# Compromised Client Credential Export

POST /cti/compromised-client-credentials/search:export: Exports every record matching filters (no pagination).

Source: https://docs.deepinfo.com/reference/cti/compromised-client-credential-export/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/cti/compromised-client-credentials/search:export`

Exports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `format` | Optional | One of: `json`, `csv`. | `csv` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `url` | The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`. |
| `username` | The customer's username or e-mail address from the leaked login (USERNAME). |
| `username_type` | Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty. |
| `password` | The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them. |
| `target.url` | The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address. |
| `target.url_raw` | The raw form of the target URL; in the samples it is always the same as `target.url`. |
| `target.fqdn` | The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order. |
| `target.domain` | The registered domain of the target, such as `acme.example` for `login.acme.example`. |
| `target.service` | The name of your site or service the client credential belongs to. |
| `target.platform` | Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column. |
| `target.main_category` | The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category. |
| `target.sub_category` | A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category. |
| `target.risk_tier` | The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `target.is_corporate` | Whether the target is a corporate service. |
| `target.requires_mfa_by_default` | Whether the target service enforces multi-factor authentication by default. Empty for a service without a category. |

Operators: `eq`, `in`

| Field | Description |
|---|---|
| `id` | The client credential's unique ID, a 24-character hex string. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `state` | The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `added_at` | When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |

### Sortable Fields

| Field | Description |
|---|---|
| `id` | The client credential's unique ID, a 24-character hex string. |
| `url` | The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`. |
| `username` | The customer's username or e-mail address from the leaked login (USERNAME). |
| `username_type` | Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty. |
| `added_at` | When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
| `password` | The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them. |
| `target.url` | The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address. |
| `target.url_raw` | The raw form of the target URL; in the samples it is always the same as `target.url`. |
| `target.fqdn` | The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order. |
| `target.domain` | The registered domain of the target, such as `acme.example` for `login.acme.example`. |
| `target.service` | The name of your site or service the client credential belongs to. |
| `target.platform` | Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column. |
| `target.main_category` | The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category. |
| `target.sub_category` | A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category. |
| `target.risk_tier` | The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category. |
| `target.is_corporate` | Whether the target is a corporate service. |
| `target.requires_mfa_by_default` | Whether the target service enforces multi-factor authentication by default. Empty for a service without a category. |
| `state` | The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-client-credentials/search:export?format=csv' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: text/csv; charset=utf-8` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```
id,url,username,username_type,state,added_at,password,target.url,target.url_raw,target.fqdn,target.domain,target.service,target.platform,target.main_category,target.sub_category,target.risk_tier,target.is_corporate,target.requires_mfa_by_default
000000000000000e37e30001,https://www.fernhill.example/,user@acme.example,,newly_detected,2025-06-01T08:00:00Z,********,https://www.fernhill.example/,https://www.fernhill.example/,www.fernhill.example,fernhill.example,Webmail,Web,,,,True,
000000000000000e37e30002,http://app.fernhill.example/,user@acme.example,,unresolved,2025-05-25T08:00:00Z,********,http://app.fernhill.example/,http://app.fernhill.example/,app.fernhill.example,fernhill.example,VPN,Android,,,,True,
000000000000000e37e30003,https://mail.kestrel.example/,user@acme.example,,unresolved,2025-05-18T08:00:00Z,********,https://mail.kestrel.example/,https://mail.kestrel.example/,mail.kestrel.example,kestrel.example,Single sign-on,iOS,,,,True,
```

### 400 · Invalid Parameter (invalid format=invalid_value)

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-client-credentials/search:export?format=invalid_value' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "format",
      "details": [
        "Select a valid choice."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-client-credentials/search:export?format=csv' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "username",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "username_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.url_raw",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.fqdn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.service",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.platform",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.main_category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.sub_category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.risk_tier",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.is_corporate",
        "type": "eq",
        "value": true
      },
      {
        "name": "target.requires_mfa_by_default",
        "type": "eq",
        "value": true
      },
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "added_at",
        "type": "eq",
        "value": "<date-time>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}'
```
