Skip to main content
GET
Checks which websites and services an e-mail address is registered with and in which breaches it appears. Every request must state its purpose.
A request without a purpose (parameter purpose, header X-Purpose, or Purpose: ... at the end of your User-Agent) is refused with 400 USER_AGENT_IDENTITY_REQUIRED.

Parameters

string
required
The e-mail address (email is accepted as well).
string
Why you run the lookup, e.g. fraud prevention. Required unless sent as a header (below).

Headers

string
required
Your API key.
string
The purpose, instead of the purpose parameter.

Usage

Counts as one lookup against your plan’s daily allowance (Max: unlimited). When the allowance is used up, the lookup can continue at a per-lookup price charged to your balance (the module’s page in the dashboard shows the price); a lookup that finds nothing is not charged.

Example request

SDK example

The same request with the official SDKs. Each one reads your key from OSINTCAT_API_KEY.

Response

Results for the same address may come from a cache for up to 15 minutes.
object
What was found.
object
Your usage after this request.

Errors

See Errors for the responses every endpoint can return.