Exposed API Keys
curl --request POST \
--url https://developer.encrata.com/api/lookup/breaches/exposed-keys \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"content": "<string>",
"type": 123,
"source": "<string>",
"config": {
"rules": [
"<string>"
],
"min_severity": "<string>",
"baseline_fingerprints": [
"<string>"
],
"include_likely_false_positives": true,
"max_findings": 123,
"validate": true
}
}
'import requests
url = "https://developer.encrata.com/api/lookup/breaches/exposed-keys"
payload = {
"content": "<string>",
"type": 123,
"source": "<string>",
"config": {
"rules": ["<string>"],
"min_severity": "<string>",
"baseline_fingerprints": ["<string>"],
"include_likely_false_positives": True,
"max_findings": 123,
"validate": True
}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
content: '<string>',
type: 123,
source: '<string>',
config: {
rules: ['<string>'],
min_severity: '<string>',
baseline_fingerprints: ['<string>'],
include_likely_false_positives: true,
max_findings: 123,
validate: true
}
})
};
fetch('https://developer.encrata.com/api/lookup/breaches/exposed-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://developer.encrata.com/api/lookup/breaches/exposed-keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'content' => '<string>',
'type' => 123,
'source' => '<string>',
'config' => [
'rules' => [
'<string>'
],
'min_severity' => '<string>',
'baseline_fingerprints' => [
'<string>'
],
'include_likely_false_positives' => true,
'max_findings' => 123,
'validate' => true
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://developer.encrata.com/api/lookup/breaches/exposed-keys"
payload := strings.NewReader("{\n \"content\": \"<string>\",\n \"type\": 123,\n \"source\": \"<string>\",\n \"config\": {\n \"rules\": [\n \"<string>\"\n ],\n \"min_severity\": \"<string>\",\n \"baseline_fingerprints\": [\n \"<string>\"\n ],\n \"include_likely_false_positives\": true,\n \"max_findings\": 123,\n \"validate\": true\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://developer.encrata.com/api/lookup/breaches/exposed-keys")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"content\": \"<string>\",\n \"type\": 123,\n \"source\": \"<string>\",\n \"config\": {\n \"rules\": [\n \"<string>\"\n ],\n \"min_severity\": \"<string>\",\n \"baseline_fingerprints\": [\n \"<string>\"\n ],\n \"include_likely_false_positives\": true,\n \"max_findings\": 123,\n \"validate\": true\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://developer.encrata.com/api/lookup/breaches/exposed-keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"content\": \"<string>\",\n \"type\": 123,\n \"source\": \"<string>\",\n \"config\": {\n \"rules\": [\n \"<string>\"\n ],\n \"min_severity\": \"<string>\",\n \"baseline_fingerprints\": [\n \"<string>\"\n ],\n \"include_likely_false_positives\": true,\n \"max_findings\": 123,\n \"validate\": true\n }\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"message": "<string>",
"result": {
"scan_id": "<string>",
"repository_id": "<string>",
"kind": "<string>",
"target": "<string>",
"type": 123,
"commit_sha": "<string>",
"depth": 123,
"config": {},
"summary": {
"total": 123,
"by_severity": {},
"by_engine": {},
"engines_run": [
"<string>"
],
"rules_requested": 123,
"deep_scan": true,
"duration_ms": 123,
"suppressed": 123,
"validated": 123,
"live": 123,
"truncated": true
},
"findings": [
{
"fingerprint": "<string>",
"rule_id": "<string>",
"description": "<string>",
"severity": "<string>",
"severity_source": "<string>",
"engines": [
"<string>"
],
"file": "<string>",
"start_line": 123,
"end_line": 123,
"column": 123,
"preview": "<string>",
"entropy": 123,
"commit": "<string>",
"author": "<string>",
"email": "<string>",
"date": "<string>",
"likely_false_positive": true,
"validation": {
"status": "<string>",
"confidence": 123,
"checked_at": "<string>"
}
}
],
"reused": true,
"charged": true,
"credits": 123,
"status": "<string>"
}
}Breaches
Exposed API Keys
Scan collected text for exposed credentials and check whether supported credentials are still live.
