POSThttps://api.deepinfo.com/v1/cti/compromised-employee-credentials/search

Searches leaked employee credentials and their state.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
page_sizeOptional
Min 25, max 100. Default 100.
Example25
pageOptional
Min 1, max 800. Default 1.
Example1

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescription
urlThe address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as target.url.
account.idThe ID of the employee account the credential belongs to, the id returned by Compromised Employee Account Search.
account.emailThe e-mail address of the employee account the credential belongs to (ACCOUNT column).
account.domainThe domain of the employee's e-mail address, one of your organization's domains.
account.first_nameThe first name of the employee the credential belongs to, when known.
account.last_nameThe last name of the employee the credential belongs to, when known.
account.departmentThe department of the employee the credential belongs to, when known.
account.titleThe job title of the employee the credential belongs to, when known.
account.linkedin_urlThe address of the LinkedIn profile of the employee the credential belongs to, when known.
passwordThe leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.
password_analysis.strength.labelThe password's strength rating: Very Weak, Weak, Medium, Strong or Very Strong, shown with a bar in the STRENGTH column.
password_analysis.composition.structureThe shape of the password, one letter per character: U uppercase, l lowercase, n digit, s special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.
password_analysis.dictionary_match.dictionary_word_foundThe dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.
target.urlThe address of the site or app the credential belongs to (Target URL). For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address.
target.url_rawThe raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as target.url.
target.fqdnThe host name of the target, such as login.acme.example (FQDN). For an Android app it is the app's package name in reverse order.
target.domainThe registered domain of the target, such as acme.example for login.acme.example (DOMAIN).
target.serviceThe name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.
target.platformWhere the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown as the platform tag next to the host.
target.main_categoryThe category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail (MAIN CATEGORY). Empty for a service without a category.
target.sub_categoryA narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider (SUB CATEGORY). Empty for a service without a category.
target.risk_tierThe risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW (RISK TIER). Empty for a service without a category.

Operators eq exists

FieldDescription
account.is_executiveWhether the employee the credential belongs to is marked as an executive.
password_analysis.composition.contains_uppercaseWhether the password contains an uppercase letter (A–Z).
password_analysis.composition.contains_lowercaseWhether the password contains a lowercase letter (a–z).
password_analysis.composition.contains_numberWhether the password contains a digit (0–9).
password_analysis.composition.contains_specialWhether the password contains a special character, such as !, @ or #.
password_analysis.composition.starts_with_uppercaseWhether the password starts with an uppercase letter (START WITH UPPERCASE).
password_analysis.composition.ends_with_numbersWhether the password ends with a digit (END WITH NUMBERS).
password_analysis.composition.ends_with_specialWhether the password ends with a special character (END WITH SPECIAL CHARACTER).
password_analysis.patterns.has_keyboard_patternWhether the password contains a keyboard pattern (KEYBOARD PATTERN).
password_analysis.patterns.has_date_patternWhether the password contains a date pattern (DATE PATTERN).
password_analysis.patterns.has_leet_speakWhether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).
password_analysis.patterns.has_sequential_charsWhether the password contains sequential characters (SEQUENTIAL CHARACTER).
password_analysis.patterns.has_repeated_charsWhether the password contains repeated characters (REPEATED CHARACTER).
password_analysis.dictionary_match.is_common_passwordWhether the password is a known common password (COMMON PASSWORD).
password_analysis.dictionary_match.is_dictionary_wordWhether the whole password, ignoring letter case, is a dictionary word.
target.is_corporateWhether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.
target.requires_mfa_by_defaultWhether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.

Operators eq in gte lte exists

FieldDescription
added_atWhen the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).
password_analysis.strength.levelThe password's strength level from 0 to 4: 0 Very Weak, 1 Weak, 2 Medium, 3 Strong, 4 Very Strong, matching password_analysis.strength.label.
password_analysis.strength.scoreThe password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).
password_analysis.strength.entropy_bitsAn estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.
password_analysis.composition.lengthThe number of characters in the password (LENGTH).
password_analysis.composition.character_classes_usedHow many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).
password_analysis.dictionary_match.common_password_rankThe password's rank in the list of common passwords, where a lower number means a more common password; set only when is_common_password is true.

