Paginated, count-sorted distinct-value breakdown for the keyword insight KPI tiles
Drill into a keyword-insight KPI tile (Total Users / Total Domains) with a
server-paginated, count-sorted list of distinct values, computed from the
organization's active keywords over leaks_history (same dedup-by-hash rows
as GET /leaks/keyword/search).
field=source is rejected (returns an empty page): keyword leaks have no
reliable per-credential source attribution (see the keyword teaser-tier
rule) -- classic leaks use GET /leaks/breakdown?field=source instead.
Parameters:
| Parameter | Default | Description |
|---|---|---|
field | required | username, domain, or source (rejected, empty page) |
page | 1 | Page number |
page_size | 50 | Items per page (max 200) |
search | - | Substring filter on the returned value |
Plus all standard DynamicFilters, exactly like GET /leaks/keyword/search.
Response:
{
"data": [{"value": "acme-corp-recrute.talent-soft.com", "count": 12}],
"total": 34,
"page": 1,
"page_size": 50,
"total_pages": 1
}total is the number of distinct field values matching the filters --
the same figure as unique_usernames / unique_domains from
GET /leaks/keyword/stats.
Example:
GET /leaks/keyword/breakdown?field=domain&page=1&page_size=50Authorization
ApiKeyAuth API key for authentication
In: header
Query Parameters
KPI dimension to break down
"username" | "domain" | "source"Page number
11 <= valueItems per page (max 200)
501 <= value <= 200Substring filter on the returned value
length <= 200Username of the leaked user (can be phone, email, ID, ...)
Type of leak (combo, stealer)
Uniq identifier for the concatenation of : username, password and domain
Upload date on stealed, ISO 8601, pattern YYYY-MM-DD
Upload date on the plateform the credential was found, ISO 8601, pattern YYYY-mm-dd
Log date of the device at compromized moment (if applicable, stealer only)
Start date to search from leaks, format: YYYY-mm-dd (default: today - 14days at 0:00am)
End date to search leaks from, format YYYY-mm-dd (default: today)
URL of the leaked data
FQDN of the leaked data
Local part of the username section (if applicable, email only)
Protocol identified (if applicable)
Email domain to filter on (if multiple email domains declared)
Root domain to filter on (if multiple root domains declared)
Machine ID (if applicable, stealer only)
Computer name (if applicable, stealer only)
Hardware ID (if applicable, stealer only)
Machine user (if applicable, stealer only)
IP address (if applicable, stealer only)
Country (if applicable, stealer only)
Software (if applicable, stealer only)
Stealer name (if applicable)
Opaque source label(s) to filter on, of the form Source-<6 hex> (as returned by the sources breakdown). The raw telegram_channel is never exposed: the label is matched back against the same MD5-prefix expression server-side.
Keyword to filter on (only active keywords for tenant)
Match type for leaks_matched table (root_domain or email_domain)
Root domains to exclude (NOT IN filter)
Email domains to exclude (NOT IN filter)
Domains to exclude (NOT IN filter)
Types to exclude
Software to exclude
Stealer names to exclude
Protocols to exclude
Countries to exclude
Show only hashes whose first appearance (min upload_stealed) falls on this exact date. Format: YYYY-MM-DD.
Show only hashes whose first appearance (min upload_stealed) is on or after this date. Format: YYYY-MM-DD.
Limit result length
Minimum number of sources (source_count >= N)
Response Body
application/json
application/json
curl -X GET "https://api.stealed.io/leaks/keyword/breakdown?field=domain"{
"data": [
{
"count": 42,
"value": "[email protected]"
},
{
"count": 17,
"value": "[email protected]"
}
],
"page": 1,
"page_size": 50,
"total": 118,
"total_pages": 3
}{
"detail": [
{
"loc": [
"string"
],
"msg": "string",
"type": "string"
}
]
}Paginated keyword search results GET
Retrieve paginated leak details matching the organization's active keywords. Returns the same paginated envelope as `/leaks/details`. The row shape differs slightly: keyword rows come from the occurrence grain, so they carry `local_part` and no per-credential value sets (`softwares`, `ip_addresses`, ...). This endpoint has an additional `matched_keyword` field indicating which keyword matched each row. Searches `leaks_history` for rows where `hasToken(host, keyword)` is true for any active keyword, excluding the org's own monitored root domains. If the organization has no active keywords, returns an empty paginated response. **Parameters:** | Parameter | Default | Description | |-----------|---------|-------------| | `page` | 1 | Page number | | `page_size` | 50 | Items per page (max 200) | | `search` | - | Full-text search across username, host, domain, root_domain | | `sort_by` | `last_seen` | Sort order: `last_seen` (most recent first) | | `start_date` / `end_date` | last 14 days | Date range filter | Plus all standard DynamicFilters. **Response Format:** ```json { "data": [ { "username": "[email protected]", "password": "p****d", "type": "Stealer", "last_seen": "2026-03-15T10:30:00", "host": "acme-corp-recrute.talent-soft.com", "domain": "acme-corp-recrute.talent-soft.com", "local_part": "user", "protocol": "https", "email_domain": "example.com", "root_domain": "talent-soft.com", "log_date": "2026-03-10T08:00:00", "country": "FR", "software": "chrome, profile: 0", "stealer_name": "RedLine", "hash": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4", "machine_id": "DESKTOP-ABC1234", "computer_name": "LAPTOP-XYZ", "hardware_id": "hwid-1234-5678", "machine_user": "john.doe", "ip_address": "192.168.1.10", "upload_date": "2026-03-14T12:00:00", "source_count": 1, "matched_keyword": "acme-corp" } ], "total": 12345, "page": 1, "page_size": 50, "total_pages": 247 } ``` **Examples:** ```bash # Basic paginated request GET /leaks/keyword/search?page=1&page_size=50 # With search filter GET /leaks/keyword/search?search=admin&page=1&page_size=50 # With date range GET /leaks/keyword/search?start_date=2026-03-01&end_date=2026-03-28 ```
Retrieve sources for a keyword leak by hash GET
Get all occurrences of a keyword leak from leaks_history by hash. Scoped to the tenant's active keywords for security.