Compromised Client Credential Search
https://api.deepinfo.com/v1/cti/compromised-client-credentials/searchSearches leaked credentials of your customers and their state.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
page_ | Optional | Min 25, max 100. Default 100.Example 25 |
page | Optional | Min 1, max 800. Default 1.Example 1 |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "id",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
url | The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as target.url. |
username | The customer's username or e-mail address from the leaked login (USERNAME). |
username_ | Whether username is an e-mail address (email) or a user name (username); it can be empty. |
password | The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them. |
target. | The address of the site or app the credential belongs to. For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address. |
target. | The raw form of the target URL; in the samples it is always the same as target.url. |
target. | The host name of the target, such as login.acme.example. For an Android app it is the app's package name in reverse order. |
target. | The registered domain of the target, such as acme.example for login.acme.example. |
target. | The name of your site or service the client credential belongs to. |
target. | Where the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown with the login address in the TARGET column. |
target. | The category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail. Empty for a service without a category. |
target. | A narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider. Empty for a service without a category. |
target. | The risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW. Empty for a service without a category. |
Operators eq exists
| Field | Description |
|---|---|
target. | Whether the target is a corporate service. |
target. | Whether the target service enforces multi-factor authentication by default. Empty for a service without a category. |
Operators eq in
| Field | Description |
|---|---|
id | The client credential's unique ID, a 24-character hex string. |
Operators eq in exists
| Field | Description |
|---|---|
state | The client credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you). |
Operators eq in gte lte exists
| Field | Description |
|---|---|
added_ | When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
Sortable Fields
| Field | Description |
|---|---|
id | The client credential's unique ID, a 24-character hex string. |
url | The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as target.url. |
username | The customer's username or e-mail address from the leaked login (USERNAME). |
username_ | Whether username is an e-mail address (email) or a user name (username); it can be empty. |
added_ | When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
password | The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them. |
target. | The address of the site or app the credential belongs to. For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address. |
target. | The raw form of the target URL; in the samples it is always the same as target.url. |
target. | The host name of the target, such as login.acme.example. For an Android app it is the app's package name in reverse order. |
target. | The registered domain of the target, such as acme.example for login.acme.example. |
target. | The name of your site or service the client credential belongs to. |
target. | Where the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown with the login address in the TARGET column. |
target. | The category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail. Empty for a service without a category. |
target. | A narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider. Empty for a service without a category. |
target. | The risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW. Empty for a service without a category. |
target. | Whether the target is a corporate service. |
target. | Whether the target service enforces multi-factor authentication by default. Empty for a service without a category. |
state | The client credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you). |
Response Fields
| Field | Type | Description |
|---|---|---|
page | integer | |
page_ | integer | |
result_ | integer | |
results | array of object | |
results[]. | string | |
results[]. | string | |
results[]. | string | |
results[]. | string | One of email, username |
results[]. | string | One of newly_detected, unresolved, marked_, risk_accepted, ignored, marked_, not_applicable, verified_resolved |
results[]. | string | date-time |
results[]. | string | |
results[]. | object |
Paginated. See Getting Started → Pagination.
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
page | number | 1 |
page_size | number | 25 |
result_count | number | 21 |
results | array< | |
results[]. | string | "000000000000000e37e30001" |
results[]. | string | "https://www.fernhill.example/" |
results[]. | string | |
results[]. | null | |
results[]. | string | "newly_detected" |
results[]. | string | "2025-06-01T08:00:00Z" |
results[]. | string | |
results[]. | object | |
results[]. | string | "https://www.fernhill.example/" |
results[]. | string | "https://www.fernhill.example/" |
results[]. | string | "www.fernhill.example" |
results[]. | string | "fernhill.example" |
results[]. | string | "Webmail" |
results[]. | string | "Web" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | boolean | true |
results[]. | null |
Examples
Selecting one loads it into the request and response panels.