Skip to main content
The DarknetSearch API puts our dark-web and breach intelligence in your own tools: search leaked credentials, sweep dark-web and paste sources, monitor your assets, and pull an organization’s risk and exposure — all over a straightforward REST API. These guides are organized by goal, in six sections. Each section opens with an overview that points you to the right guide; each guide explains what to call and why, then links into the API reference, where you can see every parameter and run it live. New here? Start with Get started, then jump to the job you came to do.

Start here

Get started

Wire the API into your stack: get a bearer token, read your organization, and set up where results are delivered — email and webhooks. Do these once; everything else assumes them.

Then, by goal

Search

Find what’s out there. Search broad across every source, deep into one of 14 indexed sources, or live against the open and dark web.

Leaked credentials

The number-one job: find your organization’s exposed passwords. Four approaches — Raw Data, the ULP feed, Filtered credentials, and Stealer logs — shaped for different jobs.

Assess & report

Turn findings into a picture: a scored risk profile, leak statistics and trends, peer benchmarks, and shareable PDF reports.

Monitor

Stay ahead of new exposure. Hand an asset to a data source and let it run — new matches recorded and delivered to email or a webhook as they appear.

Downloads & exports

Move results into files. Use the export service for result sets, and reserve original leak-file downloads for small source files.

The endpoint reference

Every guide links into the API reference — the complete, try-it-live catalog of endpoints, parameters, and response shapes. Use the guides to learn a workflow; use the reference to look up the exact call.