `export_id` integer, required — ID of the export job. Use this to check status or download the result.

## Other responses

- `400` — Too many exports already in progress.
- `401` — Authentication required, or invalid/expired API key.
- `404` — Combolist search is not enabled on this deployment.
- `409` — An identical export is already queued.
- `422` — Validation error, including `unlocked_at_min` without a timezone.
- `429` — Rate limit exceeded. See Retry-After / X-RateLimit-* headers.

## Changes

- **2026-09-04** `eb219e94d077` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/leakradar/apis/leakradar-io-api/changes/profile/unlocked/combolists/export/post.md)

---

[API](https://skmtc.dev/leakradar/apis/leakradar-io-api.md) · [All operations](https://skmtc.dev/leakradar/apis/leakradar-io-api/llms.txt) · [OpenAPI document](https://skmtc.dev/leakradar/apis/leakradar-io-api/revisions/99aaaa4fbeb1?raw)
