# Compromised Employee Credential Accept Risk

POST /cti/compromised-employee-credentials/search:accept-risk: Accepts the risk of the compromised employee credentials that match filters (risk_accepted).

Source: https://docs.deepinfo.com/reference/cti/compromised-employee-credential-accept-risk/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search:accept-risk`

Accepts the risk of the compromised employee credentials that match `filters` (`risk_accepted`).

The action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.

> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.

## Authentication

Send your API key in the `apikey` request header.

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{
  "filters": {
    "must": [
      {
        "name": "id",
        "type": "eq",
        "value": "000000000000000e37e30001"
      }
    ]
  }
}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `url` | The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`. |
| `account.id` | The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search. |
| `account.email` | The e-mail address of the employee account the credential belongs to (ACCOUNT column). |
| `account.domain` | The domain of the employee's e-mail address, one of your organization's domains. |
| `account.first_name` | The first name of the employee the credential belongs to, when known. |
| `account.last_name` | The last name of the employee the credential belongs to, when known. |
| `account.department` | The department of the employee the credential belongs to, when known. |
| `account.title` | The job title of the employee the credential belongs to, when known. |
| `account.linkedin_url` | The address of the LinkedIn profile of the employee the credential belongs to, when known. |
| `password` | The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them. |
| `password_analysis.strength.label` | The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column. |
| `password_analysis.composition.structure` | The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive. |
| `password_analysis.dictionary_match.dictionary_word_found` | The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password. |
| `target.url` | The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address. |
| `target.url_raw` | The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`. |
| `target.fqdn` | The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order. |
| `target.domain` | The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN). |
| `target.service` | The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list. |
| `target.platform` | Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host. |
| `target.main_category` | The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category. |
| `target.sub_category` | A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category. |
| `target.risk_tier` | The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `account.is_executive` | Whether the employee the credential belongs to is marked as an executive. |
| `password_analysis.composition.contains_uppercase` | Whether the password contains an uppercase letter (A–Z). |
| `password_analysis.composition.contains_lowercase` | Whether the password contains a lowercase letter (a–z). |
| `password_analysis.composition.contains_number` | Whether the password contains a digit (0–9). |
| `password_analysis.composition.contains_special` | Whether the password contains a special character, such as `!`, `@` or `#`. |
| `password_analysis.composition.starts_with_uppercase` | Whether the password starts with an uppercase letter (START WITH UPPERCASE). |
| `password_analysis.composition.ends_with_numbers` | Whether the password ends with a digit (END WITH NUMBERS). |
| `password_analysis.composition.ends_with_special` | Whether the password ends with a special character (END WITH SPECIAL CHARACTER). |
| `password_analysis.patterns.has_keyboard_pattern` | Whether the password contains a keyboard pattern (KEYBOARD PATTERN). |
| `password_analysis.patterns.has_date_pattern` | Whether the password contains a date pattern (DATE PATTERN). |
| `password_analysis.patterns.has_leet_speak` | Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK). |
| `password_analysis.patterns.has_sequential_chars` | Whether the password contains sequential characters (SEQUENTIAL CHARACTER). |
| `password_analysis.patterns.has_repeated_chars` | Whether the password contains repeated characters (REPEATED CHARACTER). |
| `password_analysis.dictionary_match.is_common_password` | Whether the password is a known common password (COMMON PASSWORD). |
| `password_analysis.dictionary_match.is_dictionary_word` | Whether the whole password, ignoring letter case, is a dictionary word. |
| `target.is_corporate` | Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list. |
| `target.requires_mfa_by_default` | Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category. |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `added_at` | When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
| `password_analysis.strength.level` | The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`. |
| `password_analysis.strength.score` | The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH). |
| `password_analysis.strength.entropy_bits` | An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess. |
| `password_analysis.composition.length` | The number of characters in the password (LENGTH). |
| `password_analysis.composition.character_classes_used` | How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES). |
| `password_analysis.dictionary_match.common_password_rank` | The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`. |

Operators: `eq`, `in`

| Field | Description |
|---|---|
| `id` | The exposed credential's unique ID, a 24-character hex string. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `state` | The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

