Search Combolists

Unlock selected combolist credentials

Unlock a list of Combolist credential IDs and return them in clear.

Identifiers Only combolist IDs are accepted, that is the cl1_ namespace followed by 60 hexadecimal characters. A stealer-log ID in the payload is a 400, never a silent skip: the two datasets never share an unlock endpoint. At most 10 000 IDs per call.

Billing

  • 1 point per pair newly unlocked, taken from the account owner's balance. Pairs you already own are free and are returned again without charge.
  • If Elasticsearch rejects part of the batch, only the pairs that were actually written are billed; the rest is refunded.
  • The Combolists dataset is sold from the Enterprise tier upwards. Unlocking without it is a 403, even though the search itself answers.

Bulk For a whole result set rather than a selection, queue POST /search/combolist/unlock/task instead: it takes a scope rather than a list of IDs and reports progress as a task.

Response A list of CombolistUnlockResult, one per credential whose unlock state could be confirmed. Passwords are omitted when your account preference hides them.

post/search/combolist/unlock

Request body

leak_idsstring[] required

List of leak document IDs to unlock.

target_list_idinteger nullable

Optional list id to assign to newly unlocked items.

Example request

{
  "leak_ids": [
    "3f1a9c2b7e",
    "8d4e0a1f6c"
  ],
  "target_list_id": 42
}

Response

Credentials unlocked and returned in clear.

idstring required
usernamestring required
passwordstring nullable
password_strengthinteger
is_emailboolean required
email_domainstring nullable
added_atstring date-time required
status'new' | 'in_progress' | 'fixed' | 'accepted_risk'
dataset'combolist'
unlockedtrue

Example response

[
  {
    "added_at": "2026-01-15T10:30:00Z",
    "dataset": "combolist",
    "email_domain": "example.com",
    "id": "cl1_9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c9f2c",
    "is_email": true,
    "password": "P@ssw0rd123",
    "password_strength": 6,
    "status": "new",
    "unlocked": true,
    "username": "john.doe@example.com"
  }
]

Changes

Changed in 1 of the 8 revisions of this API.1