Compromised Payment Credential Revert
https://api.deepinfo.com/v1/cti/compromised-payment-credentials/search:revertReverts the compromised payment credentials that match filters to their previous, active state. Only states set by a user can be reverted.
The action applies to every record matching filters. Always send a filter (for example by id); an empty filter matches all records.
State changes are applied asynchronously: the new state is visible a few seconds after the response. The response body only reports how many records matched.
Authentication
Send your API key in the apikey request header.
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "newly_detected"
}
]
}
}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "pan_last_four",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith contains_ contains_ exists
| Field | Description |
|---|---|
pan | The full card number (primary account number) found in the leak. Treat it as sensitive. |
pan_ | The card number in masked form, with part of the digits hidden. |
pan_ | The last four digits of the card number. |
bin | The card's bank identification number (BIN), the leading digits of the card number that identify the issuer. |
dedup_ | A de-duplication key for the card record. |
card_ | The card brand: visa, mastercard, amex, discover or unionpay. |
card_ | The card type: credit, debit or prepaid. |
card_ | The card's product level: classic, gold, world, platinum, business, signature, standard or enhanced. |
issuer_ | The name of the card's issuer. |
issuer_ | The country of the card's issuer. |
check_ | The result of checking the card: approved, declined or unknown, which is the default. |
confidence | The platform's confidence level for the record: high, medium or low (CONFIDENCE). |
leak_ | The names of the leaks the card was found in, as a list. |
source_ | The address of the source where the card was found. |
harvest_ | The address the card record was harvested (collected) from, recorded separately from source_url. |
state | The card record's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you). |
Operators eq in gte lte exists
| Field | Description |
|---|---|
expiry_ | The card's expiry year; it can be empty. |
expiry_ | The card's expiry month, as a number; it can be empty. |
first_ | When the card was first seen (UTC date-time). |
last_ | When the card was last seen, shown as LAST SEEN (UTC date-time). |
times_ | How many times the card was seen (TIMES SEEN). |
hackishness | The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results. |
co_ | The number of cards listed together with this card in its source. |
Operators eq exists
| Field | Description |
|---|---|
luhn_ | Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass. |
has_ | Whether the leaked record includes the card's security code (CVV). |
is_ | Whether the card has been validated as live. |
Operators Not measured
| Field | Description |
|---|---|
source_ | The kind of source the card was found in: structured_dump, checker_bot, stealer_log, bare_ccn or other. |
network | Network names recorded for the card record, as a list of strings. |
Sortable Fields
| Field | Description |
|---|---|
pan_ | The last four digits of the card number. |
bin | The card's bank identification number (BIN), the leading digits of the card number that identify the issuer. |
expiry_ | The card's expiry year; it can be empty. |
card_ | The card brand: visa, mastercard, amex, discover or unionpay. |
issuer_ | The country of the card's issuer. |
check_ | The result of checking the card: approved, declined or unknown, which is the default. |
confidence | The platform's confidence level for the record: high, medium or low (CONFIDENCE). |
source_ | The kind of source the card was found in: structured_dump, checker_bot, stealer_log, bare_ccn or other. |
first_ | When the card was first seen (UTC date-time). |
last_ | When the card was last seen, shown as LAST SEEN (UTC date-time). |
times_ | How many times the card was seen (TIMES SEEN). |
hackishness | The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results. |
co_ | The number of cards listed together with this card in its source. |
state | The card record's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you). |
Response Fields
| Field | Type |
|---|---|
count | integer |
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
count | number | 1 |
Examples
Selecting one loads it into the request and response panels.