POST
/
api
/
lookup
/
breaches
/
exposed-keys
Exposed API Keys
curl --request POST \
--url https://developer.encrata.com/api/lookup/breaches/exposed-keys \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"content": "<string>",
"type": 123,
"source": "<string>",
"config": {
"rules": [
"<string>"
],
"min_severity": "<string>",
"baseline_fingerprints": [
"<string>"
],
"include_likely_false_positives": true,
"max_findings": 123,
"validate": true
}
}
'import requests
url = "https://developer.encrata.com/api/lookup/breaches/exposed-keys"
payload = {
"content": "<string>",
"type": 123,
"source": "<string>",
"config": {
"rules": ["<string>"],
"min_severity": "<string>",
"baseline_fingerprints": ["<string>"],
"include_likely_false_positives": True,
"max_findings": 123,
"validate": True
}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
content: '<string>',
type: 123,
source: '<string>',
config: {
rules: ['<string>'],
min_severity: '<string>',
baseline_fingerprints: ['<string>'],
include_likely_false_positives: true,
max_findings: 123,
validate: true
}
})
};
fetch('https://developer.encrata.com/api/lookup/breaches/exposed-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://developer.encrata.com/api/lookup/breaches/exposed-keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'content' => '<string>',
'type' => 123,
'source' => '<string>',
'config' => [
'rules' => [
'<string>'
],
'min_severity' => '<string>',
'baseline_fingerprints' => [
'<string>'
],
'include_likely_false_positives' => true,
'max_findings' => 123,
'validate' => true
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://developer.encrata.com/api/lookup/breaches/exposed-keys"
payload := strings.NewReader("{\n \"content\": \"<string>\",\n \"type\": 123,\n \"source\": \"<string>\",\n \"config\": {\n \"rules\": [\n \"<string>\"\n ],\n \"min_severity\": \"<string>\",\n \"baseline_fingerprints\": [\n \"<string>\"\n ],\n \"include_likely_false_positives\": true,\n \"max_findings\": 123,\n \"validate\": true\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://developer.encrata.com/api/lookup/breaches/exposed-keys")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"content\": \"<string>\",\n \"type\": 123,\n \"source\": \"<string>\",\n \"config\": {\n \"rules\": [\n \"<string>\"\n ],\n \"min_severity\": \"<string>\",\n \"baseline_fingerprints\": [\n \"<string>\"\n ],\n \"include_likely_false_positives\": true,\n \"max_findings\": 123,\n \"validate\": true\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://developer.encrata.com/api/lookup/breaches/exposed-keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"content\": \"<string>\",\n \"type\": 123,\n \"source\": \"<string>\",\n \"config\": {\n \"rules\": [\n \"<string>\"\n ],\n \"min_severity\": \"<string>\",\n \"baseline_fingerprints\": [\n \"<string>\"\n ],\n \"include_likely_false_positives\": true,\n \"max_findings\": 123,\n \"validate\": true\n }\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"message": "<string>",
"result": {
"scan_id": "<string>",
"repository_id": "<string>",
"kind": "<string>",
"target": "<string>",
"type": 123,
"commit_sha": "<string>",
"depth": 123,
"config": {},
"summary": {
"total": 123,
"by_severity": {},
"by_engine": {},
"engines_run": [
"<string>"
],
"rules_requested": 123,
"deep_scan": true,
"duration_ms": 123,
"suppressed": 123,
"validated": 123,
"live": 123,
"truncated": true
},
"findings": [
{
"fingerprint": "<string>",
"rule_id": "<string>",
"description": "<string>",
"severity": "<string>",
"severity_source": "<string>",
"engines": [
"<string>"
],
"file": "<string>",
"start_line": 123,
"end_line": 123,
"column": 123,
"preview": "<string>",
"entropy": 123,
"commit": "<string>",
"author": "<string>",
"email": "<string>",
"date": "<string>",
"likely_false_positive": true,
"validation": {
"status": "<string>",
"confidence": 123,
"checked_at": "<string>"
}
}
],
"reused": true,
"charged": true,
"credits": 123,
"status": "<string>"
}
}Exposed API Keys scans text you already collected for API keys, tokens, and other credentials.
The optional
POST /api/lookup/breaches/exposed-keys
Requires an Encrata API key in the Authorization header.
Request
string
required
The text to scan. Send a crawled page, paste, message, or dump. The maximum
size is 256 KB per request.
integer
default:"0"
Detection profile:
0 uses the standard engine, 1 uses the alternate
engine, and 2 runs both and merges duplicate findings.string
A label for the source, such as
crawler, paste, or telegram. It
appears in activity history and does not affect detection.object
Optional detection and validation settings.
Show config
Show config
string[]
Run only the specified detection rule IDs. Omit this field to run every
available rule.
string
Return findings at or above
critical, high, medium, or low.string[]
Suppress findings you have already reviewed.
boolean
Include findings flagged as likely false positives.
integer
Limit the number of findings returned.
boolean
Check whether supported credentials still work. Omit this field to use the
deployment default. Set it to
false for detection only.This endpoint scans only the supplied
content. It does not fetch a URL.
