Search Combolists

Search combolists by exact email

Search the Combolists dataset for an exact email address. Provide the search payload in the JSON body.

Dataset

  • Combolists is a separate index from stealer logs: a pair returned here does not appear in POST /search/email, and unlocking it stores the record under /profile/unlocked/combolists, not /profile/unlocked.
  • Records carry no URL. A result is an identifier, a password, a password strength score, the email domain, and the date the pair was first added to the index.
  • Matching is exact and case-insensitive on the identifier. Use search to filter the matched set further on username or password.

Pagination

  • page starts at 1.
  • page_size is 1 to 100 (default 100).
  • Deep interactive paging is capped. Past the offset limit the call answers 400 and you should queue POST /search/combolist/export.

Access and visibility

  • The Combolists dataset is sold from the Enterprise tier upwards. Without it the search still runs, but identifiers come back masked, passwords are omitted and item IDs are not returned, so nothing can be unlocked.
  • Credentials are returned in clear only when unlocked=true.

Auto-unlock Pass auto_unlock=true to automatically unlock the locked pairs of the current page. 1 point is consumed per newly unlocked pair. If your balance is insufficient, a partial unlock is performed. The response field auto_unlock_points_consumed reports how many points were used.

Response CombolistSearchResponse with items, total, total_unlocked, page, page_size. blacklisted_value is set instead of any result when the query matches one of your blacklist rules.

post/search/combolist/email

Query parameters

pageinteger

Page number (starts at 1).

Page number (starts at 1).

page_sizeinteger

Items per page (1-100, default 100).

Items per page (1-100, default 100).

auto_unlockboolean

Automatically unlock the locked credentials of the current page using your points.

Automatically unlock the locked credentials of the current page using your points.

Request body

emailstring required

Exact email address to search.

searchstring nullable

Optional substring in the identifier or password.

Response

Search results successfully returned.

totalinteger required

Total pairs matching the query.

total_unlockedinteger required

How many of them you have already unlocked.

pageinteger required
page_sizeinteger required
blacklisted_valuestring nullable

Set instead of any result when the query matches one of your blacklist rules.

auto_unlock_points_consumedinteger

Points consumed by Combo auto-unlock on this request.

Example response

{
  "auto_unlock_points_consumed": 0,
  "items": [
    {
      "added_at": "2026-01-15T10:30:00Z",
      "dataset": "combolist",
      "email_domain": "example.com",
      "id": "cl1_9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c",
      "is_email": true,
      "password": "P@ssw0rd123",
      "password_strength": 6,
      "status": "new",
      "unlocked": true,
      "username": "john.doe@example.com"
    }
  ],
  "page": 1,
  "page_size": 100,
  "total": 128,
  "total_unlocked": 1
}

Changes

Changed in 1 of the 8 revisions of this API.1