fields parameter, or omit it to get everything.
How field selection works
Pass afields array in your request body to receive only the data you need. This reduces response size and speeds up processing.
fields is omitted or empty, all fields are returned.
Data sources
Encrata aggregates data from multiple sources in a single API call:Person fields
Core identity and demographic data about the person.Work fields
Professional and career information.Education fields
Academic background.Social fields
Links to social media profiles. These are nested atperson.socials.<field>.
There are no top-level social fields. Empty string if not found.
Company fields
Structured data about the person’s employer, nested atperson.company_info.<field>. There are no flat company_* fields.
Security fields
Email security, breach exposure, and account detection.validity
Email deliverability status. Returns a single string value.
breach_info
Data breach history from aggregated breach databases. Returns an object.
Each item in
services:
registered_services
Detects which online services the email is registered on by probing login, registration, and password-reset flows across 219+ platforms (GitHub, Spotify, Netflix, Adobe, etc.).
Dedicated endpoint responses
The fields above describe the full identity lookup (POST /api/lookup/email/identity), which returns everything in one call. Encrata also exposes focused, single-purpose endpoints that return only their own compact response. Use these when you need one signal quickly and cheaply. Each endpoint’s full response schema lives on its reference page, linked below.
Every endpoint bills 1 credit on the first lookup of an address, then serves free repeats within the charge window.
credits reports what the call actually billed (0 on a free repeat). cached is a separate performance signal: a cached result is still billed on your first lookup of that address.Email Validity
POST /api/lookup/email/validity verifies whether an address can receive mail and enriches the domain behind it.
validity is also returned as a top-level alias of status for backward compatibility with older clients.Email Gender
POST /api/lookup/email/gender infers the most likely gender and country behind an address.
Email Breaches
POST /api/lookup/email/breaches returns the breach exposure (HIBP) for an address.
breach_info object:
Email Compliance
POST /api/lookup/email/compliance tells you whether it is legally safe to email an address and which laws apply.
checking and result_id are omitted when they are false / 0, so a settled verdict has neither key. While checking is true the verdict is provisional - repeat the request to get the settled one. The repeat is free within the billing window. There is no webhook event for this.Password Breaches
POST /api/lookup/email/password/breaches checks whether a password appears in known breaches using HIBP k-anonymity. The plaintext password is never sent; only the first 5 characters of its SHA-1 hash leave the server.
GitHub Leaks
POST /api/lookup/breaches/github scans a public GitHub repository for leaked secrets. Returns the { success, result, message } envelope, with the fields below inside result.
Each item in
findings:
A GitHub Leaks scan with zero findings is a success, not an error, and is free. Scans are always asynchronous: a new scan returns
202 with status: "processing", and you poll GET /api/lookup/breaches/github/{id} for the findings.Response structure
The full API response wraps fields inside theperson object:
Most
person fields are serialized even when empty: expect "" for unresolved strings and null for unresolved lists. Check for a truthy value rather than for the key’s presence.