---
title: "Queue an asynchronous Combolist mass unlock"
method: POST
path: "/search/combolist/unlock/task"
tags: ["Search Combolists"]
---

# Queue an asynchronous Combolist mass unlock

`POST /search/combolist/unlock/task`

Unlock every Combolist pair matching a search scope, as a background task.

**Scope**
The body is the search itself, not a list of IDs: `scope` is one of `email`, `username`, `domain` or `advanced`, with `value` for the first three and `filters` for the last. The scope is revalidated by the worker, so a task cannot widen its own perimeter.

**Cost and cap**
- 1 point per pair newly unlocked. The task is capped at your current point balance, and further capped by `max` when you pass it.
- Pairs you already own are skipped and cost nothing.
- Plans that never spend points (Unlimited) get a 400: everything is already readable, use the export instead.

**Progress**
The response carries a `task_id`. Poll it on `GET /profile/activities/tasks` to follow `updated` against `total`.

**Concurrency**
One combolist unlock task at a time per account. Queuing a second one while the first runs is a 429.

## Query parameters

- `max` integer, nullable — Upper bound on the number of pairs to unlock. Omit to use the whole point balance.
- `list_id` integer, nullable — Assign every newly unlocked pair to this unlocked list.

## Request body

- CombolistScopedRequest — Stable search contract persisted by Combo unlock/export jobs.
  - `scope` 'email' | 'username' | 'domain' | 'advanced', required — Which search the job replays: `email`, `username` and `domain` take `value`, `advanced` takes `filters`.
  - `value` string, nullable — Exact email, username or root email domain, per `scope`.
  - `search` string, nullable — Optional filter on username or password, applied on top of `value`. Not allowed on the advanced scope.
  - `filters` CombolistAdvancedSearchRequest — Combolist filters. Text is literal; only match_type adds operators. Characters such as *, ? and backslash are searched as written.
    - `username` string[], nullable
    - `username_not` string[], nullable
    - `username_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `username_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `password` string[], nullable
    - `password_not` string[], nullable
    - `password_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `password_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `email_domain` string[], nullable
    - `email_domain_not` string[], nullable
    - `email_domain_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `email_domain_not_match_type` 'contains' | 'starts_with' | 'ends_with'
    - `username_hash` string[], nullable
    - `password_hash` string[], nullable
    - `is_email` boolean, nullable
    - `password_strength` 'too_weak' | 'weak' | 'medium' | 'strong'
    - `added_from` string, date-time, nullable
    - `added_to` string, date-time, nullable
    - `force_and` boolean

## Response `200`

Task queued.

- TaskStatusOut
  - `task_id` string, required
  - `running` boolean, required
  - `completed` boolean, required
  - `total` integer, nullable
  - `updated` integer, nullable
  - `version_conflicts` integer, nullable

## Other responses

- `400` — Insufficient points, or the plan does not spend points.
- `401` — Authentication required, or invalid/expired API key.
- `403` — No active subscription, or the Combolists dataset is not on your plan for this scope.
- `404` — Combolist search is not enabled on this deployment, or the target list does not exist.
- `422` — Validation error.
- `429` — Too many concurrent unlock tasks, or rate limit exceeded.
- `503` — Combolist search under maintenance, or public API temporarily disabled.

## Changes

- **2026-09-04** `eb219e94d077` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/leakradar/apis/leakradar-io-api/changes/search/combolist/unlock/task/post.md)

---

[API](https://skmtc.dev/leakradar/apis/leakradar-io-api.md) · [All operations](https://skmtc.dev/leakradar/apis/leakradar-io-api/llms.txt) · [OpenAPI document](https://skmtc.dev/leakradar/apis/leakradar-io-api/revisions/99aaaa4fbeb1?raw)
