List unlocked combolist credentials
List the Combolist credentials you have unlocked, in clear.
Separate from unlocked leaks This space is disjoint from GET /profile/unlocked: a pair unlocked from a combolist search never shows up there, and a stealer-log record never shows up here. Unlocked lists, however, are shared between the two datasets.
Filters
- search matches on username or password.
- is_email splits email identifiers from username-only ones.
- list_id and list_none are mutually exclusive.
- status is the remediation status you set on the record.
- unlocked_at_min keeps only what you unlocked at or after that instant, which is how you page an incremental sync. It must carry a timezone.
Pagination
- page starts at 1.
- page_size is 1 to 1000 (default 100).
Response PaginatedUnlockedCombolistsResponse. total is the filtered count and total_unlocked the unfiltered one, so a client can show "x of y" without a second call.
Query parameters
Page number (starts at 1).
Page number (starts at 1).
Items per page (1-1000, default 100).
Items per page (1-1000, default 100).
Filter on username or password.
Filter on username or password.
true keeps only email identifiers, false only username-only pairs. Omit for both.
true keeps only email identifiers, false only username-only pairs. Omit for both.
Keep only the records assigned to this list.
Keep only the records assigned to this list.
Keep only the records with no list assigned.
Keep only the records with no list assigned.
Keep only the records in this remediation status.
Keep only the records in this remediation status.
Keep only what was unlocked at or after this instant. Must carry a timezone, for example 2026-09-01T00:00:00Z.
Keep only what was unlocked at or after this instant. Must carry a timezone, for example 2026-09-01T00:00:00Z.
Response
Unlocked credentials returned.
Changes
Changed in 1 of the 8 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○