Skip to main content
The Lookup API returns a rich profile object across identity, work, education, social, company, and security categories. You can request specific fields using the fields parameter, or omit it to get everything.
In the Sandbox, hover over any field name to see a short description. This page provides the full reference.

How field selection works

Pass a fields array in your request body to receive only the data you need. This reduces response size and speeds up processing.
If fields is omitted or empty, all fields are returned.

Data sources

Encrata aggregates data from multiple sources in a single API call:

Person fields

Core identity and demographic data about the person.

Work fields

Professional and career information.

Education fields

Academic background.

Social fields

Links to social media profiles. These are nested at person.socials.<field>. There are no top-level social fields. Empty string if not found.

Company fields

Structured data about the person’s employer, nested at person.company_info.<field>. There are no flat company_* fields.

Security fields

Email security, breach exposure, and account detection.

validity

Email deliverability status. Returns a single string value.

breach_info

Data breach history from aggregated breach databases. Returns an object. Each item in services:

registered_services

Detects which online services the email is registered on by probing login, registration, and password-reset flows across 219+ platforms (GitHub, Spotify, Netflix, Adobe, etc.).
Recovery data (partial emails/phones like s***a@outlook.com or +1***456) may be exposed by platforms during password reset flows. This is public information but should be handled carefully.

Dedicated endpoint responses

The fields above describe the full identity lookup (POST /api/lookup/email/identity), which returns everything in one call. Encrata also exposes focused, single-purpose endpoints that return only their own compact response. Use these when you need one signal quickly and cheaply. Each endpoint’s full response schema lives on its reference page, linked below.
Every endpoint bills 1 credit on the first lookup of an address, then serves free repeats within the charge window. credits reports what the call actually billed (0 on a free repeat). cached is a separate performance signal: a cached result is still billed on your first lookup of that address.

Email Validity

POST /api/lookup/email/validity verifies whether an address can receive mail and enriches the domain behind it.
validity is also returned as a top-level alias of status for backward compatibility with older clients.

Email Gender

POST /api/lookup/email/gender infers the most likely gender and country behind an address.

Email Breaches

POST /api/lookup/email/breaches returns the breach exposure (HIBP) for an address. breach_info object:

Email Compliance

POST /api/lookup/email/compliance tells you whether it is legally safe to email an address and which laws apply.
checking and result_id are omitted when they are false / 0, so a settled verdict has neither key. While checking is true the verdict is provisional - repeat the request to get the settled one. The repeat is free within the billing window. There is no webhook event for this.

Password Breaches

POST /api/lookup/email/password/breaches checks whether a password appears in known breaches using HIBP k-anonymity. The plaintext password is never sent; only the first 5 characters of its SHA-1 hash leave the server.

GitHub Leaks

POST /api/lookup/breaches/github scans a public GitHub repository for leaked secrets. Returns the { success, result, message } envelope, with the fields below inside result. Each item in findings:
A GitHub Leaks scan with zero findings is a success, not an error, and is free. Scans are always asynchronous: a new scan returns 202 with status: "processing", and you poll GET /api/lookup/breaches/github/{id} for the findings.

Response structure

The full API response wraps fields inside the person object:
Most person fields are serialized even when empty: expect "" for unresolved strings and null for unresolved lists. Check for a truthy value rather than for the key’s presence.