Create one private vault key, save it yourself, and use that exact key whenever you return. It is also your API key—there is no email, password, or fragile browser-only login to recover.
Automatic accounting review
{{ sessionData.accountReview.heldCredits || 0 }} promotional credits are temporarily held. Purchased credits and active paid plans still work.
{{ fmtTs(ann.ts) }}
{{ paymentReturn.message }}{{ paymentReturn.detail }}
Receipt {{ paymentReturn.orderId }} (not an API key) - {{ paymentReturn.grantLabel }}
Problem with a payment? You'll never lose money or pay twice - message @HiGIMY on Telegram and we'll sort it out. Your past orders are always visible in Account > Plans.
DropbaseShop
Plans, access, and balance
Choose what you need, review the exact price, and complete delivery from this private vault.
Search credits{{ creditStr }}
Vault-protected checkout
Prices are shown before an order is created. Delivery and receipts remain linked to this vault.
Plans
Choose a plan
Loading current plans...
{{ buyCredits.error }}
Plan purchasesSearch credit and API plan orders{{ paymentHistory.orders.length }}
{{ searchExecuted ? 'Broaden the query' : 'Start with the strongest identifier' }}
{{ searchExecuted ? 'Shorten the value, change its field, or enable both data sources.' : 'Use an email, username, phone, IP, name, address, domain, SSN, or another exact value.' }}
Exact firstBegin with the most specific value.
Stack filtersUse + to narrow the same person.
Vault privateYour workspace stays in this vault.
No records found
No matches for this query in {{ lookupSourceLabel }}
Try enabling Smart Search - it normalises input and also searches hashed passwords.Turn both Database sources on from the Sources dropdown.Try another field or a shorter query. Some sources only support certain identifiers.
This image carries no GPS tag. The metadata below is everything the file itself records.
File metadata
{{ key }}
{{ imageExifResults[key] }}
Reading image metadata
{{ imageGeoError }}
Search results
{{ osintExtraResults._target }}
Live · building{{ osintSimpleResultGroups().length + (osintIsNameResult && osintPossiblePeopleBlocks.length ? 1 : 0) }} data groups{{ (osintExtraElapsedMs / 1000).toFixed(1) }}s{{ osintProgress.evidenceCount }} found so far
Source coverage{{ osintScanCoverageBlock().fields['Providers Responded'] || 0 }} provider tasks respondedSome sources could not complete
Unavailable sources leave gaps. Their failure is not evidence of no match.
{{ osintResultQuery ? 'No results match this filter' : (osintExtraLoading ? 'Waiting for the first results' : (osintReportHasSourceIssues() ? 'Search coverage is incomplete' : 'No matching data')) }}
{{ osintResultQuery ? 'Try a different term or clear the filter to see the report.' : (osintExtraLoading ? 'Completed sources will appear here as they arrive.' : (osintReportHasSourceIssues() ? 'Some sources failed or are unavailable. Open Source coverage to see what needs attention; this is not a confirmed no-match.' : 'The sources checked did not return matching data.')) }}
{{ osintVisibleSelectedModuleCount }} modules checked. {{ osintNameReturnedSourceCount() }} returned relevant evidence; providers with no exact match are hidden.
{{ osintDossierSummaryHeading() }}
{{ osintDossierCorrelationNotice() }}
{{ card.title }}
{{ item.value }}{{ item.source }}
No confirmed data
Source coverage
{{ osintDossierCoverageCards().length }} groups checked
{{ card.hiddenHudsonCredentials }} masked credential field{{ card.hiddenHudsonCredentials === 1 ? '' : 's' }} hidden from this summary. Use All Intel or unmask/search actions for details.
Exact-target search
Pivoting masked credentials against the stealer-log DB…
Every request below is a real, runnable call against this account's API. Authenticate with your vault API key, then copy a sample and change the values.
{{ sample.title }}
{{ sample.summary }}
{{ sample.method }}
{{ sample.path }} API key Public {{ sample.cost }}
Display density
Compact is the default and keeps more information visible.
