---
title: "Search combolists by exact email"
method: POST
path: "/search/combolist/email"
tags: ["Search Combolists"]
---

# Search combolists by exact email

`POST /search/combolist/email`

Search the Combolists dataset for an exact email address. Provide the search payload in the JSON body.

**Dataset**
- Combolists is a separate index from stealer logs: a pair returned here does not appear in `POST /search/email`, and unlocking it stores the record under `/profile/unlocked/combolists`, not `/profile/unlocked`.
- Records carry no URL. A result is an identifier, a password, a password strength score, the email domain, and the date the pair was first added to the index.
- Matching is exact and case-insensitive on the identifier. Use `search` to filter the matched set further on username or password.

**Pagination**
- `page` starts at 1.
- `page_size` is 1 to 100 (default 100).
- Deep interactive paging is capped. Past the offset limit the call answers 400 and you should queue `POST /search/combolist/export`.

**Access and visibility**
- The Combolists dataset is sold from the Enterprise tier upwards. Without it the search still runs, but identifiers come back masked, passwords are omitted and item IDs are not returned, so nothing can be unlocked.
- Credentials are returned in clear only when `unlocked=true`.

**Auto-unlock**
Pass `auto_unlock=true` to automatically unlock the locked pairs of the current page. 1 point is consumed per newly unlocked pair. If your balance is insufficient, a partial unlock is performed. The response field `auto_unlock_points_consumed` reports how many points were used.

**Response**
`CombolistSearchResponse` with `items`, `total`, `total_unlocked`, `page`, `page_size`. `blacklisted_value` is set instead of any result when the query matches one of your blacklist rules.

## Query parameters

- `page` integer — Page number (starts at 1).
- `page_size` integer — Items per page (1-100, default 100).
- `auto_unlock` boolean — Automatically unlock the locked credentials of the current page using your points.

## Request body

- CombolistEmailSearchRequest
  - `email` string, required — Exact email address to search.
  - `search` string, nullable — Optional substring in the identifier or password.

## Response `200`

Search results successfully returned.

- CombolistSearchResponse
  - `items` CombolistCredentialDetails[], required
    - `id` string, nullable — Immutable combolist credential identifier. Hidden when the plan does not grant access to the selected search surface.
    - `username` string, nullable — Email address or username. Present only for unlocked rows.
    - `username_masked` string, nullable — Masked identifier shown while the credential is locked.
    - `password` string, nullable — Exact password. Present only for unlocked rows.
    - `password_strength` integer — Raw password-strength score.
    - `is_email` boolean, required — True for an email, false for a username.
    - `email_domain` string, nullable — Normalized domain, present only for email credentials.
    - `added_at` string, date-time, required — Date of the earliest accepted RawFile occurrence.
    - `unlocked` boolean — Whether the row is unlocked.
    - `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk', nullable — Remediation status, present only for unlocked rows.
    - `dataset` 'combolist' — Fixed provenance guard for this dedicated API.
  - `total` integer, required — Total pairs matching the query.
  - `total_unlocked` integer, required — How many of them you have already unlocked.
  - `page` integer, required
  - `page_size` integer, required
  - `blacklisted_value` string, nullable — Set instead of any result when the query matches one of your blacklist rules.
  - `auto_unlock_points_consumed` integer — Points consumed by Combo auto-unlock on this request.

## Other responses

- `400` — Pagination too deep for interactive search.
- `401` — Authentication required, or invalid/expired API key.
- `403` — Account banned, or pending email verification.
- `404` — Combolist search is not enabled on this deployment.
- `422` — Validation error.
- `429` — Rate limit exceeded. See Retry-After / X-RateLimit-* headers.
- `503` — Combolist search under maintenance, or public API temporarily disabled.

## Changes

- **2026-09-04** `eb219e94d077` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/leakradar/apis/leakradar-io-api/changes/search/combolist/email/post.md)

---

[API](https://skmtc.dev/leakradar/apis/leakradar-io-api.md) · [All operations](https://skmtc.dev/leakradar/apis/leakradar-io-api/llms.txt) · [OpenAPI document](https://skmtc.dev/leakradar/apis/leakradar-io-api/revisions/99aaaa4fbeb1?raw)