Operators eq in

FieldDescription
idThe exposed credential's unique ID, a 24-character hex string.

Operators eq in exists

FieldDescription
stateThe credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you).

Sortable Fields

FieldDescription
idThe exposed credential's unique ID, a 24-character hex string.
urlThe address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as target.url.
account.idThe ID of the employee account the credential belongs to, the id returned by Compromised Employee Account Search.
account.emailThe e-mail address of the employee account the credential belongs to (ACCOUNT column).
account.domainThe domain of the employee's e-mail address, one of your organization's domains.
account.is_executiveWhether the employee the credential belongs to is marked as an executive.
account.first_nameThe first name of the employee the credential belongs to, when known.
account.last_nameThe last name of the employee the credential belongs to, when known.
account.titleThe job title of the employee the credential belongs to, when known.
account.linkedin_urlThe address of the LinkedIn profile of the employee the credential belongs to, when known.
account.departmentThe department of the employee the credential belongs to, when known.
added_atWhen the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).
passwordThe leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.
password_analysis.strength.levelThe password's strength level from 0 to 4: 0 Very Weak, 1 Weak, 2 Medium, 3 Strong, 4 Very Strong, matching password_analysis.strength.label.
password_analysis.strength.scoreThe password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).
password_analysis.strength.labelThe password's strength rating: Very Weak, Weak, Medium, Strong or Very Strong, shown with a bar in the STRENGTH column.
password_analysis.strength.entropy_bitsAn estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.
password_analysis.composition.lengthThe number of characters in the password (LENGTH).
password_analysis.composition.structureThe shape of the password, one letter per character: U uppercase, l lowercase, n digit, s special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.
password_analysis.composition.character_classes_usedHow many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).
password_analysis.composition.contains_uppercaseWhether the password contains an uppercase letter (A–Z).
password_analysis.composition.contains_lowercaseWhether the password contains a lowercase letter (a–z).
password_analysis.composition.contains_numberWhether the password contains a digit (0–9).
password_analysis.composition.contains_specialWhether the password contains a special character, such as !, @ or #.
password_analysis.composition.starts_with_uppercaseWhether the password starts with an uppercase letter (START WITH UPPERCASE).
password_analysis.composition.ends_with_numbersWhether the password ends with a digit (END WITH NUMBERS).
password_analysis.composition.ends_with_specialWhether the password ends with a special character (END WITH SPECIAL CHARACTER).
password_analysis.patterns.has_keyboard_patternWhether the password contains a keyboard pattern (KEYBOARD PATTERN).
password_analysis.patterns.has_date_patternWhether the password contains a date pattern (DATE PATTERN).
password_analysis.patterns.has_leet_speakWhether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).
password_analysis.patterns.has_sequential_charsWhether the password contains sequential characters (SEQUENTIAL CHARACTER).
password_analysis.patterns.has_repeated_charsWhether the password contains repeated characters (REPEATED CHARACTER).
password_analysis.dictionary_match.is_common_passwordWhether the password is a known common password (COMMON PASSWORD).
password_analysis.dictionary_match.common_password_rankThe password's rank in the list of common passwords, where a lower number means a more common password; set only when is_common_password is true.
password_analysis.dictionary_match.is_dictionary_wordWhether the whole password, ignoring letter case, is a dictionary word.
password_analysis.dictionary_match.dictionary_word_foundThe dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.
target.urlThe address of the site or app the credential belongs to (Target URL). For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address.
target.url_rawThe raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as target.url.
target.fqdnThe host name of the target, such as login.acme.example (FQDN). For an Android app it is the app's package name in reverse order.
target.domainThe registered domain of the target, such as acme.example for login.acme.example (DOMAIN).
target.serviceThe name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.
target.platformWhere the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown as the platform tag next to the host.
target.main_categoryThe category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail (MAIN CATEGORY). Empty for a service without a category.
target.sub_categoryA narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider (SUB CATEGORY). Empty for a service without a category.
target.risk_tierThe risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW (RISK TIER). Empty for a service without a category.
target.is_corporateWhether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.
target.requires_mfa_by_defaultWhether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.
stateThe credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you).

