Raw Search

Search raw leak blocks

Perform a full-text search across raw leak blocks. Provide the search payload in the JSON body.

Request body

  • q: Optional search string (minimum 4 characters once quotes are removed).
  • container_id: Optional container identifier.
  • exts / exts_not: File extensions to include / exclude.
  • categories / categories_not: Raw file categories to include / exclude.
  • file_name / file_name_not: Wildcard on entry_name (max 50 items, min 4 chars each).
  • file_name_exact: Match file_name values against the whole entry name instead of a substring.
  • folder_name / folder_name_not: Match on the folder holding the block (max 20 items, min 4 chars each, surrounding slashes ignored). folder_name_not is not a standalone selector.
  • folder_name_exact: Require folder_name values to be a whole folder at any depth (data matches a/b/data, not a/b/database) instead of a substring of the folder path.
  • exclude_terms: Content terms to exclude (substring, case-insensitive, max 20 items, min 4 chars each). Not a standalone selector.
  • force_and: Apply AND logic within file_name and within folder_name (default OR).
  • ingested_at_min / ingested_at_max: Datetime range filter (ISO 8601 with timezone).

If q is omitted, you must provide at least one filter among container_id, exts, categories, file_name, folder_name.

Query parameters

  • page starts at 1.
  • page_size ranges from 1 to 100 (default 10).
  • cursor: Cursor returned in the previous response to fetch the next page of results.

Rate limit: 5 requests per second per user.

Response: { items, total, page, page_size }


Limits:

ConstraintValue
Max file name filters50
Max folder name filters20
Min characters per file / folder name4
Max export results5 000
Max export files25
Download link retention7 days
post/search/raw

Query parameters

pageinteger

Page number (starts at 1).

Page number (starts at 1).

page_sizeinteger

Items per page (1–100, default 10).

Items per page (1–100, default 10).

cursorstring nullable

Cursor from previous response to fetch the next page

Cursor from previous response to fetch the next page

dedupboolean

Collapse blocks with identical content (same block_fp64) into a single result. Dedup is per-page: with cursor pagination the same content may resurface on a later page.

Collapse blocks with identical content (same block_fp64) into a single result. Dedup is per-page: with cursor pagination the same content may resurface on a later page.

Request body

qstring nullable

Optional full text query to match within raw blocks. Quotes are ignored for the length check. When omitted or empty, you must provide at least one filter among container_id, exts, categories, file_name.

container_idinteger nullable

Restrict the search to a specific container id.

extsstring[] nullable

List of file extensions to include (case-insensitive, without leading dot).

exts_notstring[] nullable

List of file extensions to exclude (case-insensitive, without leading dot).

categoriesstring[] nullable

Filter results by raw file category. Applied after the search query.

categories_notstring[] nullable

Exclude these raw file categories. Applied after the search query.

file_namestring[] nullable

Case-insensitive wildcards that must match the entry name (OR by default, AND if force_and=true).

file_name_notstring[] nullable

Case-insensitive wildcards that must NOT match the entry name.

folder_namestring[] nullable

Case-insensitive match on the folder holding the block (OR by default, AND if force_and=true). By default the value must appear anywhere in the folder path; with folder_name_exact=true it must be a whole folder at any depth. Leading and trailing slashes are ignored.

folder_name_notstring[] nullable

Folders to exclude, same matching rules as folder_name. Not a standalone selector: a search using only folder_name_not is rejected, provide q or another positive filter.

force_andboolean nullable

When true, require all file_name values to match, and all folder_name values to match (AND instead of OR within each list).

file_name_exactboolean nullable

When true, file_name / file_name_not match the entry name exactly (case-insensitive) instead of as a 'contains' wildcard.

folder_name_exactboolean nullable

When true, folder_name / folder_name_not must match a whole folder at any depth: 'data' matches 'a/b/data' but not 'a/b/database'. A value containing slashes matches a whole run of folders ('b/data' matches 'a/b/data/c'). Without it the value is matched as a substring of the folder path.

q_exactboolean nullable

When true, the q term must match on word boundaries: '4.4.4.4' will not match '4.4.4.400'. Applied as a content post-filter (no effect without q).

exclude_termsstring[] nullable

Content terms to exclude: any block whose content contains one of these (substring, case-insensitive) is removed from the results. Min 4 characters per term, max 20 terms. Not a standalone selector: a search using only exclude_terms is rejected, provide q or another positive filter.

ingested_at_minstring date-time nullable

Filter results ingested on or after this datetime (inclusive).

ingested_at_maxstring date-time nullable

Filter results ingested on or before this datetime (inclusive).

Example request

{
  "q": "example.com"
}

Response

Search executed successfully.

totalinteger required

Total number of results (-1 if using cursor mode).

pageinteger required

Requested page index (1-based).

page_sizeinteger required

Maximum number of items returned in this page.

has_moreboolean nullable

True if more results available (cursor mode only).

next_cursorstring nullable

Cursor for next page (cursor mode only).

blacklisted_valuestring nullable

If a filter value matched a blacklist entry, this field contains the matched value.

Changes

No recorded changes to this endpoint across all 1 revision of this API.