1. Partner API v2
  2. Resources
  3. Dark Web

Dark Web

Dark Web Monitoring exposure data. Requires the feature to be enabled for the client.
4 endpointsScope readExposureDarkWebSummaryUserExposureSummaryBreach
GET/v2/users/{user_id}/exposures
RequiresreadscopeCursor-paginatedReturns Page of Exposure

Each breach the user's email appears in, with the data classes exposed and whether it has been resolved.

Path parameters

user_idstringRequired

User id (the user's INFIMA id).

Query parametersall optional unless marked

resolvedboolean

Filter to resolved or unresolved exposures. Omit for both.

limitinteger

Default 100min 1 · max 500

cursorstring

Opaque cursor from the previous page's page.next_cursor.

curl "https://app.infimasecapis.com/v2/users/b7e1c0d2-44aa-5f9e-8c33-1a2b3c4d5e6f/exposures" \
  -H "X-API-Key: $INFIMA_API_KEY"
Response objectPage of Exposure
dataarray of Exposure
Show item properties(10)
user_idstring
breach_namestring
titlestring
domainstringNullable
breach_onstring (date)Nullable
severitystring

critical = passwords exposed; high = sensitive personal data; medium = basic account data; low = spam lists.

One ofcriticalhighmediumlow
data_classesarray of string
first_seen_atstring (date-time)
notified_atstring (date-time)Nullable
resolved_atstring (date-time)Nullable
pageobject
Show properties(2)
next_cursorstringNullable

Pass as cursor to fetch the next page. Null on the last page.

has_moreboolean
Errors403The feature is not enabled for this clientError envelope →
GET/v2/clients/{client_id}/dark-web
RequiresreadscopeReturns DarkWebSummary

When the last scan ran and the client's exposure counts. Returns 403 FEATURE_DISABLED when Dark Web Monitoring is not enabled for the client.

Path parameters

client_idstringRequired

Client id (the client's INFIMA id).

curl "https://app.infimasecapis.com/v2/clients/3f2a9c1e-7b44-5d2e-9a1f-0c6d8e4b2a10/dark-web" \
  -H "X-API-Key: $INFIMA_API_KEY"
Response objectDarkWebSummary
client_idstring
enabledboolean
last_scan_atstring (date-time)Nullable
users_monitoredinteger
users_exposedinteger
unresolvedobject
Show properties(4)
criticalinteger
highinteger
mediuminteger
lowinteger
resolved_totalinteger
new_since_30dinteger
Errors403The feature is not enabled for this clientError envelope →
GET/v2/clients/{client_id}/dark-web/exposures
RequiresreadscopeCursor-paginatedReturns Page of UserExposureSummary

One row per exposed user with counts. since / until filter on when the exposure was first seen, which is how you pull "new since last month". Use GET /users/{user_id}/exposures for the breach-level detail.

Path parameters

client_idstringRequired

Client id (the client's INFIMA id).

Query parametersall optional unless marked

sincestring (date-time)

Only records at or after this time (RFC 3339).

untilstring (date-time)

Only records before this time (RFC 3339).

severitystring

critical = passwords exposed; high = sensitive personal data; medium = basic account data; low = spam lists.

One ofcriticalhighmediumlow
unresolved_onlyboolean

Default false

limitinteger

Default 100min 1 · max 500

cursorstring

Opaque cursor from the previous page's page.next_cursor.

curl "https://app.infimasecapis.com/v2/clients/3f2a9c1e-7b44-5d2e-9a1f-0c6d8e4b2a10/dark-web/exposures" \
  -H "X-API-Key: $INFIMA_API_KEY"
Response objectPage of UserExposureSummary
dataarray of UserExposureSummary
Show item properties(8)
user_idstring
emailstring
first_namestring
last_namestring
unresolved_exposuresinteger
resolved_exposuresinteger
highest_severitystring

critical = passwords exposed; high = sensitive personal data; medium = basic account data; low = spam lists.

One ofcriticalhighmediumlow
latest_first_seen_atstring (date-time)
pageobject
Show properties(2)
next_cursorstringNullable

Pass as cursor to fetch the next page. Null on the last page.

has_moreboolean
Errors403The feature is not enabled for this clientError envelope →
GET/v2/clients/{client_id}/dark-web/breaches
RequiresreadscopeCursor-paginatedReturns Page of Breach

The breach catalog entries that include at least one of the client's users, with affected counts.

Path parameters

client_idstringRequired

Client id (the client's INFIMA id).

Query parametersall optional unless marked

sincestring (date-time)

Only records at or after this time (RFC 3339).

limitinteger

Default 100min 1 · max 500

cursorstring

Opaque cursor from the previous page's page.next_cursor.

curl "https://app.infimasecapis.com/v2/clients/3f2a9c1e-7b44-5d2e-9a1f-0c6d8e4b2a10/dark-web/breaches" \
  -H "X-API-Key: $INFIMA_API_KEY"
Response objectPage of Breach
dataarray of Breach
Show item properties(9)
namestring
titlestring
domainstringNullable
breach_onstring (date)Nullable
added_onstring (date)
severitystring

critical = passwords exposed; high = sensitive personal data; medium = basic account data; low = spam lists.

One ofcriticalhighmediumlow
data_classesarray of string
affected_usersinteger
unresolved_usersinteger
pageobject
Show properties(2)
next_cursorstringNullable

Pass as cursor to fetch the next page. Null on the last page.

has_moreboolean
Errors403The feature is not enabled for this clientError envelope →
Coming in 2.x1 more Dark Web operation is specified for a later 2.x release.See the roadmap