Compromised Client Credential Mark False Positive
https://api.deepinfo.com/v1/cti/compromised-client-credentials/search:mark-false-positiveMarks the compromised client credentials that match filters as false positive (marked_as_false_positive).
The action applies to every record matching filters. Always send a filter (for example by id); an empty filter matches all records.
State changes are applied asynchronously: the new state is visible a few seconds after the response. The response body only reports how many records matched.
Authentication
Send your API key in the apikey request header.
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{
"filters": {
"must": [
{
"name": "id",
"type": "eq",
"value": "000000000000000e37e30001"
}
]
}
}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "id",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
url | The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as target.url. |
username | The customer's username or e-mail address from the leaked login (USERNAME). |
username_ | Whether username is an e-mail address (email) or a user name (username); it can be empty. |
password | The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them. |
target. | The address of the site or app the credential belongs to. For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address. |
target. | The raw form of the target URL; in the samples it is always the same as target.url. |
target. | The host name of the target, such as login.acme.example. For an Android app it is the app's package name in reverse order. |
target. | The registered domain of the target, such as acme.example for login.acme.example. |
target. | The name of your site or service the client credential belongs to. |
target. | Where the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown with the login address in the TARGET column. |
target. | The category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail. Empty for a service without a category. |
target. | A narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider. Empty for a service without a category. |
target. | The risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW. Empty for a service without a category. |
Operators eq exists
| Field | Description |
|---|---|
target. | Whether the target is a corporate service. |
target. | Whether the target service enforces multi-factor authentication by default. Empty for a service without a category. |
Operators eq in
| Field | Description |
|---|---|
id | The client credential's unique ID, a 24-character hex string. |
Operators eq in exists
| Field | Description |
|---|---|
state | The client credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you). |
Operators eq in gte lte exists
| Field | Description |
|---|---|
added_ | When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
Sortable Fields
| Field | Description |
|---|---|
id | The client credential's unique ID, a 24-character hex string. |
url | The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as target.url. |
username | The customer's username or e-mail address from the leaked login (USERNAME). |
username_ | Whether username is an e-mail address (email) or a user name (username); it can be empty. |
added_ | When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
password | The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them. |
target. | The address of the site or app the credential belongs to. For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address. |
target. | The raw form of the target URL; in the samples it is always the same as target.url. |
target. | The host name of the target, such as login.acme.example. For an Android app it is the app's package name in reverse order. |
target. | The registered domain of the target, such as acme.example for login.acme.example. |
target. | The name of your site or service the client credential belongs to. |
target. | Where the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown with the login address in the TARGET column. |
target. | The category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail. Empty for a service without a category. |
target. | A narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider. Empty for a service without a category. |
target. | The risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW. Empty for a service without a category. |
target. | Whether the target is a corporate service. |
target. | Whether the target service enforces multi-factor authentication by default. Empty for a service without a category. |
state | The client credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you). |
Response Fields
| Field | Type |
|---|---|
count | integer |
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
count | number | 1 |
Examples
Selecting one loads it into the request and response panels.