Base URL
All API requests are made to:Cache-Control: no-store.
Authentication
Every endpoint needs your API key, in theAuthorization header (recommended) or in X-API-Key:
key, api_key, apikey, token or access_token query parameter is refused with 400 api_key_in_url. See Authentication.
Get your API keyOpen Dashboard → API to copy your key, or regenerate it.
API families
{module} is one of six search slugs, grouped in this reference as:
- IntelX Modules, powered by our search provider Intelligence X:
intelligence-search,phonebook,identity-portal,system-id,storage-id— plus Stealer Export, which has its own endpoint because it answers with a file. - FindLy Module:
breach-search, on the breach index Find.ly runs itself, with its own daily quota.
Requests
- Searches and exports are
POSTwith a JSON object body of 16 KB or less.Content-Type: application/jsonis recommended but not required. - Unknown fields are rejected with
422 invalid_input, so a typo is reported instead of ignored. - The only query parameter the API reads is
format:?format=txton Phonebook, System ID and Storage ID. Other parameters are ignored, except key-like ones, which are refused (see above). See Raw files and text output. - A method an endpoint does not support (for example
GETon a search) returns405 Method Not Allowed.
Success responses
Envelope example
A successful search returns JSON withmodule, the results, billed and usage — the quota the call drew from, after the call:
Plain text example
With?format=txt, the same search returns a text/plain; charset=utf-8 attachment at the same price. An empty result is 204 No Content.
File example
POST /api/v1/stealer-export answers with the archive itself (Content-Type: application/zip). See Stealer Export.
Error handling
Every error has the same JSON shape, and no error uses a request:
Branch on
error.code, never on message. The full list, with every 429 reason, is in Errors.
Quotas and plans
- Free has no API access. On Starter, the key only opens
POST /api/v1/search/breach-searchandGET /api/v1/usage; any other search module returns403 plan_required. - IntelX modules and Stealer Export draw from the IntelX quota; Breach Search from its own bucket. Spending one never touches the other.
- Both reset every day at 02:00 Europe/Paris. The dashboard and the API share them.
- Per account: 2 searches running at once and 20 per minute, IntelX and Breach Search together. Per IP address: 60 API calls per minute.
OpenAPI specification
The endpoint pages of this reference are generated from an OpenAPI 3.1 file:openapi.json. Import it into your HTTP client or code generator to get every request body, response schema and error code.
