# Compromised Client Credential Search

POST /cti/compromised-client-credentials/search: Searches leaked credentials of your customers and their state.

Source: https://docs.deepinfo.com/reference/cti/compromised-client-credential-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/cti/compromised-client-credentials/search`

Searches leaked credentials of your customers and their state.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `url` | The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`. |
| `username` | The customer's username or e-mail address from the leaked login (USERNAME). |
| `username_type` | Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty. |
| `password` | The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them. |
| `target.url` | The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address. |
| `target.url_raw` | The raw form of the target URL; in the samples it is always the same as `target.url`. |
| `target.fqdn` | The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order. |
| `target.domain` | The registered domain of the target, such as `acme.example` for `login.acme.example`. |
| `target.service` | The name of your site or service the client credential belongs to. |
| `target.platform` | Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column. |
| `target.main_category` | The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category. |
| `target.sub_category` | A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category. |
| `target.risk_tier` | The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `target.is_corporate` | Whether the target is a corporate service. |
| `target.requires_mfa_by_default` | Whether the target service enforces multi-factor authentication by default. Empty for a service without a category. |

Operators: `eq`, `in`

| Field | Description |
|---|---|
| `id` | The client credential's unique ID, a 24-character hex string. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `state` | The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `added_at` | When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |

### Sortable Fields

| Field | Description |
|---|---|
| `id` | The client credential's unique ID, a 24-character hex string. |
| `url` | The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`. |
| `username` | The customer's username or e-mail address from the leaked login (USERNAME). |
| `username_type` | Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty. |
| `added_at` | When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
| `password` | The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them. |
| `target.url` | The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address. |
| `target.url_raw` | The raw form of the target URL; in the samples it is always the same as `target.url`. |
| `target.fqdn` | The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order. |
| `target.domain` | The registered domain of the target, such as `acme.example` for `login.acme.example`. |
| `target.service` | The name of your site or service the client credential belongs to. |
| `target.platform` | Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column. |
| `target.main_category` | The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category. |
| `target.sub_category` | A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category. |
| `target.risk_tier` | The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category. |
| `target.is_corporate` | Whether the target is a corporate service. |
| `target.requires_mfa_by_default` | Whether the target service enforces multi-factor authentication by default. Empty for a service without a category. |
| `state` | The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].url` | string |  |
| `results[].username` | string |  |
| `results[].username_type` | string | One of `email`, `username` |
| `results[].state` | string | One of `newly_detected`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |
| `results[].added_at` | string | date-time |
| `results[].password` | string |  |
| `results[].target` | object |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].url` | string |
| `results[].username` | string |
| `results[].username_type` | null |
| `results[].state` | string |
| `results[].added_at` | string |
| `results[].password` | string |
| `results[].target` | object |
| `results[].target.url` | string |
| `results[].target.url_raw` | string |
| `results[].target.fqdn` | string |
| `results[].target.domain` | string |
| `results[].target.service` | string |
| `results[].target.platform` | string |
| `results[].target.main_category` | null |
| `results[].target.sub_category` | null |
| `results[].target.risk_tier` | null |
| `results[].target.is_corporate` | boolean |
| `results[].target.requires_mfa_by_default` | null |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-client-credentials/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "000000000000000e37e30001",
      "url": "https://www.fernhill.example/",
      "username": "user@acme.example",
      "username_type": null,
      "state": "newly_detected",
      "added_at": "2025-06-01T08:00:00Z",
      "password": "********",
      "target": {
        "url": "https://www.fernhill.example/",
        "url_raw": "https://www.fernhill.example/",
        "fqdn": "www.fernhill.example",
        "domain": "fernhill.example",
        "service": "Webmail",
        "platform": "Web",
        "main_category": null,
        "sub_category": null,
        "risk_tier": null,
        "is_corporate": true,
        "requires_mfa_by_default": null
      }
    },
    {
      "id": "000000000000000e37e30002",
      "url": "http://app.fernhill.example/",
      "username": "user@acme.example",
      "username_type": null,
      "state": "unresolved",
      "added_at": "2025-05-25T08:00:00Z",
      "password": "********",
      "target": {
        "url": "http://app.fernhill.example/",
        "url_raw": "http://app.fernhill.example/",
        "fqdn": "app.fernhill.example",
        "domain": "fernhill.example",
        "service": "VPN",
        "platform": "Android",
        "main_category": null,
        "sub_category": null,
        "risk_tier": null,
        "is_corporate": true,
        "requires_mfa_by_default": null
      }
    }
  ]
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-client-credentials/search?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-client-credentials/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "username",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "username_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.url_raw",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.fqdn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.service",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.platform",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.main_category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.sub_category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.risk_tier",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.is_corporate",
        "type": "eq",
        "value": true
      },
      {
        "name": "target.requires_mfa_by_default",
        "type": "eq",
        "value": true
      },
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "added_at",
        "type": "eq",
        "value": "<date-time>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}'
```
