Search Combolists

Search combolists with mapping-safe advanced filters

Combine multiple filters over the Combolists dataset. Provide the filters in the JSON body.

Filterable fields Only the fields that exist in the combolist mapping are accepted, which is a strict subset of stealer-log advanced search: username, password, email_domain (each with a _not variant and a _match_type of contains, starts_with or ends_with), username_hash, password_hash, is_email, password_strength, added_from, added_to and force_and. There is no url filter: combolist records carry no URL. Sending a stealer-only field is a 422 rather than a silently ignored filter.

Boolean logic

  • Values inside one field are OR by default; force_and=true requires every positive value of the same field to match. Excluded values stay OR whatever the setting.
  • Different fields are always AND.

Pagination

  • page starts at 1.
  • page_size is 1 to 1000 (default 100).
  • Deep interactive paging is capped. Past the offset limit the call answers 400 and you should queue POST /search/combolist/export.

Rate limit This endpoint counts as a heavy search: it is bound by the advanced per-second limit and by your plan's concurrent heavy search slots, not by the lighter limit of the email and domain endpoints.

Access and visibility

  • The Combolists dataset is sold from the Enterprise tier upwards. Without it the search still runs, but identifiers come back masked, passwords are omitted and item IDs are not returned.

Auto-unlock Pass auto_unlock=true to unlock the locked pairs of the current page. 1 point per newly unlocked pair, partial unlock on insufficient balance, amount reported in auto_unlock_points_consumed.

Response CombolistSearchResponse with items, total, total_unlocked, page, page_size.

post/search/combolist/advanced

Query parameters

pageinteger

Page number (starts at 1).

Page number (starts at 1).

page_sizeinteger

Items per page (1-1000, default 100).

Items per page (1-1000, default 100).

auto_unlockboolean

Automatically unlock the locked credentials of the current page using your points.

Automatically unlock the locked credentials of the current page using your points.

Request body

usernamestring[] nullable
username_notstring[] nullable
username_match_type'contains' | 'starts_with' | 'ends_with'
username_not_match_type'contains' | 'starts_with' | 'ends_with'
passwordstring[] nullable
password_notstring[] nullable
password_match_type'contains' | 'starts_with' | 'ends_with'
password_not_match_type'contains' | 'starts_with' | 'ends_with'
email_domainstring[] nullable
email_domain_notstring[] nullable
email_domain_match_type'contains' | 'starts_with' | 'ends_with'
email_domain_not_match_type'contains' | 'starts_with' | 'ends_with'
username_hashstring[] nullable
password_hashstring[] nullable
is_emailboolean nullable
password_strength'too_weak' | 'weak' | 'medium' | 'strong'
added_fromstring date-time nullable
added_tostring date-time nullable
force_andboolean

Response

Search results successfully returned.

totalinteger required

Total pairs matching the query.

total_unlockedinteger required

How many of them you have already unlocked.

pageinteger required
page_sizeinteger required
blacklisted_valuestring nullable

Set instead of any result when the query matches one of your blacklist rules.

auto_unlock_points_consumedinteger

Points consumed by Combo auto-unlock on this request.

Example response

{
  "auto_unlock_points_consumed": 0,
  "items": [
    {
      "added_at": "2026-01-15T10:30:00Z",
      "dataset": "combolist",
      "email_domain": "example.com",
      "id": "cl1_9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c",
      "is_email": true,
      "password": "P@ssw0rd123",
      "password_strength": 6,
      "status": "new",
      "unlocked": true,
      "username": "john.doe@example.com"
    }
  ],
  "page": 1,
  "page_size": 100,
  "total": 128,
  "total_unlocked": 1
}

Changes

Changed in 1 of the 8 revisions of this API.1