Skip to main content
Webhook API reference rewritten
Webhook management is documented at its real paths. The previous /api/account/webhooks paths were wrong and returned 404.
  • Fixed Every webhook endpoint now documents /api/webhooks*. Update any hard-coded /api/account/webhooks paths.
  • New Get webhook documents GET /api/webhooks/{id}, the only way to read a signing secret after creation.
  • Changed Responses are shown with the real {success, result, message} envelope instead of bare objects.
  • Changed Create webhook documents all four destination kinds (generic, slack, discord, telegram) and all eight subscribable events. The list previously showed five.
  • Changed Update webhook is a partial update: only id is required, and omitted fields keep their stored values.
  • Fixed Delivery status values are pending, retrying, delivered, and failed. The docs previously showed a success status that the API never returns.
  • Fixed The retry policy is 4 attempts at 30 seconds, 2 minutes, and 10 minutes, with a 10 second timeout per attempt. The old “respond within 5 seconds, exponential backoff” guidance was wrong.
  • Fixed Signing secrets are not create-only, and each endpoint now states the workspace role it requires.
Reference corrections and a dedicated Changelog
The API Reference now documents every response field for the breach lookups, and several routes, credit costs, and key formats are corrected to match the live API.
  • New Dedicated Changelog tab so you can track releases without digging through the guides.
  • Docs The Response Fields reference now documents the full response shapes for Password Breaches and GitHub Leaks, including every finding sub-field.
  • Changed API keys use the enc_ prefix. Docs and examples that showed enc_live_ have been corrected.
  • Fixed Credit costs are now consistent across the docs: Email Identity is 1,000 credits per lookup, while Validity, Breaches, Gender, and Compliance are 1 credit each with free repeats within the billing window.
  • Fixed The LangChain, LlamaIndex, CrewAI, and Haystack integration guides now call the canonical /api/lookup/email/... routes instead of the old /api/email/... paths.
Compliance and GitHub secret scanning
Two new lookups join the API, and every email route now documents its canonical path.
  • New Email Compliance: POST /api/lookup/email/compliance resolves which country’s cold-email law applies to an address and returns that jurisdiction’s rule and recommendation, with a confidence rating. 1 credit, with free repeats. See Email Compliance.
  • New GitHub Leaks: POST /api/lookup/breaches/github scans a public GitHub repository for leaked secrets, returning each finding with its location, a masked preview, and a severity. Billed one credit per leak found - a clean scan is free. See GitHub Leaks.
  • Changed Email lookup routes are now documented under their canonical /api/lookup/email/... paths (for example /api/lookup/email/validity), matching the API. Update any hard-coded /api/email/... paths.
  • Docs Refreshed the API overview with the new lookups, and corrected paths across the Quickstart, Credits, Rate limits, and authentication guides.
One endpoint for every bulk lookup, delivered by webhook
Run any bulk lookup from a single call and let a webhook hand you the finished file - no polling.
  • New Unified bulk endpoint: POST /api/jobs/bulk runs any lookup on a list. Set type to validity, identity, email-breaches, gender, or password-breaches, attach a file, and get a job id back immediately. See Bulk Operations.
  • New Webhook result delivery: submit with download_link=true and the bulk.completed webhook now carries a download_url. Fetch it with the same API key to get the finished file - it’s built once, cached, and ready the moment the job completes. See Webhooks.
  • New Email Gender in bulk: gender and country prediction now runs as an async job, like the rest of the email suite.
  • Improved Cursor pagination on job results: page through millions of rows with a cursor (alongside the existing page/page_size), so large result sets stay fast.
  • Fixed Bulk jobs now reliably fire their completion signal and bulk.completed webhook the instant the final chunk lands, across every lookup type.
  • Docs Refreshed the Bulk Operations guide, added a concise bulk section to every lookup in the API Reference, and corrected the routes on the API overview and Workflows pages.
  • Changed The canonical credit-balance endpoint is GET /api/account/credits. The legacy GET /api/agent/credits route remains an alias for compatibility; new integrations should use the account route. See Credits.
  • Note These endpoints are rolling out and will be fully available by end of day tomorrow.
  • Note We’re continuing to refine the API Reference for accuracy and consistency - thank you for your patience while this work is in progress. If you notice a discrepancy in the meantime, the endpoint’s live response is the authoritative schema.
