---
title: "List unlocked combolist credentials"
method: GET
path: "/profile/unlocked/combolists"
tags: ["Unlocked Combolists"]
---

# List unlocked combolist credentials

`GET /profile/unlocked/combolists`

List the Combolist credentials you have unlocked, in clear.

**Separate from unlocked leaks**
This space is disjoint from `GET /profile/unlocked`: a pair unlocked from a combolist search never shows up there, and a stealer-log record never shows up here. Unlocked lists, however, are shared between the two datasets.

**Filters**
- `search` matches on username or password.
- `is_email` splits email identifiers from username-only ones.
- `list_id` and `list_none` are mutually exclusive.
- `status` is the remediation status you set on the record.
- `unlocked_at_min` keeps only what you unlocked at or after that instant, which is how you page an incremental sync. It must carry a timezone.

**Pagination**
- `page` starts at 1.
- `page_size` is 1 to 1000 (default 100).

**Response**
`PaginatedUnlockedCombolistsResponse`. `total` is the filtered count and `total_unlocked` the unfiltered one, so a client can show "x of y" without a second call.

## Query parameters

- `page` integer — Page number (starts at 1).
- `page_size` integer — Items per page (1-1000, default 100).
- `search` string, nullable — Filter on username or password.
- `is_email` boolean, nullable — `true` keeps only email identifiers, `false` only username-only pairs. Omit for both.
- `list_id` integer, nullable — Keep only the records assigned to this list.
- `list_none` boolean — Keep only the records with no list assigned.
- `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk', nullable — Keep only the records in this remediation status.
- `unlocked_at_min` string, date-time, nullable — Keep only what was unlocked at or after this instant. Must carry a timezone, for example `2026-09-01T00:00:00Z`.

## Response `200`

Unlocked credentials returned.

- PaginatedUnlockedCombolistsResponse
  - `items` CombolistUnlockedDetails[], required
    - `id` string, required
    - `username` string, required
    - `password` string, nullable
    - `password_strength` integer
    - `is_email` boolean, required
    - `email_domain` string, nullable
    - `added_at` string, date-time, required
    - `unlocked_at` string, date-time, required
    - `auto_unlocked` boolean
    - `auto_unlocked_by` integer, nullable
    - `list_id` integer, nullable
    - `comment` string, nullable
    - `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk'
    - `dataset` 'combolist'
    - `unlocked` true
  - `total` integer, required — Records matching the filters.
  - `total_unlocked` integer, required — Records you have unlocked in total, filters ignored.
  - `page` integer, required
  - `page_size` integer, required

## Other responses

- `401` — Authentication required, or invalid/expired API key.
- `404` — Combolist search is not enabled on this deployment.
- `422` — Validation error, including `unlocked_at_min` without a timezone.
- `429` — Rate limit exceeded. See Retry-After / X-RateLimit-* headers.

## Changes

- **2026-09-04** `eb219e94d077` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/leakradar/apis/leakradar-io-api/changes/profile/unlocked/combolists/get.md)

---

[API](https://skmtc.dev/leakradar/apis/leakradar-io-api.md) · [All operations](https://skmtc.dev/leakradar/apis/leakradar-io-api/llms.txt) · [OpenAPI document](https://skmtc.dev/leakradar/apis/leakradar-io-api/revisions/99aaaa4fbeb1?raw)
