Search combolists by exact email
Search the Combolists dataset for an exact email address. Provide the search payload in the JSON body.
Dataset
- Combolists is a separate index from stealer logs: a pair returned here does not appear in POST /search/email, and unlocking it stores the record under /profile/unlocked/combolists, not /profile/unlocked.
- Records carry no URL. A result is an identifier, a password, a password strength score, the email domain, and the date the pair was first added to the index.
- Matching is exact and case-insensitive on the identifier. Use search to filter the matched set further on username or password.
Pagination
- page starts at 1.
- page_size is 1 to 100 (default 100).
- Deep interactive paging is capped. Past the offset limit the call answers 400 and you should queue POST /search/combolist/export.
Access and visibility
- The Combolists dataset is sold from the Enterprise tier upwards. Without it the search still runs, but identifiers come back masked, passwords are omitted and item IDs are not returned, so nothing can be unlocked.
- Credentials are returned in clear only when unlocked=true.
Auto-unlock Pass auto_unlock=true to automatically unlock the locked pairs of the current page. 1 point is consumed per newly unlocked pair. If your balance is insufficient, a partial unlock is performed. The response field auto_unlock_points_consumed reports how many points were used.
Response CombolistSearchResponse with items, total, total_unlocked, page, page_size. blacklisted_value is set instead of any result when the query matches one of your blacklist rules.
Query parameters
Page number (starts at 1).
Page number (starts at 1).
Items per page (1-100, default 100).
Items per page (1-100, default 100).
Automatically unlock the locked credentials of the current page using your points.
Automatically unlock the locked credentials of the current page using your points.
Request body
Response
Search results successfully returned.
Example response
{
"auto_unlock_points_consumed": 0,
"items": [
{
"added_at": "2026-01-15T10:30:00Z",
"dataset": "combolist",
"email_domain": "example.com",
"id": "cl1_9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c",
"is_email": true,
"password": "P@ssw0rd123",
"password_strength": 6,
"status": "new",
"unlocked": true,
"username": "john.doe@example.com"
}
],
"page": 1,
"page_size": 100,
"total": 128,
"total_unlocked": 1
}Changes
Changed in 1 of the 8 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○