Email Breaches
curl --request POST \
--url https://developer.encrata.com/api/lookup/email/breaches \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"email": "<string>"
}
'import requests
url = "https://developer.encrata.com/api/lookup/email/breaches"
payload = { "email": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({email: '<string>'})
};
fetch('https://developer.encrata.com/api/lookup/email/breaches', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://developer.encrata.com/api/lookup/email/breaches",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'email' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://developer.encrata.com/api/lookup/email/breaches"
payload := strings.NewReader("{\n \"email\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://developer.encrata.com/api/lookup/email/breaches")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"email\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://developer.encrata.com/api/lookup/email/breaches")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"email\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"email": "safe@example.com",
"breached": false,
"breach_info": {
"breach_count": 0,
"services": [],
"interests": []
},
"credits": 1
}
{
"email": "user@example.com",
"breached": true,
"breach_info": {
"breach_count": 3,
"services": [
{ "name": "LinkedIn", "domain": "linkedin.com", "breach_date": "2012-05-05", "data_types": ["Email addresses", "Passwords"] },
{ "name": "Adobe", "domain": "adobe.com", "breach_date": "2013-10-04", "data_types": ["Email addresses", "Usernames"] },
{ "name": "Dropbox", "domain": "dropbox.com", "breach_date": "2012-07-01", "data_types": ["Email addresses", "Passwords"] }
],
"exposed_data": ["Email addresses", "Passwords", "Usernames"],
"interests": [{ "category": "Professional", "signal": 1 }]
},
"credits": 1
}
{
"error": "You don't have enough credits for this lookup. Top up to continue.",
"code": "insufficient_credits"
}
Email
Email Breaches
Check if an email has been exposed in known data breaches. 1 credit, with free repeats for 6 months.
POST
/
api
/
lookup
/
email
/
breaches
Email Breaches
curl --request POST \
--url https://developer.encrata.com/api/lookup/email/breaches \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"email": "<string>"
}
'import requests
url = "https://developer.encrata.com/api/lookup/email/breaches"
payload = { "email": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({email: '<string>'})
};
fetch('https://developer.encrata.com/api/lookup/email/breaches', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://developer.encrata.com/api/lookup/email/breaches",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'email' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://developer.encrata.com/api/lookup/email/breaches"
payload := strings.NewReader("{\n \"email\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://developer.encrata.com/api/lookup/email/breaches")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"email\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://developer.encrata.com/api/lookup/email/breaches")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"email\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"email": "safe@example.com",
"breached": false,
"breach_info": {
"breach_count": 0,
"services": [],
"interests": []
},
"credits": 1
}
{
"email": "user@example.com",
"breached": true,
"breach_info": {
"breach_count": 3,
"services": [
{ "name": "LinkedIn", "domain": "linkedin.com", "breach_date": "2012-05-05", "data_types": ["Email addresses", "Passwords"] },
{ "name": "Adobe", "domain": "adobe.com", "breach_date": "2013-10-04", "data_types": ["Email addresses", "Usernames"] },
{ "name": "Dropbox", "domain": "dropbox.com", "breach_date": "2012-07-01", "data_types": ["Email addresses", "Passwords"] }
],
"exposed_data": ["Email addresses", "Passwords", "Usernames"],
"interests": [{ "category": "Professional", "signal": 1 }]
},
"credits": 1
}
{
"error": "You don't have enough credits for this lookup. Top up to continue.",
"code": "insufficient_credits"
}
Overview
Email Breaches tells you whether an address has been exposed in known data breaches, which services leaked it, and what kinds of data were exposed (passwords, email addresses, usernames, and more). It returns a canonical breach object shared with the dashboard, so this endpoint, the CLI, and the app all report identical fields. Use it to flag risky accounts or enrich a contact with exposure signal. Check a single address here (1 credit), or run a whole list through the bulk job pipeline below.Only need a yes/no answer?
POST /api/lookup/email/breaches/check returns
whether the address is breached for 0 credits. It does not return the
breach detail documented on this page.Authentication
Requires an API key in theAuthorization header.
