The Non-Human Identities (NHI) API returns API keys, OAuth tokens, private keys, and other machine credentials that leaked from your employees' devices through infostealer malware, matched to your domain and enriched with device and source context.
Developers and operators keep secrets on their machines - in config files, shell history, browser storage, and editor projects. Infostealer malware takes those files along with everything else. Webz.io scans the leaked logs with detectors for hundreds of secret formats and matches every hit to the domains you monitor.
Each record is one secret: what kind of credential it is, which service issued it, whether it was still valid when checked, and the machine it came from.
Every record is enriched at collection time:
ApiKey, OauthPAT, RefreshToken, PrivateKey, ...), the detector that found it, and the matched value.verified, unverified, unknown).domain you want to check - see Quickstart.next URL to page through the rest - see Pagination.The first time you query a domain, Webz.io starts monitoring it. Until the initial scan finishes, responses carry "domainStatus": "pending" and may be empty or partial. Once it reads "active", the initial scan is complete - new records keep arriving as they are discovered, so query again over time.
A verified secret is a working credential. Rotate it first, then investigate the device it came from.