Skip to main content

Base URL

All API requests are made to:
HTTPS only. Every response is sent with Cache-Control: no-store.

Authentication

Every endpoint needs your API key, in the Authorization header (recommended) or in X-API-Key:
Never put the key in the URL: a key, api_key, apikey, token or access_token query parameter is refused with 400 api_key_in_url. See Authentication. Get your API keyOpen Dashboard → API to copy your key, or regenerate it.

API families

{module} is one of six search slugs, grouped in this reference as:
  • IntelX Modules, powered by our search provider Intelligence X: intelligence-search, phonebook, identity-portal, system-id, storage-id — plus Stealer Export, which has its own endpoint because it answers with a file.
  • FindLy Module: breach-search, on the breach index Find.ly runs itself, with its own daily quota.
All six search pages of this reference are the same route; each has its own page because each module takes a different body and returns a different shape. See Modules and inputs.

Requests

  • Searches and exports are POST with a JSON object body of 16 KB or less. Content-Type: application/json is recommended but not required.
  • Unknown fields are rejected with 422 invalid_input, so a typo is reported instead of ignored.
  • The only query parameter the API reads is format: ?format=txt on Phonebook, System ID and Storage ID. Other parameters are ignored, except key-like ones, which are refused (see above). See Raw files and text output.
  • A method an endpoint does not support (for example GET on a search) returns 405 Method Not Allowed.

Success responses

Envelope example

A successful search returns JSON with module, the results, billed and usage — the quota the call drew from, after the call:
The same facts travel in headers, on JSON and text responses alike:

Plain text example

With ?format=txt, the same search returns a text/plain; charset=utf-8 attachment at the same price. An empty result is 204 No Content.

File example

POST /api/v1/stealer-export answers with the archive itself (Content-Type: application/zip). See Stealer Export.

Error handling

Every error has the same JSON shape, and no error uses a request:
Branch on error.code, never on message. The full list, with every 429 reason, is in Errors.

Quotas and plans

  • Free has no API access. On Starter, the key only opens POST /api/v1/search/breach-search and GET /api/v1/usage; any other search module returns 403 plan_required.
  • IntelX modules and Stealer Export draw from the IntelX quota; Breach Search from its own bucket. Spending one never touches the other.
  • Both reset every day at 02:00 Europe/Paris. The dashboard and the API share them.
  • Per account: 2 searches running at once and 20 per minute, IntelX and Breach Search together. Per IP address: 60 API calls per minute.
See Billing and quotas and Rate limits.

OpenAPI specification

The endpoint pages of this reference are generated from an OpenAPI 3.1 file: openapi.json. Import it into your HTTP client or code generator to get every request body, response schema and error code.