Search Combolists

Search combolists by exact email domain

List the Combolist pairs whose identifier is an email address on the given root domain.

Dataset

  • Matches on the indexed email_domain, so only pairs with an email identifier are returned. Username-only pairs are out of scope by construction, unlike stealer-log domain search which also matches on the leaked URL.
  • The domain is normalized (lowercased, trailing dot removed) and must be a valid hostname without @.

Pagination

  • page starts at 1.
  • page_size is 1 to 1000 (default 100).
  • Deep interactive paging is capped. Past the offset limit the call answers 400 and you should queue POST /search/combolist/export.

Access and visibility

  • The Combolists dataset is sold from the Enterprise tier upwards. Without it the search still runs, but identifiers come back masked, passwords are omitted and item IDs are not returned.

Auto-unlock Pass auto_unlock=true to unlock the locked pairs of the current page. 1 point per newly unlocked pair, partial unlock on insufficient balance, amount reported in auto_unlock_points_consumed.

Response CombolistSearchResponse with items, total, total_unlocked, page, page_size.

get/search/combolist/domain/{domain}

Path parameters

domainstring required

Root email domain to search, for example example.com.

Root email domain to search, for example example.com.

Query parameters

searchstring nullable

Filter the matched pairs further on username or password.

Filter the matched pairs further on username or password.

pageinteger

Page number (starts at 1).

Page number (starts at 1).

page_sizeinteger

Items per page (1-1000, default 100).

Items per page (1-1000, default 100).

auto_unlockboolean

Automatically unlock the locked credentials of the current page using your points.

Automatically unlock the locked credentials of the current page using your points.

Response

Search results successfully returned.

totalinteger required

Total pairs matching the query.

total_unlockedinteger required

How many of them you have already unlocked.

pageinteger required
page_sizeinteger required
blacklisted_valuestring nullable

Set instead of any result when the query matches one of your blacklist rules.

auto_unlock_points_consumedinteger

Points consumed by Combo auto-unlock on this request.

Example response

{
  "auto_unlock_points_consumed": 0,
  "items": [
    {
      "added_at": "2026-01-15T10:30:00Z",
      "dataset": "combolist",
      "email_domain": "example.com",
      "id": "cl1_9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c",
      "is_email": true,
      "password": "P@ssw0rd123",
      "password_strength": 6,
      "status": "new",
      "unlocked": true,
      "username": "john.doe@example.com"
    }
  ],
  "page": 1,
  "page_size": 100,
  "total": 128,
  "total_unlocked": 1
}

Changes

Changed in 1 of the 8 revisions of this API.1