Response Fields

FieldTypeDescription
pageinteger
page_sizeinteger
result_countinteger
resultsarray of object
results[].idstring
results[].urlstring
results[].statestring
One of newly_detected, unresolved, marked_as_resolved, risk_accepted, ignored, marked_as_false_positive, not_applicable, verified_resolved
results[].accountobject
results[].added_atstring
date-time
results[].passwordstring
results[].password_analysisobject
results[].targetobject

Paginated. See Getting Started → Pagination.

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
pagenumber1
page_sizenumber25
result_countnumber21
resultsarray<object>
results[].idstring"000000000000000e37e30001"
results[].urlstring"https://www.fernhill.example/"
results[].statestring"unresolved"
results[].accountobject
results[].account.idstring"000000000000000ec9430001"
results[].account.emailstring
results[].account.domainstring"acme.example"
results[].account.is_executivebooleanfalse
results[].account.first_namenull
results[].account.last_namenull
results[].account.titlenull
results[].account.linkedin_urlnull
results[].account.departmentnull
results[].added_atstring"2025-06-01T08:00:00Z"
results[].passwordstring
results[].password_analysisobject
results[].password_analysis.strengthobject
results[].password_analysis.strength.levelnumber0
results[].password_analysis.strength.scorenumber25
results[].password_analysis.strength.labelstring"Very Weak"
results[].password_analysis.strength.entropy_bitsnumber20.5
results[].password_analysis.compositionobject
results[].password_analysis.composition.lengthnumber8
results[].password_analysis.composition.structurestring
results[].password_analysis.composition.character_classes_usednumber3
results[].password_analysis.composition.contains_uppercasebooleantrue
results[].password_analysis.composition.contains_lowercasebooleantrue
results[].password_analysis.composition.contains_numberbooleantrue
results[].password_analysis.composition.contains_specialbooleanfalse
results[].password_analysis.composition.starts_with_uppercasebooleanfalse
results[].password_analysis.composition.ends_with_numbersbooleanfalse
results[].password_analysis.composition.ends_with_specialbooleanfalse
results[].password_analysis.patternsobject
results[].password_analysis.patterns.has_keyboard_patternbooleanfalse
results[].password_analysis.patterns.has_date_patternbooleanfalse
results[].password_analysis.patterns.has_leet_speakbooleanfalse
results[].password_analysis.patterns.has_sequential_charsbooleanfalse
results[].password_analysis.patterns.has_repeated_charsbooleanfalse
results[].password_analysis.dictionary_matchobject
results[].password_analysis.dictionary_match.is_common_passwordbooleanfalse
results[].password_analysis.dictionary_match.common_password_ranknull
results[].password_analysis.dictionary_match.is_dictionary_wordbooleanfalse
results[].password_analysis.dictionary_match.dictionary_word_foundnull
results[].targetobject
results[].target.urlstring"https://www.fernhill.example/"
results[].target.url_rawstring"https://www.fernhill.example/"
results[].target.fqdnstring"www.fernhill.example"
results[].target.domainstring"fernhill.example"
results[].target.servicestring"Webmail"
results[].target.platformstring"Web"
results[].target.main_categorystring | null"Email"
results[].target.sub_categorystring | null"Email"
results[].target.risk_tierstring | null"LOW"
results[].target.is_corporatebooleanfalse
results[].target.requires_mfa_by_defaultboolean | nulltrue

Examples

Selecting one loads it into the request and response panels.

Reference updated