---
title: "Search combolists with mapping-safe advanced filters"
method: POST
path: "/search/combolist/advanced"
tags: ["Search Combolists"]
---

# Search combolists with mapping-safe advanced filters

`POST /search/combolist/advanced`

Combine multiple filters over the Combolists dataset. Provide the filters in the JSON body.

**Filterable fields**
Only the fields that exist in the combolist mapping are accepted, which is a strict subset of stealer-log advanced search: `username`, `password`, `email_domain` (each with a `_not` variant and a `_match_type` of `contains`, `starts_with` or `ends_with`), `username_hash`, `password_hash`, `is_email`, `password_strength`, `added_from`, `added_to` and `force_and`. There is no `url` filter: combolist records carry no URL. Sending a stealer-only field is a 422 rather than a silently ignored filter.

**Boolean logic**
- Values inside one field are OR by default; `force_and=true` requires every positive value of the same field to match. Excluded values stay OR whatever the setting.
- Different fields are always AND.

**Pagination**
- `page` starts at 1.
- `page_size` is 1 to 1000 (default 100).
- Deep interactive paging is capped. Past the offset limit the call answers 400 and you should queue `POST /search/combolist/export`.

**Rate limit**
This endpoint counts as a heavy search: it is bound by the advanced per-second limit and by your plan's concurrent heavy search slots, not by the lighter limit of the email and domain endpoints.

**Access and visibility**
- The Combolists dataset is sold from the Enterprise tier upwards. Without it the search still runs, but identifiers come back masked, passwords are omitted and item IDs are not returned.

**Auto-unlock**
Pass `auto_unlock=true` to unlock the locked pairs of the current page. 1 point per newly unlocked pair, partial unlock on insufficient balance, amount reported in `auto_unlock_points_consumed`.

**Response**
`CombolistSearchResponse` with `items`, `total`, `total_unlocked`, `page`, `page_size`.

## Query parameters

- `page` integer — Page number (starts at 1).
- `page_size` integer — Items per page (1-1000, default 100).
- `auto_unlock` boolean — Automatically unlock the locked credentials of the current page using your points.

## Request body

- CombolistAdvancedSearchRequest — Combolist filters. Text is literal; only match_type adds operators. Characters such as *, ? and backslash are searched as written.
  - `username` string[], nullable
  - `username_not` string[], nullable
  - `username_match_type` 'contains' | 'starts_with' | 'ends_with'
  - `username_not_match_type` 'contains' | 'starts_with' | 'ends_with'
  - `password` string[], nullable
  - `password_not` string[], nullable
  - `password_match_type` 'contains' | 'starts_with' | 'ends_with'
  - `password_not_match_type` 'contains' | 'starts_with' | 'ends_with'
  - `email_domain` string[], nullable
  - `email_domain_not` string[], nullable
  - `email_domain_match_type` 'contains' | 'starts_with' | 'ends_with'
  - `email_domain_not_match_type` 'contains' | 'starts_with' | 'ends_with'
  - `username_hash` string[], nullable
  - `password_hash` string[], nullable
  - `is_email` boolean, nullable
  - `password_strength` 'too_weak' | 'weak' | 'medium' | 'strong'
  - `added_from` string, date-time, nullable
  - `added_to` string, date-time, nullable
  - `force_and` boolean

## Response `200`

Search results successfully returned.

- CombolistSearchResponse
  - `items` CombolistCredentialDetails[], required
    - `id` string, nullable — Immutable combolist credential identifier. Hidden when the plan does not grant access to the selected search surface.
    - `username` string, nullable — Email address or username. Present only for unlocked rows.
    - `username_masked` string, nullable — Masked identifier shown while the credential is locked.
    - `password` string, nullable — Exact password. Present only for unlocked rows.
    - `password_strength` integer — Raw password-strength score.
    - `is_email` boolean, required — True for an email, false for a username.
    - `email_domain` string, nullable — Normalized domain, present only for email credentials.
    - `added_at` string, date-time, required — Date of the earliest accepted RawFile occurrence.
    - `unlocked` boolean — Whether the row is unlocked.
    - `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk', nullable — Remediation status, present only for unlocked rows.
    - `dataset` 'combolist' — Fixed provenance guard for this dedicated API.
  - `total` integer, required — Total pairs matching the query.
  - `total_unlocked` integer, required — How many of them you have already unlocked.
  - `page` integer, required
  - `page_size` integer, required
  - `blacklisted_value` string, nullable — Set instead of any result when the query matches one of your blacklist rules.
  - `auto_unlock_points_consumed` integer — Points consumed by Combo auto-unlock on this request.

## Other responses

- `400` — Pagination too deep for interactive search.
- `401` — Authentication required, or invalid/expired API key.
- `403` — Account banned, or pending email verification.
- `404` — Combolist search is not enabled on this deployment.
- `422` — Validation error, including a filter field absent from the combolist mapping.
- `429` — Rate limit exceeded. See Retry-After / X-RateLimit-* headers.
- `503` — Combolist search under maintenance, or public API temporarily disabled.

## Changes

- **2026-09-04** `eb219e94d077` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/leakradar/apis/leakradar-io-api/changes/search/combolist/advanced/post.md)

---

[API](https://skmtc.dev/leakradar/apis/leakradar-io-api.md) · [All operations](https://skmtc.dev/leakradar/apis/leakradar-io-api/llms.txt) · [OpenAPI document](https://skmtc.dev/leakradar/apis/leakradar-io-api/revisions/99aaaa4fbeb1?raw)
