Unlock selected combolist credentials
Unlock a list of Combolist credential IDs and return them in clear.
Identifiers Only combolist IDs are accepted, that is the cl1_ namespace followed by 60 hexadecimal characters. A stealer-log ID in the payload is a 400, never a silent skip: the two datasets never share an unlock endpoint. At most 10 000 IDs per call.
Billing
- 1 point per pair newly unlocked, taken from the account owner's balance. Pairs you already own are free and are returned again without charge.
- If Elasticsearch rejects part of the batch, only the pairs that were actually written are billed; the rest is refunded.
- The Combolists dataset is sold from the Enterprise tier upwards. Unlocking without it is a 403, even though the search itself answers.
Bulk For a whole result set rather than a selection, queue POST /search/combolist/unlock/task instead: it takes a scope rather than a list of IDs and reports progress as a task.
Response A list of CombolistUnlockResult, one per credential whose unlock state could be confirmed. Passwords are omitted when your account preference hides them.
Request body
Example request
{
"leak_ids": [
"3f1a9c2b7e",
"8d4e0a1f6c"
],
"target_list_id": 42
}Response
Credentials unlocked and returned in clear.
Example response
[
{
"added_at": "2026-01-15T10:30:00Z",
"dataset": "combolist",
"email_domain": "example.com",
"id": "cl1_9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c",
"is_email": true,
"password": "P@ssw0rd123",
"password_strength": 6,
"status": "new",
"unlocked": true,
"username": "john.doe@example.com"
}
]Changes
Changed in 1 of the 8 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○