Skip to main content
POST
Search leaked credentials

Quick Start

Authentication

Include your API key in the X-API-KEY header:

Overview

Search for leaked credentials matching an email domain, email address, or wallet address tracked on a brand.
Results may contain plaintext passwords. Always use HTTPS, restrict and rotate API keys, and do not log response bodies or expose them to unauthorized users.

Notes

  • slug and brandId are required. Find a brand’s ID in List Organization Brands. The caller must have organization access and be an owner, admin, or staff member. Dark Web Monitoring must be enabled.
  • kind must be domain, email, or crypto; target must be tracked on the brand. Email targets are normalized to lowercase; use a raw wallet address.
  • The response includes the normalized target, result counts, and matching credential records. Passwords may be null; sensitive values in results must be handled securely.
  • Returns 400 for invalid or untracked targets, 401 when unauthenticated, 403 without permission or when monitoring is disabled, and 404 when the organization cannot be found.

Authorizations

X-API-KEY
string
header
required

Your API key. This is required by most endpoints to access our API programatically. Reach out to us at support@chainpatrol.io to get an API key for your use.

Body

application/json
slug
string
required

Organization slug

Minimum string length: 1
brandId
integer
required

Brand ID

Required range: x > 0
kind
enum<string>
required

Entity type to search

Available options:
domain,
email,
crypto
target
string
required

Allowlisted brand target to search

Minimum string length: 1

Response

Successful response

kind
enum<string>
required
Available options:
domain,
email,
crypto
target
string
required
resultCount
integer
required
Required range: x >= 0
loadedCount
integer
required
Required range: x >= 0
results
object[]
required