A search costs 1 credit, however many sources it queries. Searching an email asks several sources at once (up to 55 for the widest kind of value, see the guide below) and it is still one credit. Calling a single source directly, from the API or the API Explorer, is 1 credit per call.
Every account has one balance of credits, topped back up to the daily allowance of its plan every 24 hours. The free plan gives 5 credits a day. A search that no source could answer is refunded.
When you need more each day, take a monthly plan: it raises the daily allowance and is billed every month (see the plans). Credits above the allowance (a promo code, a referral) are never taken away by the refill, and you can cancel a plan whenever you like from your account.
The same balance pays for searches on this site and for calls made with your API key (curl, a script, the API Explorer).
Only if none of the sources could answer. A search is charged 1 credit when it starts; if every source it asked failed on its side (timeout, server error, retired endpoint...), the credit is refunded automatically and the status line says so. As soon as one source answered, even to say it has nothing, the search did its job and stays charged.
The classic /api/<source> endpoints refund their single credit when their source fails and add an
X-Credit-Refunded: 1 header to the response.
A search needs 1 credit to start. Without one it is refused before any source is queried, so nothing is charged and nothing is half-done: a search that started always finishes.
Yes. Under Account → Low-credit alert you choose the balance that triggers a notice (a fifth of your daily allowance by default, 0 turns it off). You then get a banner in the dashboard and, if your email is verified, one email — and one more if you reach zero. The next daily top-up arms it again. If you run a Personnal Searcher page, its visitors are served from the same balance, so this alert matters there too.
An identical search repeated within 120 seconds replays the stored answer for free — but only if every source answered the first time. If some failed, the search runs again so those sources get another chance.
Emails, usernames, IP addresses, phone numbers, domains, hashes, Discord IDs, URLs, UUIDs and names. The guide lists what each one gets you and which sources answer.
Leave Type on Auto-detect and just paste the value: it looks at the shape (an @ and a
domain is an email, four dotted numbers an IP, 17–20 digits a Discord ID, a 32/40/64-character hex string a
hash, and so on) and shows what it picked. Pick a type by hand whenever the guess is wrong — a bare
john.doe looks like a domain, for instance.
The same rule is available to the API: omit type or send type=auto on
/api/search, or ask /api/detect-type?value=… (free, no key needed).
The value is checked against the format of the chosen type before anything is queried: an email needs an @ and a
domain, an IP must be a real IPv4/IPv6 address, a Discord ID is 17–20 digits, a domain has no
http:// or path, and so on. A refused search costs nothing, and the message says what
was expected.
Through the API, yes: /api/search accepts sources=Snusbase,LeakCheck (source names, as
listed by /api/sources) and max_sources=5 to cap the number queried. Only the sources
actually queried are charged.
Each source that found something gets its own section, with its name, how many records it holds and the records themselves as a table (the first ten, then Show more records). A source that has nothing on your value, or that failed, is not shown: the note under the results says how many were left out. A section marked Duplicate holds the same data as a source that already answered, so you can ignore it. The { } button of a section shows the raw response.
The strip at the top sums the search up: how many sources answered, how many records, how many identifiers were found, and how many sources hold a password. The rail on the left lists the sources (click one to see only that source) and, on its other tab, the emails, usernames, IP addresses, phones and Discord IDs found inside the results: click one to keep only the records that contain it; the magnifier searches it.
Once results arrive, a toolbar appears above them. Type a word to keep only the records that contain it (a word that names a source keeps all of that source’s records), or keep only the records that hold a password. Sort the sources by arrival, by most records, by newest leak date (when the source provides one) or by name. Inside a table, click a column title to sort its records, and click a record to open all its fields. Hover a value to copy it, or to search it when it is an email, an IP address, a phone number or a username. Filtering only shows or hides what you already have — it never runs a search or spends a credit.
It pulls the identifiers out of the results — emails, public IP addresses, usernames, phone numbers and Discord IDs — and shows them two ways, switched with the Graph and List buttons.
The graph draws each identifier as a dot and joins two dots when they appear in the same record of a result (the same leaked account, the same profile), so a cluster of linked dots is likely one person. The value you searched sits in the centre, in white. A number on a dot is how many sources reported it. A dashed line only means “found by the same search”: no single record holds both. Scroll to zoom, drag the background to pan, drag a dot to move it, and use the expand button to give the graph the whole window. The list groups the same identifiers by kind, with the same source count.
Click a dot (or an identifier in the list) to show only the results that contain it. Search ↗ runs a new search on it (it asks first, because it costs credits) and Add to a case copies the graph, or one dot and what shares a record with it, into one of your cases. Extraction is automatic, so treat what you see as leads to verify, not proof.
A case is a private workspace for one investigation, in the Cases tab of the dashboard. It is a graph you draw yourself: add items (people, emails, usernames, phones, IP addresses, Discord IDs, domains, addresses, companies, accounts or plain notes), link them and say how they are related, write notes on each one and mark the key ones. Cases cost no credit, you can keep up to 50, and every change is saved as you make it.
