Skip to main content
POST
Exposed API Keys
Exposed API Keys scans text you already collected for API keys, tokens, and other credentials. POST /api/lookup/breaches/exposed-keys Requires an Encrata API key in the Authorization header.

Request

string
required
The text to scan. Send a crawled page, paste, message, or dump. The maximum size is 256 KB per request.
integer
default:"0"
Detection profile: 0 uses the standard engine, 1 uses the alternate engine, and 2 runs both and merges duplicate findings.
string
A label for the source, such as crawler, paste, or telegram. It appears in activity history and does not affect detection.
object
Optional detection and validation settings.
This endpoint scans only the supplied content. It does not fetch a URL. Use GitHub Leaks to scan a public repository and its history.

Example

Response

The endpoint always runs synchronously. A 200 OK response uses the {success, result, message} envelope.
boolean
Whether the scan completed.
string
A human-readable summary of the result.
object
The scan result.

Read a stored scan

Read a previous result without rescanning or charging again:
The optional min_severity query filters stored findings. It does not run the scanner again.

Errors

Credits

You pay 1 credit per exposed credential found. A clean scan is free. Submitting identical content with the same configuration reuses the stored scan, so your account is not charged twice. See Credits.