POSThttps://api.deepinfo.com/v1/cti/compromised-client-credentials/search:accept-risk

Accepts the risk of the compromised client credentials that match filters (risk_accepted).

The action applies to every record matching filters. Always send a filter (for example by id); an empty filter matches all records.

State changes are applied asynchronously: the new state is visible a few seconds after the response. The response body only reports how many records matched.

Authentication

Send your API key in the apikey request header.

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{
  "filters": {
    "must": [
      {
        "name": "id",
        "type": "eq",
        "value": "000000000000000e37e30001"
      }
    ]
  }
}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescription
urlThe address of the login page or app of your service where the customer's credential was used; in the samples it is the same as target.url.
usernameThe customer's username or e-mail address from the leaked login (USERNAME).
username_typeWhether username is an e-mail address (email) or a user name (username); it can be empty.
passwordThe customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.
target.urlThe address of the site or app the credential belongs to. For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address.
target.url_rawThe raw form of the target URL; in the samples it is always the same as target.url.
target.fqdnThe host name of the target, such as login.acme.example. For an Android app it is the app's package name in reverse order.
target.domainThe registered domain of the target, such as acme.example for login.acme.example.
target.serviceThe name of your site or service the client credential belongs to.
target.platformWhere the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown with the login address in the TARGET column.
target.main_categoryThe category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail. Empty for a service without a category.
target.sub_categoryA narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider. Empty for a service without a category.
target.risk_tierThe risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW. Empty for a service without a category.

Operators eq exists

FieldDescription
target.is_corporateWhether the target is a corporate service.
target.requires_mfa_by_defaultWhether the target service enforces multi-factor authentication by default. Empty for a service without a category.

Operators eq in

FieldDescription
idThe client credential's unique ID, a 24-character hex string.

Operators eq in exists

FieldDescription
stateThe client credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you).

Operators eq in gte lte exists

FieldDescription
added_atWhen the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).

Sortable Fields

FieldDescription
idThe client credential's unique ID, a 24-character hex string.
urlThe address of the login page or app of your service where the customer's credential was used; in the samples it is the same as target.url.
usernameThe customer's username or e-mail address from the leaked login (USERNAME).
username_typeWhether username is an e-mail address (email) or a user name (username); it can be empty.
added_atWhen the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).
passwordThe customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.
target.urlThe address of the site or app the credential belongs to. For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address.
target.url_rawThe raw form of the target URL; in the samples it is always the same as target.url.
target.fqdnThe host name of the target, such as login.acme.example. For an Android app it is the app's package name in reverse order.
target.domainThe registered domain of the target, such as acme.example for login.acme.example.
target.serviceThe name of your site or service the client credential belongs to.
target.platformWhere the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown with the login address in the TARGET column.
target.main_categoryThe category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail. Empty for a service without a category.
target.sub_categoryA narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider. Empty for a service without a category.
target.risk_tierThe risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW. Empty for a service without a category.
target.is_corporateWhether the target is a corporate service.
target.requires_mfa_by_defaultWhether the target service enforces multi-factor authentication by default. Empty for a service without a category.
stateThe client credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you).

Response Fields

FieldType
countinteger

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
countnumber1

Examples

Selecting one loads it into the request and response panels.

Reference updated