Breach intelligence

DeHashed OSINT integration

Credential and breach intelligence from the DeHashed dataset.

DeHashed searches breach records for emails, usernames, phones, domains, names, and IPs — returning credential rows with database provenance, leak dates, and related identity fields. Its public list, as of 22 September 2026, has 24,051 data wells and 24,507,853,884 pieces of data.

Capabilities
What this integration is designed to return.
Field-scoped search across email, username, phone, domain, name, and IP
Return breach records with database name and leak metadata
Surface plaintext and hashed passwords when present in source data
Public corpus of 24,051 data wells and 24,507,853,884 pieces of data (as of 22 September 2026)
Show total hits and remaining API balance from upstream metadata
Best for
Typical investigation fits.
Credential stuffing and account takeover assessments
Domain and employee exposure reviews
Complementing LeakRadar and LeakOSINTbot breach views

How the DeHashed integration works

What happens between pressing run and reading a result.

  1. 1Choose email, username, phone, domain, name, or IP and select DeHashed.
  2. 2SearchIn maps your input type onto the matching DeHashed search field and issues the query.
  3. 3Matching breach records return with database provenance, leak metadata, and identity fields.
  4. 4SearchIn groups records by database, masks password and hash fields behind a reveal toggle, and keeps totals from upstream.
Data coverage
What the underlying dataset reaches.

As of 22 September 2026, DeHashed’s public list has 24,051 data wells and 24,507,853,884 pieces of data. Each well is a named source with a date and a record count.

Data sources

SearchIn queries DeHashed by email, username, phone, domain, name, or IP. The figures below are from DeHashed’s public data-wells page, so you can see the size of the corpus before you spend a query.

DeHashed data wells
Data wells
24,051
Pieces of data
24.51 billion

DeHashed’s published total is 24,507,853,884 pieces of data across those wells. That is a record count, not a count of unique people.

Stats checked
22 September 2026
Named sources
24,051 wells

Name

DeHashed publishes each data well by name. A SearchIn result is grouped under the well it came from.

Record counts
Per well

Count

Each well has its own record count. Added together, DeHashed reports 24,507,853,884 pieces of data.

Well dates
On the public list

Date

Each well includes a date. DeHashed’s site also says 4.0 records are still being indexed, so a missing well may not be searchable yet.

What a SearchIn query returns
A query returns the wells that match one identifier.
Rows come back grouped by data well, with a leak date when DeHashed sends one.
Password and hash fields stay masked until you reveal them.
A row is historical breach data. It does not confirm the credential still works.
DeHashed’s site says records are still being indexed after the 4.0 release.

Supported inputs & pricing

Prices are USD. LeakRadar includes 1,000 credential unlocks in the query price, then $0.50 per extra 1,000. OSINT Industries is $0.60 plus optional premium modules at $1.80. Other integrations are flat per query. Full SearchIn rates are on pricing.

DeHashed SearchIn pricing by input type
Input typePrice
Emailemail$0.30
Usernameusername$0.30
Phonephone$0.30
Domaindomain$0.30
Namename$0.30
IP addressip$0.30

Why run DeHashed through OSINTverse

You can always buy DeHashed directly. Here is what changes when the same data comes through SearchIn instead. Full write-up: OSINTverse vs DeHashed.

Pay $0.30 when you actually search instead of carrying a subscription between cases.

Password and hash fields are masked by default with a reveal toggle — safer for screen shares and shared team workspaces.

Run DeHashed, Snusbase, and LeakRadar on the same identifier in one batch to see where the datasets disagree.

DeHashed directly compared with DeHashed through OSINTverse SearchIn
 DeHashed directlyThrough OSINTverse
Getting startedDeHashed sells its own paid subscription with an API key bound to a single account.Sign in, top up from $10, and run DeHashed the same minute — no vendor contract, seat, or sales call.
What a query costsPlan, credit pack, or contract pricing set by the vendor and paid up front.Pay per query from your prepaid balance — DeHashed starts at $0.30 for email lookups, with the exact price shown before you run it.
Failed lookupsHandled under the vendor's own credit and refund policy.Automatically refunded to your wallet — a search that fails upstream after billing is not charged.
Output formatA vendor-specific response shape you normalise and render yourself.Normalised result panels plus the raw JSON, returned by the same POST /v1/search contract as every other integration.
Cross-source workCopy-paste between vendor dashboards to follow a lead into another dataset.Results join one case graph, so you can pivot an entity into any of the other 16 integrations in a click.
Running it for a teamPer-seat or per-account access, billed and administered per analyst.One shared team wallet with roles, provider allowlists, enforced MFA, and audit history — no per-seat fee.
Volume workScript the vendor API yourself, including retries, polling, and rate handling.Bulk search takes up to 50 queries across selected providers in one submission (max 100 jobs), with per-job status and partial-failure handling.

