Unlocked Combolists

List unlocked combolist credentials

List the Combolist credentials you have unlocked, in clear.

Separate from unlocked leaks This space is disjoint from GET /profile/unlocked: a pair unlocked from a combolist search never shows up there, and a stealer-log record never shows up here. Unlocked lists, however, are shared between the two datasets.

Filters

  • search matches on username or password.
  • is_email splits email identifiers from username-only ones.
  • list_id and list_none are mutually exclusive.
  • status is the remediation status you set on the record.
  • unlocked_at_min keeps only what you unlocked at or after that instant, which is how you page an incremental sync. It must carry a timezone.

Pagination

  • page starts at 1.
  • page_size is 1 to 1000 (default 100).

Response PaginatedUnlockedCombolistsResponse. total is the filtered count and total_unlocked the unfiltered one, so a client can show "x of y" without a second call.

get/profile/unlocked/combolists

Query parameters

pageinteger

Page number (starts at 1).

Page number (starts at 1).

page_sizeinteger

Items per page (1-1000, default 100).

Items per page (1-1000, default 100).

searchstring nullable

Filter on username or password.

Filter on username or password.

is_emailboolean nullable

true keeps only email identifiers, false only username-only pairs. Omit for both.

true keeps only email identifiers, false only username-only pairs. Omit for both.

list_idinteger nullable

Keep only the records assigned to this list.

Keep only the records assigned to this list.

list_noneboolean

Keep only the records with no list assigned.

Keep only the records with no list assigned.

status'new' | 'in_progress' | 'fixed' | 'accepted_risk' nullable

Keep only the records in this remediation status.

Keep only the records in this remediation status.

unlocked_at_minstring date-time nullable

Keep only what was unlocked at or after this instant. Must carry a timezone, for example 2026-09-01T00:00:00Z.

Keep only what was unlocked at or after this instant. Must carry a timezone, for example 2026-09-01T00:00:00Z.

Response

Unlocked credentials returned.

totalinteger required

Records matching the filters.

total_unlockedinteger required

Records you have unlocked in total, filters ignored.

pageinteger required
page_sizeinteger required

Changes

Changed in 1 of the 8 revisions of this API.1