Authorization: Bearer YOUR_API_KEY
Request
string
required
The email address to check for data breaches.
Example request
curl -X POST "https://developer.encrata.com/api/lookup/email/breaches" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email": "test@example.com"}'
import requests
resp = requests.post(
"https://developer.encrata.com/api/lookup/email/breaches",
headers={"Authorization": "Bearer YOUR_API_KEY"},
json={"email": "test@example.com"},
)
print(resp.json())
const resp = await fetch("https://developer.encrata.com/api/lookup/email/breaches", {
method: "POST",
headers: {
Authorization: "Bearer YOUR_API_KEY",
"Content-Type": "application/json",
},
body: JSON.stringify({ email: "test@example.com" }),
});
const data = await resp.json();
Response
Returns the canonical breach shape shared with the dashboard, so the CLI and this endpoint all return identical fields.string
The email address that was checked.
boolean
Whether the email appears in one or more known breaches.
object
The canonical breach detail object. Can serialize as
null when no breach
record was produced.Show breach_info
Show breach_info
number
Number of known data breaches the email appears in.
object[]
Breached services. Each entry has
name, plus domain, breach_date,
and data_types when known - those three are omitted when empty.string[]
Aggregated data types exposed across all breaches (e.g.
["Passwords", "Email addresses"]).
Omitted when empty.object[]
Inferred interest categories, each
{ category, signal }, derived from
which services the email was breached on.number
Credits charged for this request.
1 on a fresh charge, or 0 when you were
already charged for this address within the billing window (a free repeat).Errors
Errors return a JSON body of the form{"error": "<message>", "code": "<code>"}
with the matching HTTP status code.
| Status | Message | Cause |
|---|---|---|
400 | Invalid request body | Malformed JSON |
400 | Invalid email address | Address fails syntax parsing |
401 | API key required / bad key | Missing or invalid API key |
401 | Unauthorized | The key’s account could not be resolved |
402 | You don't have enough credits for this lookup. Top up to continue. | Not enough credits and not a free repeat |
405 | Only POST method is allowed | Wrong HTTP method |
413 | body too large | Request body exceeds 1 MiB |
500 | internal error | Unexpected server failure |
502 | Breach lookup failed. Please try again. | Transient provider error, retry shortly |
503 | Breach lookup is temporarily unavailable | Breach provider not configured |
Credits
Each check costs 1 credit. Billing is per-customer: 1 on the first check of an address,0 for repeats within the billing window. See Credits.
{
"email": "safe@example.com",
"breached": false,
"breach_info": {
"breach_count": 0,
"services": [],
"interests": []
},
"credits": 1
}
{
"email": "user@example.com",
"breached": true,
"breach_info": {
"breach_count": 3,
"services": [
{ "name": "LinkedIn", "domain": "linkedin.com", "breach_date": "2012-05-05", "data_types": ["Email addresses", "Passwords"] },
{ "name": "Adobe", "domain": "adobe.com", "breach_date": "2013-10-04", "data_types": ["Email addresses", "Usernames"] },
{ "name": "Dropbox", "domain": "dropbox.com", "breach_date": "2012-07-01", "data_types": ["Email addresses", "Passwords"] }
],
"exposed_data": ["Email addresses", "Passwords", "Usernames"],
"interests": [{ "category": "Professional", "signal": 1 }]
},
"credits": 1
}
{
"error": "You don't have enough credits for this lookup. Top up to continue.",
"code": "insufficient_credits"
}
Bulk jobs
To check a whole list, submit it as a bulk job instead of looping this endpoint. One entrypoint handles every lookup - settype=email-breaches - and a
webhook delivers the finished file when it’s done.
curl -X POST "https://developer.encrata.com/api/jobs/bulk" \
-H "Authorization: Bearer YOUR_API_KEY" \
-F "type=email-breaches" \
-F "download_link=true" \
-F "file=@list.csv"
- Up to 1,000,000 emails per job, charged 1 credit per email (with free repeats).
download_link=truereturns adownload_urlin thebulk.completedwebhook; fetch it with your API key.- Export filters:
all,breached.
Was this page helpful?