Your private vault
One saved key for Search, OSINT, Shop, SMS, and API
Site profile
{{ row.label }}{{ row.value }}
Optional ad rewards
A little support. More searches.
Choose an ad link, complete the provider's steps, then claim your credits here.
{{ credits }}your credits
Only verified completions earn credits. No signup bonuses or referral rewards. Your existing balance stays yours.
Telegram
{{ earnTelegram.credits }} credits a day for the channel link in your bio
Keep {{ earnTelegram.channelLink }} in your Telegram bio and stay in the channel. {{ earnTelegram.credits }} credits now, then {{ earnTelegram.credits }} more every full day both hold.
+{{ earnTelegram.credits }} per day
{{ earnTelegram.initials }}
{{ earnTelegram.displayName }}@{{ earnTelegram.username }}no username set
Disconnected. Reconnect the same account to start earning the daily credits again{{ earnTelegram.joiningBonusPaid ? ' — the joining bonus has already been paid' : '' }}.Not connected. Connecting opens Telegram so we can confirm which account is yours.
{{ earnTelegramMessage }}
Updates on its own while this page is open. One Telegram account per vault.
Last checked {{ historyTimeAgo(sip.lastCheck.at) }} —
registered with {{ sip.lastCheck.server || 'the provider' }} in {{ sip.lastCheck.latencyMs }} ms.
{{ sip.lastCheck.hint || sip.lastCheck.reason || 'the provider refused the credentials.' }}
Nothing has been tested yet. Add your provider details and press Test.
API access
One vault. Every API.
Your saved private vault key authenticates every API request. Dropbase only shows a masked preview here and never re-displays the raw key.
Choosing “Not my vault” never disables anti-abuse protection; it only declines this account connection.
Developer platform
Dropbase API reference
Search data and run OSINT with one private vault key.
Data/api/v1
Quick start
One key for the complete platform
Choose an endpoint, authenticate from your server, and receive structured JSON or streaming events.
One private vault key authenticates every documented endpoint, and each billable call spends one credit.
Keep the key on your server and review account status in Settings → API.
Base URL{{ apiDocsBaseUrl }}/api/v1
Auth headerX-Api-Key: YOUR_KEY
FormatJSON / streaming SSE
Endpoints
GET/healthservice status - no auth
GET/planyour key + limits
GET/schematables & columns
POST/searchbreach & malware search
POST/osintOSINT on one target
POST/backup-lookupfallback provider
GET/osint/modulesOSINT module catalog
Credits
Every account starts with 10 credits (one-time - they don't reset). Each API call spends 1.
Pick what the key spends in the API tab:
Site creditsYour normal balance. Top up anytime with crypto on the main page.
RecurringRegenerating pool that refills every minute. Buy or extend it in Shop → Plans.
Exact breach searches automatically include reviewed values stored in extended JSON. Existing concepts keep one name: for example email searches both the primary email and approved alternate-email keys. JSON-only fields are exact-match only. Leading wildcard searches such as %example.com use the primary column and may take longer.
For malware URL credential pulls, dedupe:true makes the server fetch an expanded raw window, remove duplicate login:password pairs, then apply limit. A limit of 1000 means up to 1000 final unique credential pairs, not 1000 raw rows reduced in the browser.
Breach columns
email username password
phone name first_name
middle_name last_name address
street city state
zip ssn dob
ip discord_id url
display_name country county
company job_title industry
gender age language
registration_date last_active latitude
longitude carrier line_type
fax income net_worth
home_value marital_status children
education ethnicity vehicle_vin
vehicle_make vehicle_model vehicle_year
facebook_id steam_id xbox_id
fivem_id source breach_source
Run typed or automatically detected public-source modules with optional evidence-linked pivots.
POST/api/v1/osint
Target type is auto-detected using the public suffix list. Accepts: emails, usernames, phone numbers, IPs, domains, Discord IDs, Steam IDs, hashes, Bitcoin addresses, names, and addresses. For ambiguous dotted handles, pass "type":"username" or "type":"domain". Set "advanced": true (or "smart": true) to scan exact linked artifacts with source provenance. Pass "modules":["module_key"] to run only selected modules.
