---
title: "Unlock selected combolist credentials"
method: POST
path: "/search/combolist/unlock"
tags: ["Search Combolists"]
---

# Unlock selected combolist credentials

`POST /search/combolist/unlock`

Unlock a list of Combolist credential IDs and return them in clear.

**Identifiers**
Only combolist IDs are accepted, that is the `cl1_` namespace followed by 60 hexadecimal characters. A stealer-log ID in the payload is a 400, never a silent skip: the two datasets never share an unlock endpoint. At most 10 000 IDs per call.

**Billing**
- 1 point per pair newly unlocked, taken from the account owner's balance. Pairs you already own are free and are returned again without charge.
- If Elasticsearch rejects part of the batch, only the pairs that were actually written are billed; the rest is refunded.
- The Combolists dataset is sold from the Enterprise tier upwards. Unlocking without it is a 403, even though the search itself answers.

**Bulk**
For a whole result set rather than a selection, queue `POST /search/combolist/unlock/task` instead: it takes a scope rather than a list of IDs and reports progress as a task.

**Response**
A list of `CombolistUnlockResult`, one per credential whose unlock state could be confirmed. Passwords are omitted when your account preference hides them.

## Request body

- UnlockRequest
  - `leak_ids` string[], required — List of leak document IDs to unlock.
  - `target_list_id` integer, nullable — Optional list id to assign to newly unlocked items.

## Response `200`

Credentials unlocked and returned in clear.

- CombolistUnlockResult[]
  - `id` string, required
  - `username` string, required
  - `password` string, nullable
  - `password_strength` integer
  - `is_email` boolean, required
  - `email_domain` string, nullable
  - `added_at` string, date-time, required
  - `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk'
  - `dataset` 'combolist'
  - `unlocked` true

## Other responses

- `400` — No IDs provided, more than 10 000 IDs, an ID outside the combolist namespace, insufficient points, or every selected credential was already unlocked.
- `401` — Authentication required, or invalid/expired API key.
- `403` — No active subscription, the Combolists dataset is not on your plan, account banned, or pending email verification.
- `404` — Combolist search is not enabled on this deployment.
- `410` — The selected credentials are no longer in the index. Refresh your search results and retry with the new IDs.
- `422` — Validation error.
- `429` — Rate limit exceeded. See Retry-After / X-RateLimit-* headers.
- `500` — Unlock state could not be verified, or indexation error.
- `503` — Combolist search under maintenance, or public API temporarily disabled.

## Changes

- **2026-09-04** `eb219e94d077` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/leakradar/apis/leakradar-io-api/changes/search/combolist/unlock/post.md)

---

[API](https://skmtc.dev/leakradar/apis/leakradar-io-api.md) · [All operations](https://skmtc.dev/leakradar/apis/leakradar-io-api/llms.txt) · [OpenAPI document](https://skmtc.dev/leakradar/apis/leakradar-io-api/revisions/99aaaa4fbeb1?raw)