The quickest way to add something is the bar above the graph: paste an email, an IP, a phone number, a
@username, a domain or a name and press Enter. It works out what it is, and if an item is selected the new one
is linked to it (separate several values with ;). Drag the round + handle of a
selected item onto another one to link them, or let go on empty space to create a new linked item. Double-click
the background to add an item there. You can export a case as an image or as a JSON file.
Work on many items at once: draw a loop around them with the lasso (M), or hold Shift and click or drag. A selection can be moved, deleted, copied and pasted (also into another case), duplicated with Ctrl+D, or grouped into a cluster that folds into one dot. Ctrl+Z and Ctrl+Y undo and redo every step. Right-click an item for its menu, and press ? in a case for every shortcut.
Say how far you trust something: every item and every link has a reliability (unrated, unverified, probable or confirmed) shown as three arcs under an item and as the thickness of a link. What a search adds to a case is rated from how many sources agreed.
Search from an item. Right-click an email, username, phone, IP address, domain, Discord ID or a person and choose Search this…. It asks you first (it costs the same credits as a normal search of that kind), then adds what it finds around the item and links it to it, without duplicating anything already in the case.
Sharing. Open Share in a case. You can invite other Seeleaks accounts by email or username as viewers or editors (editors change everything except who has access; only you can delete the case; a collaborator can leave at any time), and you can create a read-only link that opens the case without an account. A link expires after the time you choose, can be revoked at any moment, follows your edits, and leaves out your notes and description unless you tick the box. Open it yourself while logged out to see exactly what people get.
Nobody else can open a case you did not share. Cases are stored on our servers next to your account, and are deleted with the account's key. You can also send a Correlation or Multi-criteria graph into a case with Add to a case.
Export to JSON, CSV, TXT or PDF from the bar above the results. Share link creates a page anyone can open without an account or credits; it expires after 24 hours, 3 days or 7 days, your choice. Exports always contain every result, whatever filter is active.
Send your key in the X-API-Key header. Every endpoint, with ready-to-paste code, is on the
documentation page.
Regenerate it from Account → Regenerate my API key. The old key stops working immediately, and your dashboard session stays signed in.
A white-label public search page (/p/your-name) that we set up for a client. The client brands it,
picks which fields and sources visitors can use within the grants we gave them, and pays for the searches from
their own credits.
The search history we keep for statistics records the kind of search, how many sources were queried and each source's outcome — not the value you typed. What you choose to keep, like Favorites or a share link, is stored until you delete it or the link expires. Usage logs are purged automatically after a set time. The Privacy Policy has the full detail.
Use the data removal form. See also the Terms of Use and Global Compliance pages.
No question matches that filter.
Pick what you have in hand. This list is generated from the sources a search really queries: a search asks all the sources below at once, for a single credit.
Breaches, stealer logs, the services an address is registered on and the identities tied to it.
Breach records, social-network profiles, gaming accounts and username history.
Carrier and line intelligence, messaging-app lookups and breach records.
People-search and breach records matching a first and last name.
Address validation and geocoding, and US property and owner records.
Geolocation, ISP and organisation, exposed services, and breach or stealer records tied to the address.
WHOIS and DNS data, and stealer-log exposure of a company's users and employees.
Breach and stealer records that reference a URL, and profile links.
Which leaked accounts and stealer logs use this exact password.
Hash lookups against breach databases, to recover the plaintext where one is known.
Discord profile data, username history, risk score and links to other platforms.
Steam profile, aliases and linked accounts.
Xbox profile and activity.
Telegram user, channel or group behind a numeric ID.
Minecraft-style profile lookups by UUID, and breach records.
Wallet activity and the leaks that mention it.
Wallet activity and the leaks that mention it.
Public Snapchat profile, story snaps and analytics behind a username.
Public Instagram profile, followers and linked details for a username.
TikTok profile, counters and activity for a username.
X (Twitter) profile data and history for a username.
Telegram user, channel or group behind a public username.
Reddit account activity, communities and writing profile for a username.
GitHub profile, repositories and the emails seen in its commits.
Roblox profile, history and linked accounts for a username.
Minecraft profile and username history for a player name.
The Discord server behind an invite code: its name, size and the person who made the invite.
A Discord server's public widget: its name, channels and online members.
Internet-facing devices and services matching a search (product, port, country, organisation).
The communities a subreddit is linked to.
Reddit posts and comments that contain a word, an email, a username or a phrase.
People and records tied to a bank account number.
The person and vehicle registered under a French licence plate.
People and records tied to a French company number (SIRET of 14 digits, or SIREN of 9).
Issuing bank, country, card brand and type behind the first digits of a card.
Manufacturer, model, engine and specifications decoded from a VIN.
Company name, status, address and registration data.
Company name, status, address and registration data.