---
title: "Search combolists by exact username"
method: POST
path: "/search/combolist/username"
tags: ["Search Combolists"]
---

# Search combolists by exact username

`POST /search/combolist/username`

Search the Combolists dataset for an exact username, that is a pair whose identifier is not an email address. Provide the search payload in the JSON body.

**Dataset**
- Same index and same isolation rules as `POST /search/combolist/email`; only the identifier shape differs. This endpoint filters on `is_email = false`, so an email address never matches here, and `email_domain` is always null in the results.
- Matching is exact and case-insensitive. Use `search` to filter the matched set further on username or password.

**Pagination**
- `page` starts at 1.
- `page_size` is 1 to 100 (default 100).
- Deep interactive paging is capped. Past the offset limit the call answers 400 and you should queue `POST /search/combolist/export`.

**Access and visibility**
- The Combolists dataset is sold from the Enterprise tier upwards. Without it the search still runs, but identifiers come back masked, passwords are omitted and item IDs are not returned, so nothing can be unlocked.

**Auto-unlock**
Pass `auto_unlock=true` to unlock the locked pairs of the current page. 1 point per newly unlocked pair, partial unlock on insufficient balance, amount reported in `auto_unlock_points_consumed`.

**Response**
`CombolistSearchResponse` with `items`, `total`, `total_unlocked`, `page`, `page_size`.

## Query parameters

- `page` integer — Page number (starts at 1).
- `page_size` integer — Items per page (1-100, default 100).
- `auto_unlock` boolean — Automatically unlock the locked credentials of the current page using your points.

## Request body

- CombolistUsernameSearchRequest
  - `username` string, required — Exact non-email username to search.
  - `search` string, nullable — Optional substring in the identifier or password.

## Response `200`

Search results successfully returned.

- CombolistSearchResponse
  - `items` CombolistCredentialDetails[], required
    - `id` string, nullable — Immutable combolist credential identifier. Hidden when the plan does not grant access to the selected search surface.
    - `username` string, nullable — Email address or username. Present only for unlocked rows.
    - `username_masked` string, nullable — Masked identifier shown while the credential is locked.
    - `password` string, nullable — Exact password. Present only for unlocked rows.
    - `password_strength` integer — Raw password-strength score.
    - `is_email` boolean, required — True for an email, false for a username.
    - `email_domain` string, nullable — Normalized domain, present only for email credentials.
    - `added_at` string, date-time, required — Date of the earliest accepted RawFile occurrence.
    - `unlocked` boolean — Whether the row is unlocked.
    - `status` 'new' | 'in_progress' | 'fixed' | 'accepted_risk', nullable — Remediation status, present only for unlocked rows.
    - `dataset` 'combolist' — Fixed provenance guard for this dedicated API.
  - `total` integer, required — Total pairs matching the query.
  - `total_unlocked` integer, required — How many of them you have already unlocked.
  - `page` integer, required
  - `page_size` integer, required
  - `blacklisted_value` string, nullable — Set instead of any result when the query matches one of your blacklist rules.
  - `auto_unlock_points_consumed` integer — Points consumed by Combo auto-unlock on this request.

## Other responses

- `400` — Pagination too deep for interactive search.
- `401` — Authentication required, or invalid/expired API key.
- `403` — Account banned, or pending email verification.
- `404` — Combolist search is not enabled on this deployment.
- `422` — Validation error.
- `429` — Rate limit exceeded. See Retry-After / X-RateLimit-* headers.
- `503` — Combolist search under maintenance, or public API temporarily disabled.

## Changes

- **2026-09-04** `eb219e94d077` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/leakradar/apis/leakradar-io-api/changes/search/combolist/username/post.md)

---

[API](https://skmtc.dev/leakradar/apis/leakradar-io-api.md) · [All operations](https://skmtc.dev/leakradar/apis/leakradar-io-api/llms.txt) · [OpenAPI document](https://skmtc.dev/leakradar/apis/leakradar-io-api/revisions/99aaaa4fbeb1?raw)