Use GitHub Leaks to scan a public
repository and its history.Example
curl -X POST "https://developer.encrata.com/api/lookup/breaches/exposed-keys" \
-H "Authorization: Bearer enc_xxxxxxxxxxxx" \
-H "Content-Type: application/json" \
-d '{
"content": "AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE",
"source": "crawler",
"config": {
"validate": true,
"min_severity": "medium"
}
}'
import requests
response = requests.post(
"https://developer.encrata.com/api/lookup/breaches/exposed-keys",
headers={"Authorization": "Bearer enc_xxxxxxxxxxxx"},
json={
"content": "AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE",
"source": "crawler",
"config": {"validate": True, "min_severity": "medium"},
},
)
response.raise_for_status()
print(response.json())
Response
The endpoint always runs synchronously. A200 OK response uses the
{success, result, message} envelope.
{
"success": true,
"result": {
"scan_id": "8f4ae53c-8b72-4d63-93ef-5bb369a8e351",
"repository_id": "3edce238-986c-4897-b088-826791967f52",
"kind": "keys",
"target": "sha256:8a2ff5c3...",
"type": 0,
"commit_sha": "8a2ff5c3...",
"depth": 0,
"config": {
"min_severity": "medium",
"validate": true
},
"summary": {
"total": 1,
"by_severity": {"high": 1},
"by_engine": {"encrata intelligence": 1},
"engines_run": ["encrata intelligence"],
"rules_requested": 0,
"duration_ms": 84,
"suppressed": 0,
"validated": 1,
"live": 0,
"truncated": false
},
"findings": [
{
"fingerprint": "b9d1...e2",
"rule_id": "aws-access-key-id",
"description": "AWS access key ID",
"severity": "high",
"severity_source": "engine",
"engines": ["encrata intelligence"],
"start_line": 1,
"end_line": 1,
"column": 19,
"preview": "AKIA****************",
"entropy": 3.8,
"likely_false_positive": false,
"validation": {
"status": "invalid",
"confidence": 1,
"checked_at": "2026-10-07T09:30:00Z"
}
}
],
"reused": false,
"charged": true,
"credits": 1
},
"message": "Scan complete. 1 exposed credential found."
}
boolean
Whether the scan completed.
string
A human-readable summary of the result.
object
The scan result.
Show result
Show result
string
The stored scan ID.
string
The internal target ID used to store and authorize the result.
string
Always
keys for this endpoint.string
A SHA-256 identifier for the submitted content. The raw content is not
stored in this field.
integer
The detection profile that ran:
0, 1, or 2.string
The SHA-256 digest of the submitted content.
integer
Always
0. Text scans have no repository history.object
The effective configuration used for the scan.
object
Counts and timing for the scan.
Show summary
Show summary
integer
Number of findings returned.
object
Finding counts grouped by severity.
object
Finding counts grouped under
encrata intelligence.string[]
Detection sources that ran.
integer
Number of requested rules.
0 means every available rule.boolean
Omitted for this endpoint because text has no repository history.
integer
Scan duration in milliseconds.
integer
Findings removed by rules, severity filters, or baseline fingerprints.
integer
Findings that received a validation verdict.
integer
Validated credentials that still work.
boolean
Whether
max_findings truncated the result.object[]
Detected credentials. Raw credentials are never returned.
Show finding
Show finding
string
Stable hash-derived ID for deduplication and baselines.
string
Detection rule that matched.
string
Human-readable finding type.
string
critical, high, medium, low, or unknown.string
engine or unreported.string[]
Detection sources that reported the location.
string
Source file name when the submitted text includes file context.
integer
1-based first line of the match.
integer
1-based last line of the match.
integer
1-based starting column.
string
Masked preview of the credential.
number
Shannon entropy of the match.
string
Commit SHA when source context contains one.
string
Commit author when source context contains one.
string
Commit author email when source context contains one.
string
Commit timestamp when source context contains one.
boolean
Whether the finding is flagged as a likely false positive.
boolean
Whether an existing scan of identical content and configuration answered
the request.
boolean
Whether the request deducted credits.
integer
Credits deducted. The cost is one credit per finding.
string
Omitted for this synchronous endpoint.
Read a stored scan
Read a previous result without rescanning or charging again:curl "https://developer.encrata.com/api/lookup/breaches/exposed-keys/{scan_id}?min_severity=high" \
-H "Authorization: Bearer enc_xxxxxxxxxxxx"
min_severity query filters stored findings. It does not run the
scanner again.
Errors
| Status | Cause |
|---|---|
400 | The JSON body cannot be read. |
401 | The API key is missing or invalid. |
402 | The account has no available credits. |
413 | content exceeds 256 KB. |
422 | content is empty, type is outside 0-2, or a repository-only option was sent. |
502 | The scanner could not complete the request. |
503 | Secret scanning or the selected detection profile is unavailable. |
504 | The scan exceeded its time limit. |
Credits
You pay 1 credit per exposed credential found. A clean scan is free. Submitting identical content with the same configuration reuses the stored scan, so your account is not charged twice. See Credits.Was this page helpful?