openapi: 3.2.0 info: title: NordStellar Enterprise Data Password Intelligence API description: '## Overview The NordStellar Enterprise Data API provides comprehensive access to our data breach intelligence platform, enabling organizations to integrate real-time security monitoring and alerting capabilities directly into their existing infrastructure. This API allows you to proactively protect your users by detecting when their sensitive information has been compromised in data breaches across the internet. **Key Features**: - **Real-time Breach Monitoring**: Receive immediate notifications when user data appears in newly discovered data breaches. - **Zero-Knowledge Architecture**: Search for compromised sensitive data (credit cards, national identification numbers) using secure hash-based methods that never transmit the actual sensitive information. - **Comprehensive Data Sources**: Access intelligence from multiple sources including corporate data breaches, malware infection logs, and stolen credential lists. - **Flexible Integration Options**: Support for webhook notifications, bulk operations, and subscription management to fit your organization''s unique requirements. - **Enterprise-Grade Security**: Secure authentication methods, rate limiting, and quota management to ensure responsible and controlled API usage.' version: '3.1' servers: - url: /api/v3/data security: - ApiKeyAuth: [] - BasicAuth: [] tags: - name: Password Intelligence description: 'Endpoints for comprehensive password data monitoring in data breaches, including zero-knowledge search capabilities. These operations enable robust password security protection and exposure assessment.' paths: /email/{email-sha256}/password: get: tags: - Password Intelligence summary: Single email ATO prevention description: 'Used for looking up an email address and its fuzzed passwords. Fuzzed passwords are passwords transformed according to pre-defined rules. The rule set, and thus the number of fuzzed passwords returned depends on the fuzzing_intensity parameter, which ranges from **0** to **10**, **0** being no fuzzing, only original password returned, and **10** being the biggest rule set that returns over 50,000 fuzzed passwords per original password. **Rate limit: 10 per second.**' operationId: singleEmailPassword parameters: - $ref: '#/components/parameters/Email' - $ref: '#/components/parameters/FuzzingIntensity' responses: '200': description: Returns found data headers: X-RateLimit-Limit: $ref: '#/components/headers/X-RateLimit-Limit' X-RateLimit-Remaining: $ref: '#/components/headers/X-RateLimit-Remaining' X-RateLimit-Reset: $ref: '#/components/headers/X-RateLimit-Reset' X-Quota-Limit: $ref: '#/components/headers/X-Quota-Limit' X-Quota-Remaining: $ref: '#/components/headers/X-Quota-Remaining' X-Quota-Reset: $ref: '#/paths/~1email/post/responses/200/headers/X-Quota-Reset' content: application/json: schema: $ref: '#/components/schemas/EmailAtoPreventionSample' '400': description: Bad request content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' '401': description: Unauthorized content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' '404': description: No data found content: {} security: - ApiKeyAuth: [] /email/password: post: tags: - Password Intelligence summary: Bulk email ATO prevention description: 'Used for looking up email addresses and their fuzzed passwords in bulk. Fuzzed passwords are passwords transformed according to pre-defined rules. The rule set, and thus the number of fuzzed passwords returned depends on the **fuzzing_intensity** parameter, which ranges from **0** to **10**, **0** being no fuzzing, only original password returned, and **10** being the biggest rule set that returns over 50,000 fuzzed passwords per original password. The data is returned using pagination by default, pagination behaviour can be modified using **limit** and **offset** parameters. **Rate limit: 100 per second.