Breach & Leak Data
Domain Lookup
Breach records that contain a domain
GET
/
api
/
domain
curl "https://www.osintcat.net/api/domain?query=example.com" \
-H "X-API-KEY: YOUR_API_KEY"
import requests
url = "https://www.osintcat.net/api/domain"
params = {"query": "example.com"}
headers = {"X-API-KEY": "YOUR_API_KEY"}
response = requests.get(url, params=params, headers=headers, timeout=60)
print(response.status_code, response.json())
const response = await fetch("https://www.osintcat.net/api/domain?query=example.com", {
headers: { "X-API-KEY": "YOUR_API_KEY" },
});
console.log(response.status, await response.json());
<?php
$curl = curl_init("https://www.osintcat.net/api/domain?query=example.com");
curl_setopt_array($curl, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ["X-API-KEY: YOUR_API_KEY"],
]);
$response = curl_exec($curl);
$status = curl_getinfo($curl, CURLINFO_RESPONSE_CODE);
curl_close($curl);
echo $status . " " . $response;
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, _ := http.NewRequest("GET", "https://www.osintcat.net/api/domain?query=example.com", nil)
req.Header.Set("X-API-KEY", "YOUR_API_KEY")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(resp.StatusCode, string(body))
}
[
{
"email": "jane@example.com",
"password": "hunter2",
"breach": "Example 2021"
}
]
Returns breach records whose e-mail addresses or URLs belong to a domain.
See Errors for the responses every endpoint can return.
Parameters
string
required
The domain, e.g.
example.com.Headers
string
required
Your API key.
Usage
Counts as one lookup against your plan’s daily allowance (Max: unlimited). When the allowance is used up, requests are refused with429 LIMIT_REACHED until it resets at 00:00 UTC.
Example request
curl "https://www.osintcat.net/api/domain?query=example.com" \
-H "X-API-KEY: YOUR_API_KEY"
import requests
url = "https://www.osintcat.net/api/domain"
params = {"query": "example.com"}
headers = {"X-API-KEY": "YOUR_API_KEY"}
response = requests.get(url, params=params, headers=headers, timeout=60)
print(response.status_code, response.json())
const response = await fetch("https://www.osintcat.net/api/domain?query=example.com", {
headers: { "X-API-KEY": "YOUR_API_KEY" },
});
console.log(response.status, await response.json());
<?php
$curl = curl_init("https://www.osintcat.net/api/domain?query=example.com");
curl_setopt_array($curl, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ["X-API-KEY: YOUR_API_KEY"],
]);
$response = curl_exec($curl);
$status = curl_getinfo($curl, CURLINFO_RESPONSE_CODE);
curl_close($curl);
echo $status . " " . $response;
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, _ := http.NewRequest("GET", "https://www.osintcat.net/api/domain?query=example.com", nil)
req.Header.Set("X-API-KEY", "YOUR_API_KEY")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(resp.StatusCode, string(body))
}
SDK example
The same request with the official SDKs. Each one reads your key fromOSINTCAT_API_KEY.
import { OsintCatClient } from "osintcat";
const client = new OsintCatClient(); // reads OSINTCAT_API_KEY
const result = await client.breach.domain({
query: "example.com"
});
console.log(result);
from osintcat import OsintCat
client = OsintCat() # reads OSINTCAT_API_KEY
result = client.breach.domain(
query="example.com",
)
print(result)
package main
import (
"context"
"fmt"
osintcat "github.com/OsintCatHQ/osintcat-go"
osintcatclient "github.com/OsintCatHQ/osintcat-go/client"
)
func main() {
client := osintcatclient.NewClient() // reads OSINTCAT_API_KEY
request := &osintcat.DomainBreachRequest{
Query: "example.com",
}
result, err := client.Breach.Domain(context.Background(), request)
if err != nil {
panic(err)
}
fmt.Printf("%+v\n", result)
}
<?php
require __DIR__ . '/vendor/autoload.php';
use OsintCat\OsintCatClient;
use OsintCat\Breach\Requests\DomainBreachRequest;
$client = new OsintCatClient(); // reads OSINTCAT_API_KEY
$result = $client->breach->domain(
new DomainBreachRequest([
'query' => 'example.com',
]),
);
echo json_encode($result, JSON_PRETTY_PRINT), PHP_EOL;
Response
An array of breach records. The fields of a record depend on the breach it comes from.[
{
"email": "jane@example.com",
"password": "hunter2",
"breach": "Example 2021"
}
]
Errors
| Status | Error | When |
|---|---|---|
| 404 | No results found | Nothing was found for the domain. |
| 424 | Upstream error | The search could not be completed; the response carries an error_id. |
Was this page helpful?
⌘I
curl "https://www.osintcat.net/api/domain?query=example.com" \
-H "X-API-KEY: YOUR_API_KEY"
import requests
url = "https://www.osintcat.net/api/domain"
params = {"query": "example.com"}
headers = {"X-API-KEY": "YOUR_API_KEY"}
response = requests.get(url, params=params, headers=headers, timeout=60)
print(response.status_code, response.json())
const response = await fetch("https://www.osintcat.net/api/domain?query=example.com", {
headers: { "X-API-KEY": "YOUR_API_KEY" },
});
console.log(response.status, await response.json());
<?php
$curl = curl_init("https://www.osintcat.net/api/domain?query=example.com");
curl_setopt_array($curl, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ["X-API-KEY: YOUR_API_KEY"],
]);
$response = curl_exec($curl);
$status = curl_getinfo($curl, CURLINFO_RESPONSE_CODE);
curl_close($curl);
echo $status . " " . $response;
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, _ := http.NewRequest("GET", "https://www.osintcat.net/api/domain?query=example.com", nil)
req.Header.Set("X-API-KEY", "YOUR_API_KEY")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(resp.StatusCode, string(body))
}
[
{
"email": "jane@example.com",
"password": "hunter2",
"breach": "Example 2021"
}
]
