Webz.io logoDocs
Overview
Start Here
News, Blogs, Forums & Reviews APIs
News Search API
Firehose
Cyber API
Data Breaches API
Leaked Cookies API
Non-Human Identities (NHI) API
Domain Exposure API
Introduction
Quickstart
Response Fields
API Reference
Use Cases
News, Blogs, Forums & Reviews Archive
Web Content API (Deprecated)
Webz.io logo
Overview
Start Here
News, Blogs, Forums & Reviews APIs
News Search API
Firehose
Cyber API
Data Breaches API
Leaked Cookies API
Non-Human Identities (NHI) API
Domain Exposure API
Introduction
Quickstart
Response Fields
API Reference
Use Cases
News, Blogs, Forums & Reviews Archive
Web Content API (Deprecated)
Webz.io DocumentationContact our team© 2026

Introduction

The Domain Exposure API summarizes credential exposure associated with a domain over the previous 12 months.

The report combines two types of compromised credential data:

  • Data breaches — credentials exposed through breaches, database dumps, and combo lists.
  • Infostealer logs — credentials collected from malware-infected devices.

It also distinguishes between two types of exposure:

  • Employee exposure — compromised accounts associated with the organization's domain.
  • Client exposure — compromised users found logging into services belonging to the domain.

For example, a compromised @example.com employee account would contribute to employee exposure. A compromised Gmail user whose infostealer log contains credentials for example.com would contribute to client exposure.

The API returns aggregated statistics rather than individual credentials or personally identifiable information.

Terms of use

The Domain Exposure API is completely free to use. No account, API key, or access token is required, and there is no defined rate limit. As with any public page or service operated by Webz.io, abusive traffic from a single IP address, such as excessive automated requests that resemble a denial-of-service attack, may be blocked or restricted. When using data from the API publicly, a link to LunarCyber.com as the data source is appreciated, but attribution is not required.

Last updated: August 30, 2026
PreviousDomain Exposure APINextQuickstart