**' operationId: emailAtoPrevention requestBody: content: application/json: schema: $ref: '#/components/schemas/EmailsAto' required: true responses: '200': description: Returns found data headers: X-RateLimit-Limit: $ref: '#/components/headers/X-RateLimit-Limit' X-RateLimit-Remaining: $ref: '#/components/headers/X-RateLimit-Remaining' X-RateLimit-Reset: $ref: '#/components/headers/X-RateLimit-Reset' X-Quota-Limit: $ref: '#/components/headers/X-Quota-Limit' X-Quota-Remaining: $ref: '#/components/headers/X-Quota-Remaining' X-Quota-Reset: $ref: '#/paths/~1email/post/responses/200/headers/X-Quota-Reset' content: application/json: schema: $ref: '#/components/schemas/EmailsAtoPreventionSample' '400': description: Bad request content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' '401': description: Unauthorized content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' security: - ApiKeyAuth: [] x-codegen-request-body-name: payload /email/password/filtered: post: tags: - Password Intelligence summary: Single email ATO prevention with filtering description: 'Used for looking up an email address and its fuzzed passwords. Fuzzed passwords are passwords transformed according to pre-defined rules. The rule set, and thus the number of fuzzed passwords returned depends on the fuzzing_intensity parameter, which ranges from **0** to **10**, **0** being no fuzzing, only original password returned, and **10** being the biggest rule set that returns over 50,000 fuzzed passwords per original password. This endpoint provides the ability to only return fuzzed passwords from specific sources from IDs provided in the body. **Rate limit: 50 per second.**' operationId: singleEmailFilteredAtoPrevention requestBody: content: application/json: schema: $ref: '#/components/schemas/EmailAtoFiltered' required: true responses: '200': description: Returns found data headers: X-RateLimit-Limit: $ref: '#/components/headers/X-RateLimit-Limit' X-RateLimit-Remaining: $ref: '#/components/headers/X-RateLimit-Remaining' X-RateLimit-Reset: $ref: '#/components/headers/X-RateLimit-Reset' X-Quota-Limit: $ref: '#/components/headers/X-Quota-Limit' X-Quota-Remaining: $ref: '#/components/headers/X-Quota-Remaining' X-Quota-Reset: $ref: '#/paths/~1email/post/responses/200/headers/X-Quota-Reset' content: application/json: schema: $ref: '#/components/schemas/EmailAtoPreventionSample' '400': description: Bad request content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' '401': description: Unauthorized content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' security: - ApiKeyAuth: [] x-codegen-request-body-name: payload /email/password/filtered/bulk: post: tags: - Password Intelligence summary: Bulk email ATO prevention description: 'Used for looking up email addresses and their fuzzed passwords in bulk. Fuzzed passwords are passwords transformed according to pre-defined rules. The rule set, and thus the number of fuzzed passwords returned depends on the **fuzzing_intensity** parameter, which ranges from **0** to **10**, **0** being no fuzzing, only original password returned, and **10** being the biggest rule set that returns over 50,000 fuzzed passwords per original password. This endpoint provides the ability to only return fuzzed passwords from specific sources from IDs provided in the body. The data is returned using pagination by default, pagination behaviour can be modified using **limit** and **offset** parameters. **Rate limit: 10 per second.**' operationId: emailFilteredAtoPrevention requestBody: content: application/json: schema: $ref: '#/components/schemas/EmailsAtoFiltered' required: true responses: '200': description: Returns found data headers: X-RateLimit-Limit: $ref: '#/components/headers/X-RateLimit-Limit' X-RateLimit-Remaining: $ref: '#/components/headers/X-RateLimit-Remaining' X-RateLimit-Reset: $ref: '#/components/headers/X-RateLimit-Reset' X-Quota-Limit: $ref: '#/components/headers/X-Quota-Limit' X-Quota-Remaining: $ref: '#/components/headers/X-Quota-Remaining' X-Quota-Reset: $ref: '#/paths/~1email/post/responses/200/headers/X-Quota-Reset' content: application/json: schema: $ref: '#/components/schemas/EmailsAtoPreventionSample' '400': description: Bad request content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' '401': description: Unauthorized content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' security: - ApiKeyAuth: [] x-codegen-request-body-name: payload /zero-knowledge/password/{hash-type}/{hash-range}: get: tags: - Password Intelligence summary: Passwords search description: 'Zero knowledge endpoints are endpoints for sensitive data specifically designed to avoid the transfer of such data. Used for checking if the password has been compromised previously. The request must include first 6 characters of the password, hashed using **SHA-256** algorithm. Hashed passwords are returned in a response that start with the filter characters provided in the request. **Rate limit: 200 per second.