### Sortable Fields

| Field | Description |
|---|---|
| `id` | The exposed credential's unique ID, a 24-character hex string. |
| `url` | The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`. |
| `account.id` | The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search. |
| `account.email` | The e-mail address of the employee account the credential belongs to (ACCOUNT column). |
| `account.domain` | The domain of the employee's e-mail address, one of your organization's domains. |
| `account.is_executive` | Whether the employee the credential belongs to is marked as an executive. |
| `account.first_name` | The first name of the employee the credential belongs to, when known. |
| `account.last_name` | The last name of the employee the credential belongs to, when known. |
| `account.title` | The job title of the employee the credential belongs to, when known. |
| `account.linkedin_url` | The address of the LinkedIn profile of the employee the credential belongs to, when known. |
| `account.department` | The department of the employee the credential belongs to, when known. |
| `added_at` | When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
| `password` | The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them. |
| `password_analysis.strength.level` | The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`. |
| `password_analysis.strength.score` | The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH). |
| `password_analysis.strength.label` | The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column. |
| `password_analysis.strength.entropy_bits` | An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess. |
| `password_analysis.composition.length` | The number of characters in the password (LENGTH). |
| `password_analysis.composition.structure` | The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive. |
| `password_analysis.composition.character_classes_used` | How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES). |
| `password_analysis.composition.contains_uppercase` | Whether the password contains an uppercase letter (A–Z). |
| `password_analysis.composition.contains_lowercase` | Whether the password contains a lowercase letter (a–z). |
| `password_analysis.composition.contains_number` | Whether the password contains a digit (0–9). |
| `password_analysis.composition.contains_special` | Whether the password contains a special character, such as `!`, `@` or `#`. |
| `password_analysis.composition.starts_with_uppercase` | Whether the password starts with an uppercase letter (START WITH UPPERCASE). |
| `password_analysis.composition.ends_with_numbers` | Whether the password ends with a digit (END WITH NUMBERS). |
| `password_analysis.composition.ends_with_special` | Whether the password ends with a special character (END WITH SPECIAL CHARACTER). |
| `password_analysis.patterns.has_keyboard_pattern` | Whether the password contains a keyboard pattern (KEYBOARD PATTERN). |
| `password_analysis.patterns.has_date_pattern` | Whether the password contains a date pattern (DATE PATTERN). |
| `password_analysis.patterns.has_leet_speak` | Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK). |
| `password_analysis.patterns.has_sequential_chars` | Whether the password contains sequential characters (SEQUENTIAL CHARACTER). |
| `password_analysis.patterns.has_repeated_chars` | Whether the password contains repeated characters (REPEATED CHARACTER). |
| `password_analysis.dictionary_match.is_common_password` | Whether the password is a known common password (COMMON PASSWORD). |
| `password_analysis.dictionary_match.common_password_rank` | The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`. |
| `password_analysis.dictionary_match.is_dictionary_word` | Whether the whole password, ignoring letter case, is a dictionary word. |
| `password_analysis.dictionary_match.dictionary_word_found` | The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password. |
| `target.url` | The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address. |
| `target.url_raw` | The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`. |
| `target.fqdn` | The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order. |
| `target.domain` | The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN). |
| `target.service` | The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list. |
| `target.platform` | Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host. |
| `target.main_category` | The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category. |
| `target.sub_category` | A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category. |
| `target.risk_tier` | The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category. |
| `target.is_corporate` | Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list. |
| `target.requires_mfa_by_default` | Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category. |
| `state` | The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

## Response Fields

| Field | Type |
|---|---|
| `count` | integer |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `count` | number |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search:accept-risk' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "id",
        "type": "eq",
        "value": "000000000000000e37e30001"
      }
    ]
  }
}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "count": 1
}
```

### 400 · Malformed JSON

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search:accept-risk' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{"filters": '
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "details": [
    "Invalid JSON data."
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search:accept-risk' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.email",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.first_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.last_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.department",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.title",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.linkedin_url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password_analysis.strength.label",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password_analysis.composition.structure",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password_analysis.dictionary_match.dictionary_word_found",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.url_raw",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.fqdn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.service",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.platform",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.main_category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.sub_category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.risk_tier",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.is_executive",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.contains_uppercase",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.contains_lowercase",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.contains_number",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.contains_special",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.starts_with_uppercase",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.ends_with_numbers",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.ends_with_special",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_keyboard_pattern",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_date_pattern",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_leet_speak",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_sequential_chars",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_repeated_chars",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.dictionary_match.is_common_password",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.dictionary_match.is_dictionary_word",
        "type": "eq",
        "value": true
      },
      {
        "name": "target.is_corporate",
        "type": "eq",
        "value": true
      },
      {
        "name": "target.requires_mfa_by_default",
        "type": "eq",
        "value": true
      },
      {
        "name": "added_at",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "password_analysis.strength.level",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.strength.score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.strength.entropy_bits",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.composition.length",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.composition.character_classes_used",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.dictionary_match.common_password_rank",
        "type": "eq",
        "value": 0
      },
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}'
```
