> ## Documentation Index
> Fetch the complete documentation index at: https://chainpatrol.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Search Dark Web Credentials

> Search for leaked credentials tied to an allowlisted brand target. Passwords are returned in plaintext when available. Treat the response as sensitive, use TLS, and never log response bodies.

## Quick Start

### Authentication

Include your API key in the `X-API-KEY` header:

```bash theme={null}
X-API-KEY: <api-key>
```

## Overview

Search for leaked credentials matching an email domain, email address, or wallet address
tracked on a brand.

<Warning>
  Results may contain plaintext passwords. Always use HTTPS, restrict and rotate API keys,
  and do not log response bodies or expose them to unauthorized users.
</Warning>

## Notes

* `slug` and `brandId` are required. Find a brand's ID in
  [List Organization Brands](/docs/external-api/organization-brands). The caller must have
  organization access and be an owner, admin, or staff member. Dark Web Monitoring must
  be enabled.
* `kind` must be `domain`, `email`, or `crypto`; `target` must be tracked on the brand.
  Email targets are normalized to lowercase; use a raw wallet address.
* The response includes the normalized target, result counts, and matching credential
  records. Passwords may be null; sensitive values in results must be handled securely.
* Returns `400` for invalid or untracked targets, `401` when unauthenticated, `403`
  without permission or when monitoring is disabled, and `404` when the organization
  cannot be found.


## OpenAPI

````yaml POST /dark-web/credentials/search
openapi: 3.0.3
info:
  title: ChainPatrol External API - OpenAPI 3.0
  description: ChainPatrol External API documentation
  version: 2.0.0
servers:
  - url: https://app.chainpatrol.io/api/v2
security: []
tags:
  - name: asset
  - name: report
  - name: dark-web
externalDocs:
  url: https://chainpatrol.com/docs
paths:
  /dark-web/credentials/search:
    post:
      tags:
        - dark-web
      summary: Search leaked credentials
      description: >-
        Search DarkOwl for leaked credentials tied to an allowlisted brand
        target. Passwords are returned in plaintext when available. Treat the
        response as sensitive, use TLS, and never log response bodies.
      operationId: darkWebCredentialsSearch
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                slug:
                  type: string
                  minLength: 1
                  description: Organization slug
                brandId:
                  type: integer
                  minimum: 0
                  exclusiveMinimum: true
                  description: Brand ID
                kind:
                  type: string
                  enum:
                    - domain
                    - email
                    - crypto
                  description: Entity type to search
                target:
                  type: string
                  minLength: 1
                  description: Allowlisted brand target to search
              required:
                - slug
                - brandId
                - kind
                - target
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  kind:
                    type: string
                    enum:
                      - domain
                      - email
                      - crypto
                  target:
                    type: string
                  resultCount:
                    type: integer
                    minimum: 0
                  loadedCount:
                    type: integer
                    minimum: 0
                  results:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        email:
                          type: string
                          nullable: true
                        address:
                          type: string
                          nullable: true
                        source:
                          type: string
                          nullable: true
                        leakName:
                          type: string
                          nullable: true
                        fragment:
                          type: string
                          nullable: true
                        crawlDate:
                          type: string
                          nullable: true
                        password:
                          type: string
                          nullable: true
                          description: >-
                            Plaintext leaked password when DarkOwl provides one.
                            Treat this response as sensitive and do not log it.
                        passwordType:
                          type: string
                          nullable: true
                      required:
                        - id
                        - email
                        - address
                        - source
                        - leakName
                        - fragment
                        - crawlDate
                        - password
                        - passwordType
                required:
                  - kind
                  - target
                  - resultCount
                  - loadedCount
                  - results
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.BAD_REQUEST'
        '401':
          description: Authorization not provided
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.UNAUTHORIZED'
        '403':
          description: Insufficient access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.FORBIDDEN'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.INTERNAL_SERVER_ERROR'
      security:
        - ApiKey: []
components:
  schemas:
    error.BAD_REQUEST:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Invalid input data
        code:
          type: string
          description: The error code
          example: BAD_REQUEST
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Invalid input data error (400)
      description: The error information
      example:
        code: BAD_REQUEST
        message: Invalid input data
        issues: []
    error.UNAUTHORIZED:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Authorization not provided
        code:
          type: string
          description: The error code
          example: UNAUTHORIZED
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Authorization not provided error (401)
      description: The error information
      example:
        code: UNAUTHORIZED
        message: Authorization not provided
        issues: []
    error.FORBIDDEN:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Insufficient access
        code:
          type: string
          description: The error code
          example: FORBIDDEN
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Insufficient access error (403)
      description: The error information
      example:
        code: FORBIDDEN
        message: Insufficient access
        issues: []
    error.INTERNAL_SERVER_ERROR:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Internal server error
        code:
          type: string
          description: The error code
          example: INTERNAL_SERVER_ERROR
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Internal server error error (500)
      description: The error information
      example:
        code: INTERNAL_SERVER_ERROR
        message: Internal server error
        issues: []
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: X-API-KEY
      description: >-
        Your API key. This is required by most endpoints to access our API
        programatically. Reach out to us at
        [support@chainpatrol.io](mailto:support@chainpatrol.io?subject=Re:%20API%20Key%20for%20SDK&body=Company:%20%0AName:%20%0APurpose:%20)
        to get an API key for your use.

````