API Reference improvements are underway
We’re refreshing our endpoint documentation to ensure it remains accurate, complete, and aligned with the current API. Updates will roll out incrementally over the coming days.
  • Docs We are updating the API Reference endpoints. This includes revised request and response schemas, updated examples, and clearer descriptions that reflect current behavior.
  • Note We appreciate your patience while this work is in progress. If you notice a discrepancy in the meantime, please refer to the endpoint’s response for the authoritative schema.
Email Breaches and Identity on the API, plus async breach jobs
The full email suite is now reachable with an API key, and breach checks scale to a million.
  • New Email Breaches on the agent API: POST /api/agent/breaches checks an email against known data breaches with an API key, returning the same breach_info shape (breach count, services, exposed data) as the dashboard. See Email Breaches.
  • New Email Identity on the agent API: POST /api/agent/email-identity resolves the person behind an email with an API key. See Email Identity.
  • New Async breach jobs: POST /api/agent/breaches-jobs checks up to 1,000,000 emails in the background, with status polling, paginated results, CSV download, cancel, and retry.
  • Docs API Reference corrections: accurate request/response schemas for API Keys and Webhooks, and the async “Bulk” sections now match the real per-batch limits.
Three new export destinations
Enriched records can now go straight to Airtable, Slack, and Notion.
  • New Airtable export: append enriched rows to any Airtable table. Pick your connected Airtable account, enter the base ID and table name, and rows are created in batches with automatic type coercion.
  • New Slack export: post a message to a Slack channel for each enriched record. Write your own message template with {{field}} placeholders, or leave it blank to post every column. Best paired with a Condition step so only the records you care about reach the channel.
  • New Notion export: create a page in a Notion database for each enriched record. Encrata reads the database schema and matches columns to properties by name, coercing values to the right property type (title, email, URL, number, select, and more).
  • Note All three connect from the Integrations page in one click with OAuth. Encrata never stores your third-party credentials.
Enrich files and send results to your apps
Upload a list, enrich every row, and push the results to Google Sheets, your CRM, a webhook, or a CSV.
  • New Bulk file enrichment: upload a list of emails (CSV, TXT, MD, XLS, or XLSX) to a workflow, enrich every row through your lookup steps, and download the results as a CSV. See Workflows.
  • New Export destinations: the new export step sends enriched records to a downloadable CSV, an inbound webhook (Zapier, Make, or any CRM), or a connected app. Field mapping is optional, so an empty mapping writes all enriched columns automatically.
  • New Integrations: connect apps like Google Sheets, HubSpot, and Salesforce on the Integrations page and write enriched rows to them from an Export step. Connections use OAuth with automatic token refresh, and Encrata never stores the third-party credentials. See the Workflow Integrations API.
  • New One-click Google Sheet creation from an Export step, so there is no spreadsheet ID to copy.
  • Changed Workflow secrets were removed in favor of Integrations. Webhook steps take the URL directly in their config.
Email Lookup is in public beta
Our full email suite is live over the API, AI agents, and bulk.
  • Beta Encrata is entering public beta with Email Lookup as the first generally available product. The full email suite is live: Email Validity, Email Identity, Check Breaches, and Password Breaches, each with single, agent (API-key), and bulk (up to 1M) access.
  • Docs The API Reference is now organized by lookup. Email Lookup is available today; Phone, IP, and Domain lookups roll out after beta.
  • Note Endpoints under a “Coming soon” badge are still documented for preview but are not yet part of the beta.
Smarter email validity
Every email now gets a clear status (valid, invalid, catch-all, or risky) with the reasons behind it.
  • New Email Validity now returns a full deliverability report instead of a single string. Every check resolves to one of four statuses valid, invalid, catch-all, or risky alongside metadata that explains it: reason, provider-calibrated confidence, a role flag, did_you_mean typo suggestions, domain_trust (an A-F grade from the SPF/DMARC/MTA-STS/TLS-RPT auth stack), person_signal (OSINT corroboration from HIBP, Gravatar, GitHub, GitLab and PGP keyservers), and raw smtp probe details.
  • New Catch-all disambiguation: a catch-all domain with a positive person signal is promoted to valid (reason=catchall_corroborated); a definitive SMTP verdict is never overridden.