**' operationId: passwordsSearch parameters: - name: hash-type in: path required: true description: Currently only **sha256** schema: type: string - $ref: '#/components/parameters/HashRange' responses: '200': description: Returns found data headers: X-RateLimit-Limit: schema: type: integer description: Request limit per second. Defaults 200 per second X-RateLimit-Remaining: schema: type: integer description: The number of requests left for the time window. X-RateLimit-Reset: schema: type: string format: date-time X-Quota-Limit: $ref: '#/components/headers/X-Quota-Limit' X-Quota-Remaining: $ref: '#/components/headers/X-Quota-Remaining' X-Quota-Reset: $ref: '#/paths/~1email/post/responses/200/headers/X-Quota-Reset' content: application/json: schema: $ref: '#/components/schemas/ZeroKnowledgePasswordSample' '400': description: Bad request content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' '401': description: Unauthorized content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' security: - ApiKeyAuth: [] /zero-knowledge/password: post: tags: - Password Intelligence summary: Bulk passwords search description: 'Zero knowledge endpoints are endpoints for sensitive data specifically designed to avoid the transfer of such data. Used for checking if the password has been compromised previously. The request must include first 6 characters of the password, hashed using **SHA-256** algorithm. Hashed passwords are returned in a response that start with the filter characters provided in the request. **Rate limit: 200 per second.**' operationId: passwordsBulkSearch requestBody: content: application/json: schema: $ref: '#/components/schemas/PasswordHashRangesSample' required: true responses: '200': description: Returns found data headers: X-RateLimit-Limit: schema: type: integer description: Request limit per second. Defaults 200 per second X-RateLimit-Remaining: schema: type: integer description: The number of requests left for the time window. X-RateLimit-Reset: schema: type: string format: date-time X-Quota-Limit: $ref: '#/components/headers/X-Quota-Limit' X-Quota-Remaining: $ref: '#/components/headers/X-Quota-Remaining' X-Quota-Reset: $ref: '#/paths/~1email/post/responses/200/headers/X-Quota-Reset' content: application/json: schema: $ref: '#/components/schemas/ZeroKnowledgePasswordSample' '400': description: Bad request content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' '401': description: Unauthorized content: application/json: schema: $ref: '#/paths/~1user/get/responses/400/content/application~1json/schema' security: - ApiKeyAuth: [] components: schemas: EmailAtoFiltered: required: - email_sha256 type: object properties: email_sha256: type: string description: A SHA256 hashed email address to generate fuzzed passwords for example: 2fc8583f3be53fcf1a6e0f972869478e392ef2a6f62b7b3735ca53af921ea304 database_ids: type: array description: A list of datbase IDs to generate fuzzed passwords items: type: string example: - 5f4e1f2e4b1d4d4e4b1d4d4e - 5f4e1f2e4b1d4d4e4b1d4d4f malware_ids: type: array description: A list of malware IDs to generate fuzzed passwords items: type: string example: - 5f4e1f2e4b1d4d4e4b1d4d4e - 5f4e1f2e4b1d4d4e4b1d4d4f credential_list_ids: type: array description: A list of credential list IDs to generate fuzzed passwords items: type: string example: - 5f4e1f2e4b1d4d4e4b1d4d4e - 5f4e1f2e4b1d4d4e4b1d4d4f fuzzing_intensity: type: integer description: Fuzzing intensity level parameter, which ranges from 0 to 10, 0 being no fuzzing, only original password returned, and 10 being the biggest rule set that returns over 50,000 fuzzed passwords per original password. default: 1 EmailsAto: required: - emails_sha256 type: object properties: emails_sha256: type: array description: A list of SHA256 hashed email addresses to generate fuzzed passwords items: type: string example: - 2fc8583f3be53fcf1a6e0f972869478e392ef2a6f62b7b3735ca53af921ea304 fuzzing_intensity: type: integer description: Fuzzing intensity level parameter, which ranges from 0 to 10, 0 being no fuzzing, only original password returned, and 10 being the biggest rule set that returns over 50,000 fuzzed passwords per original password. default: 1 example: 0 limit: description: Default is the maximum limit of 5 records type: integer example: 10 offset: type: integer example: 0 ZeroKnowledgePasswordSample: type: object properties: data: type: array items: type: object properties: hash: type: string example: 961b6dd3ede3cb8ecbaacbd68de040cd78eb2ed5889130cceb4c49268ea4d506 count: type: integer example: 11534 EmailsAtoPreventionSample: type: object properties: data: type: array items: $ref: '#/components/schemas/EmailAtoPreventionSample' limit: type: integer example: 10 offset: type: integer example: 0 EmailAtoPreventionSample: type: object properties: id: type: string example: 2a539d6520266b56c3b0c525b9e6128858baeccb5ee9b694a2906e123c8d6dd3 email: type: string example: email@example.com password: type: array items: type: string example: - password1 - password2 PasswordHashRangesSample: required: - data type: object properties: hash_ranges: type: array description: A list of hash ranges (6 hexadecimal characters) to lookup zero knowledge data items: type: string example: - '000000' - ffffff hash_type: type: string description: Currently only **sha256** is supported. example: sha256 EmailsAtoFiltered: required: - emails_sha256 type: object properties: data: type: array description: A list of SHA256 hashed email addresses together with source IDs to generate fuzzed passwords items: type: object properties: email_sha256: type: string description: A SHA256 hashed email address to generate fuzzed passwords for example: e9e7d0a8f5792167a054b4b1788fbe0bf0eb3d8ba8a6eee8ef42d3d7acb67f18 database_ids: type: array description: A list of datbase IDs to generate fuzzed passwords items: type: string example: - 5f4e1f2e4b1d4d4e4b1d4d4e - 5f4e1f2e4b1d4d4e4b1d4d4f malware_ids: type: array description: A list of malware IDs to generate fuzzed passwords items: type: string example: - 5f4e1f2e4b1d4d4e4b1d4d4e - 5f4e1f2e4b1d4d4e4b1d4d4f credential_list_ids: type: array description: A list of credential list IDs to generate fuzzed passwords items: type: string example: - 5f4e1f2e4b1d4d4e4b1d4d4e - 5f4e1f2e4b1d4d4e4b1d4d4f fuzzing_intensity: type: integer description: Fuzzing intensity level parameter, which ranges from 0 to 10, 0 being no fuzzing, only original password returned, and 10 being the biggest rule set that returns over 50,000 fuzzed passwords per original password. default: 1 example: 1 limit: description: Default is the maximum limit of 5 records type: integer example: 10 offset: type: integer example: 0 headers: X-Quota-Remaining: schema: type: integer description: The number of requests left for the period X-RateLimit-Limit: schema: type: integer description: Request limit per minute X-RateLimit-Remaining: schema: type: integer description: The number of requests left for the time window X-Quota-Limit: schema: type: integer description: Quota limit per minute X-RateLimit-Reset: schema: type: string format: date-time description: Date and time when rate limit counter resets parameters: Email: name: email-sha256 in: path required: true description: Hashed lower-cased email address using SHA256 algorithm schema: type: string HashRange: name: hash-range in: path required: true schema: type: string FuzzingIntensity: name: fuzzing-intensity in: query description: Fuzzing intensity level parameter, which ranges from 0 to 10, 0 being no fuzzing, only original password returned, and 10 being the biggest rule set that returns over 50,000 fuzzed passwords per original password. schema: type: integer securitySchemes: BasicAuth: type: http scheme: basic description: Authorization string. Needs to be in the standard BasicAuth format - "Basic BASE64_CREDENTIALS", where BASE64_CREDENTIALS is the user username:password encoded in base64 format. ApiKeyAuth: type: apiKey in: header name: X-API-KEY