POSThttps://api.deepinfo.com/v1/cti/compromised-payment-credentials/search:export

Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. Large exports can time out: narrow them with filters.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
formatOptional
One of: json, csv.
Examplecsv

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "pan_last_four",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith contains_any contains_all exists

FieldDescription
panThe full card number (primary account number) found in the leak. Treat it as sensitive.
pan_maskedThe card number in masked form, with part of the digits hidden.
pan_last_fourThe last four digits of the card number.
binThe card's bank identification number (BIN), the leading digits of the card number that identify the issuer.
dedup_keyA de-duplication key for the card record.
card_brandThe card brand: visa, mastercard, amex, discover or unionpay.
card_typeThe card type: credit, debit or prepaid.
card_levelThe card's product level: classic, gold, world, platinum, business, signature, standard or enhanced.
issuer_nameThe name of the card's issuer.
issuer_countryThe country of the card's issuer.
check_statusThe result of checking the card: approved, declined or unknown, which is the default.
confidenceThe platform's confidence level for the record: high, medium or low (CONFIDENCE).
leak_nameThe names of the leaks the card was found in, as a list.
source_urlThe address of the source where the card was found.
harvest_urlThe address the card record was harvested (collected) from, recorded separately from source_url.
stateThe card record's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you).

Operators eq in gte lte exists

FieldDescription
expiry_yearThe card's expiry year; it can be empty.
expiry_monthThe card's expiry month, as a number; it can be empty.
first_seenWhen the card was first seen (UTC date-time).
last_seenWhen the card was last seen, shown as LAST SEEN (UTC date-time).
times_seenHow many times the card was seen (TIMES SEEN).
hackishnessThe record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.
co_listed_card_countThe number of cards listed together with this card in its source.

Operators eq exists

FieldDescription
luhn_validWhether the card number passes the Luhn check, the check-digit test that valid card numbers pass.
has_cvvWhether the leaked record includes the card's security code (CVV).
is_validated_liveWhether the card has been validated as live.

Operators Not measured

FieldDescription
source_formatThe kind of source the card was found in: structured_dump, checker_bot, stealer_log, bare_ccn or other.
networkNetwork names recorded for the card record, as a list of strings.

Sortable Fields

FieldDescription
pan_last_fourThe last four digits of the card number.
binThe card's bank identification number (BIN), the leading digits of the card number that identify the issuer.
expiry_yearThe card's expiry year; it can be empty.
card_brandThe card brand: visa, mastercard, amex, discover or unionpay.
issuer_countryThe country of the card's issuer.
check_statusThe result of checking the card: approved, declined or unknown, which is the default.
confidenceThe platform's confidence level for the record: high, medium or low (CONFIDENCE).
source_formatThe kind of source the card was found in: structured_dump, checker_bot, stealer_log, bare_ccn or other.
first_seenWhen the card was first seen (UTC date-time).
last_seenWhen the card was last seen, shown as LAST SEEN (UTC date-time).
times_seenHow many times the card was seen (TIMES SEEN).
hackishnessThe record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.
co_listed_card_countThe number of cards listed together with this card in its source.
stateThe card record's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you).

Examples

Selecting one loads it into the request and response panels.

Reference updated