  • Improved Explicit mail-route checks surface null_mx, no_dns, and no_mail_route reasons, and the SMTP probe now rotates source IPs, retries greylisting, and confirms catch-all with a double-random probe.
  • Improved The same structured result now powers the app endpoint and the agent endpoint (POST /api/agent/email-validity). validity is retained as a legacy mirror of status.
  • Dashboard Redesigned Email Validity page: an inline report with the verdict, provider, domain-trust grade, person footprint, and SMTP details, plus a redesigned bulk-upload flow.
Use-case map and AI advisor
Browse what Encrata can do, and let an assistant match it to your workflow.
  • New Use cases: a browsable commercial map of Encrata workflows (Sales, Marketing, Security, Fraud, E-commerce, Finance, Recruiting, AI, Data Ops and more), filterable by industry and function, each with a dedicated page covering what it means, when to use it, how Encrata powers it, and an example payload.
  • New Use-case advisor: an AI assistant on every use-case page that maps your product, team, risk workflow, data pipeline, or AI agent to the right Encrata lookups and a first workflow right in the browser.
  • Improved Marketing site polish: Across the home and use-case pages and a cleaner pure-white light theme.
Deeper IP intelligence
Passive DNS history, reputation over time, routing changes, TLS fingerprints, and C2 detection.
  • New Passive DNS history: IP lookups now return passive_dns - the domains that have resolved to an IP, with per-domain first_seen/last_seen, accumulated over time.
  • New Reputation over time: reputation_history returns a growing timeline of abuse score, malicious counts, and threat level on each lookup, plus an overall trend (improving/worsening/stable).
  • New Allocation & routing history: routing_history shows which ASNs have originated the IP over time, with origin_changes and a possible_hijack flag.
  • New TLS & certificate fingerprints: tls adds a live JARM hash, certificate SHA-256, subject/issuer/SANs, and self-signed / expired detection for pivoting to related infrastructure.
  • New C2 & honeypot detection: c2 flags known command-and-control / botnet controllers, and honeypot flags likely decoy systems.
  • New Named VPN/proxy provider: security.provider_name and security.provider_type identify the actual operator (e.g. NordVPN, Mullvad, Bright Data) instead of a generic flag.
  • Improved Open ports now include friendly services labels (port to service name, plus a banner).
Richer domain intelligence
Subdomain ownership eras, more email-auth records, and agent-readiness discovery.
  • New Subdomain ownership era: subdomain rows now include first_seen and an owner_era flag (current / previous) so Certificate Transparency entries that predate the current registration are surfaced as likely prior-owner assets.
  • New Extended email-auth posture: the email sheet now reports CAA, BIMI, and TLS-RPT records alongside SPF, DKIM, DMARC, and MTA-STS, with a finding raised when no CAA record is published.
  • New Agent-readiness discovery: passive .well-known probing now detects llms.txt, ai-plugin.json, A2A agent-card.json, and openapi.json, surfaced as machine-readable product/API surfaces.
  • Improved Technology attribution: domain-verification TXT records now resolve to the actual vendor (e.g. Postman, Google Search Console, Amazon SES, Stripe) instead of a generic label, and hostnames are normalized to plain values.
Domain recon and company data
Domain search now returns a recon report and the company behind the domain.
  • New Domain Intelligence: Domain search now returns an intel recon report - subdomain enumeration, live host probing, tech-stack and CDN detection, TLS details, and aggregate DNS. Powered by Encrata’s self-hosted, keyless recon engine.
  • New Company enrichment on domain search: A company object adds the organization behind the domain - industry, headquarters, social profiles, and registry data (LEI, company number, jurisdiction, officers).
  • Note Domain Intelligence runs in passive mode for API requests; no port scanning or intrusive probes are sent to the target.
Workflows and bulk operations
Build multi-step pipelines, run bulk lookups, and manage everything in one place.
  • New Workflows: Build automated multi-step OSINT pipelines with triggers, conditions, enrichment steps, delays, and webhook delivery.
  • New Workflow triggers: manual, webhook, schedule, and file_upload.
  • New Workflow step types: email_lookup, phone_lookup, domain_lookup, ip_lookup, condition, delay, webhook, transform.
  • New Workflow templates: Pre-built automations you can clone and customize.
  • New Workflow secrets: Encrypted key-value store for webhook step credentials.
  • New Workflow versioning: Immutable version history created on every update.