What every integration inherits

One wallet, no subscriptions
Top up prepaid USD from $10 and spend it a query at a time across all 17 integrations. No monthly fee, no seat count — and the balance never expires.
Failed searches are refunded
If an upstream provider errors or times out after the charge, the search is marked refunded and the money goes back to your wallet automatically.
One API for every source
The same POST /v1/search contract and x-api-key header work for every integration, so adding a source to your automation is a one-word change.
Cases and pivot graph
Results land in a named case you can reopen. Entities become graph nodes you can pivot from into any other integration without retyping.
Team wallets and controls
Share one balance with roles, provider allowlists, enforced MFA, and audit history — instead of buying a vendor seat for every analyst.
Exports built in
Download any result as JSON, CSV, or PDF, and export the case graph as PNG, SVG, entities CSV, or graph JSON.

Good to know

Constraints worth reading before you spend a query.

A returned password or hash comes from a historical breach. It does not confirm the credential still works.

DeHashed’s site says 4.0 records are still being indexed, so a well on the public list may not be in search results yet. Figures on this page are from 22 September 2026.

The published total counts pieces of data, not unique people.

Name and IP searches are broader than email or username, so expect more noise to filter.

Going direct still makes sense at sustained high volume on a single source. DeHashed sells its own paid subscription with an API key bound to a single account. Through SearchIn you trade that commitment for per-query pricing across 17 integrations.

How to access DeHashed

Access via SearchIn UI
Run the integration without leaving the dashboard.
  1. Choose Email, Username, Phone, Domain, Name, or IP.
  2. Select DeHashed.
  3. Review grouped breach records and expand sensitive fields as needed.

What you'll see

  • ·Records grouped by breach database
  • ·Masked password fields with reveal toggle
  • ·Filter across databases and record fields
  • ·Upstream total and balance metadata
Open with this integration
Access via API
Authenticate with x-api-key, then create a search job.

Use POST /v1/search with provider dehashed. Poll GET /v1/search/{id} when status is running (FaceCheck).

curl -X POST "https://apiv1.osintverse.com/v1/search" \
  -H "Content-Type: application/json" \
  -H "x-api-key: ov_your_api_key" \
  -d '{"provider":"dehashed","input_type":"email","query":"alex.rivera@example.com"}'

Sample queries

email
alex.rivera@example.com
Credential exposure check
domain
example.com
Domain-wide breach footprint
ip
203.0.113.45
IP-linked breach records

Investigations that use DeHashed

FAQ

DeHashed on OSINTverse, answered

How do I use DeHashed in SearchIn?

Choose Email, Username, Phone, Domain, Name, or IP. Select DeHashed. Review grouped breach records and expand sensitive fields as needed.

How do I call DeHashed from the OSINTverse API?

Authenticate with an x-api-key header, then POST /v1/search with provider "dehashed" and a supported input_type (email, username, phone, domain, name, ip). Poll GET /v1/search/{id} if the job returns running.

What does DeHashed cost on SearchIn?

Email: $0.30. Username: $0.30. Phone: $0.30. Domain: $0.30. Name: $0.30. IP address: $0.30. You see the price before every run, and there is no subscription.

Why use OSINTverse instead of DeHashed directly?

DeHashed sells its own paid subscription with an API key bound to a single account. On OSINTverse you pay per query from one prepaid USD wallet with no subscription, failed searches are refunded automatically, results are normalised into a case graph you can pivot into other sources, and the same POST /v1/search contract reaches every integration. Pay $0.30 when you actually search instead of carrying a subscription between cases. Password and hash fields are masked by default with a reveal toggle — safer for screen shares and shared team workspaces. Run DeHashed, Snusbase, and LeakRadar on the same identifier in one batch to see where the datasets disagree.

What are the limits of DeHashed on SearchIn?

A returned password or hash comes from a historical breach. It does not confirm the credential still works. DeHashed’s site says 4.0 records are still being indexed, so a well on the public list may not be in search results yet. Figures on this page are from 22 September 2026. The published total counts pieces of data, not unique people. Name and IP searches are broader than email or username, so expect more noise to filter.

Run DeHashed alongside every other source

One login, one prepaid wallet, and the price shown before every lookup.

  • No subscription
  • Credits never expire
  • Human support