Requires X-Api-Key.
Lists every module key, target type,
source, license, and access class.
GET /api/v1/health
No key required.
Returns service status.
GET /api/v1/plan & /schema
Requires X-Api-Key.
plan -> key name & limits
schema -> tables, columns, OSINT types
Fallback API
Use the backup provider safely
Submit one exact value with strict limits, caching, and predictable provider costs.
POST/api/v1/backup-lookup
{{ apiServiceStatus.backup === 'up' ? 'Working' : apiServiceStatus.backup === 'down' ? 'Down right now' : 'Waiting for first lookup' }} API-key-only fallback search against the backup database provider. It accepts one exact value per request. Successful identical searches are cached for one hour to avoid repeat provider charges.
— means no eligible denominator exists in this window; it does not mean a measured 0% rate. Referral activation uses accepted referrals as its cohort. Block rate is unique participants with a blocked attempt divided by unique accepted-or-blocked participants; no block reasons, referral codes, IPs, or device data enter this ledger.
Lifecycle healthAggregate consent and provider state
Active consent{{ adminGrowth.lifecycle.activeConsent || 0 }}
List opt-out rate{{ growthRateDisplay(adminGrowth.lifecycle.listOptOutRate, adminGrowth.lifecycle.consented) }}
Provider acceptance does not prove inbox delivery, opens, or clicks. List opt-out rate describes current consent-list health, not campaign attribution. No addresses, recipient IDs, provider errors, tokens, or message content are shown.
Updated {{ adminGrowth.generatedAt ? adminRelTime(adminGrowth.generatedAt) : 'when data is available' }}. Empty states are real; this dashboard never fabricates baseline metrics.
Legacy accounts{{ adminLegacySessionCount }}upgrade on next vault sign-in
Paid plans awaiting import{{ adminLegacyPaidCount }}preserved until claimed
Existing credits, purchases, and API plans move into a newly opened vault when that owner imports their old API key or paid receipt. Two existing vaults are never merged.
Repeated attempts are grouped into one incident. Actor, browser, session, and key evidence is hashed or redacted so this page is safe to export for analysis.
Index query latency{{ adminDbHealth.took_ms || 0 }} ms
Edit Credits
Investigator ToolsFocused utilities for credentials, domains, usernames, hashes, and logs 6 tested utilities
{{ toolsTab==='urlcreds' ? 'Search credential combinations' : toolsTab==='domain' ? 'Explore a domain' : toolsTab==='userpivot' ? 'Pivot from a username' : toolsTab==='planner' ? 'Plan a mixed-identifier investigation' : toolsTab==='hashgen' ? 'Generate hash variants' : 'Parse a credential log' }}{{ toolsTab==='urlcreds' ? 'Search malware records without leaving the current workspace.' : toolsTab==='domain' ? 'Collect matching breach records with useful export controls.' : toolsTab==='userpivot' ? 'Connect breach evidence, public profiles, and related identifiers.' : toolsTab==='planner' ? 'Normalize and classify mixed evidence before launching exact OSINT scans.' : toolsTab==='hashgen' ? 'Generate common hashes and search them individually or together.' : 'Turn pasted stealer-log text into clean credential pairs.' }}
Search malware logs by URL, login, or password. Filters can import more rows when the visible pair count is short.
All {{ toolsUrlFilterCounts.all }} email:pass {{ toolsUrlFilterCounts.email }} user:pass {{ toolsUrlFilterCounts.user }} has password {{ toolsUrlFilterCounts.pair }}
Searching exact password valuesChecking plaintext and all generated hashes in breach and malware datasets.
The search did not run{{ toolsHashError }} Nothing was checked against the breach or malware datasets, so this is not a result — try again once it can run.
Database matchesExact matches only · {{ toolsHashMatches.length }} records