  • New Workflow audit log: Full trail of who created, updated, and ran each workflow.
  • New Public webhook ingest: Trigger workflows via a unique token URL without authentication.
  • New Bulk domain search: POST /api/bulk-domain-search up to 100 domains per request.
  • New Bulk IP search: POST /api/bulk-ip-search up to 100 IPs per request.
  • New Async bulk jobs: Upload CSV files for background processing (up to 10,000 rows) with progress tracking and download.
  • New AI chat: Conversational interface for lookups and workflow building.
  • New Settings integrated into app sidebar: All settings pages accessible from the main navigation without leaving the app.
  • Improved UI consistency: Standardized to 16px (text-base) across all sidebars, dropdowns, and menus.
  • Improved Removed breadcrumb clutter from settings pages.
Enriched views and social profiles
A visual view for every lookup, plus automatic social-profile detection.
  • New Enriched output mode: All sandbox lookups now support a visual “Enriched” view alongside raw JSON.
  • New Person enrichment: Additional intelligence sources integrated into email lookups.
Auto top-up and more data
Never run out of credits, with deeper domain results.
  • New Auto top-up: Automatically recharge credits when balance drops below your configured threshold.
  • New Domain lookup enhanced: DNS records, SSL certificates, host intelligence, and threat scoring now included.
CLI and developer docs
Run lookups from your terminal, with full docs and API-key auth.
  • New CLI: Look up emails, domains, phones, and more directly from your terminal.
  • New Developer docs: Errors, rate limits, pagination, credits, SDKs, and code examples.
  • New API key auth: All endpoints now use X-API-Key header (JWT removed). (Superseded: the API now authenticates with Authorization: Bearer - see authentication.)
  • New Careers page: Public job board with application support.
Multi-type contact lists
Reusable target lists for phones, domains, and IPs.
  • New Contact lists with types: Create reusable target lists scoped to a type (POST /api/lists with type field).
  • New GET /api/lists?type=X filter contact lists by type.
Webhooks
Real-time event callbacks for your workspace.
  • New Webhooks: Receive real-time HTTP callbacks when events occur in your workspace - lookup completions, API key changes, and credit alerts.
  • New Webhook management API: Full CRUD endpoints to create, list, update, delete, and test webhooks programmatically.
  • New Webhook delivery logs: Track every delivery attempt with status, response codes, and payload history.
  • New HMAC-SHA256 signature verification: Every webhook delivery is signed so you can verify authenticity.
  • New OTP verification for destructive actions: Delete account and leave workspace now require email OTP confirmation.
  • Improved Updated to Inter font across the entire UI for better readability.
  • Improved Lightened dialog backdrop overlay for less intrusive modals.
  • Fixed Dialog footer no longer shows a dark background strip.
Agent API and bulk streaming
A token-optimized endpoint for AI agents and streaming bulk lookups.
  • New Agent Lookup API: Token-optimized endpoint for AI agents with compact field keys and selective field retrieval.
  • New Bulk Lookup with SSE streaming: Look up up to 1,000 emails in a single request with real-time results.
  • New Breach detection: Lookups now return breach history - compromised services, exposed data types, and breach dates.
  • New Email validation: Every lookup includes deliverability status - valid, invalid, or disposable.
  • New Export to CSV & JSON: Download lookup results directly from the dashboard or via the API.
Dashboard, logs, and teams
Usage analytics, an activity feed, workspaces, and API key management.
  • New Dashboard & analytics: Lookup volume charts, validity breakdowns, and endpoint usage stats.
  • New Logs & activity feed: Detailed log of every API call, filterable by endpoint, validity, and date range.
  • New Team & workspace management: Invite members, manage roles, and collaborate in a shared workspace.
  • New API key management: Create, revoke, and manage multiple API keys with per-key usage tracking.
  • Improved Lookup response expanded to 30+ structured fields across identity, professional, education, and social categories.
Faster, more reliable lookups
Single email lookups are 40% faster with more consistent fields.
  • Improved Response time reduced by 40% for single email lookups.
  • Improved More consistent field formatting across all response objects.
  • Fixed Occasional timeout on lookups with uncommon email providers.
Encrata is live
The core Email Lookup API: pass any email, get structured intelligence about the person behind it.
  • Launch Encrata is live. Core Email Lookup API: pass any email, get structured intelligence about the person behind it.