datafetch.wtf

Documentation

Platform & API Reference

Integrate datafetch.wtf via REST API or use the web console. All endpoints require a valid API key on Pro, Ultra, or Owner plans.

Getting started

datafetch.wtf provides targeted OSINT for email, phone, Discord, IP, domain, username, Xbox Network, and PlayStation Network. Use the web console at datafetch.wtf, the REST API at https://api.datafetch.wtf, or the Telegram bot (optional).

Step 2Create your email + password at checkout (or register a free account)
Step 4Search in the dashboard, or call https://api.datafetch.wtf/api/v1/search with your API key

Console login is email and password. API keys are for REST automation only — create or rotate them under Dashboard → API keys after you sign in.

Architecture

Split stack: Next.js frontend (datafetch.wtf), Python API on a dedicated VPS. Cloudflare sits in front of both the site and API for TLS, WAF, and bot filtering. Always call the API over HTTPS (https://api.datafetch.wtf) — plain HTTP redirects with 301.

Websitehttps://datafetch.wtf — Next.js console, docs, login
APIhttps://api.datafetch.wtf — Python REST (HTTPS only)
EdgeCloudflare — DDoS, WAF, Turnstile, TLS
BFFNext.js /api/* proxies session to backend with X-DataFetch-BFF
Telegram botOptional client; same API underneath

Quick check

# Use HTTPS. On Windows PowerShell use curl.exe (curl is an alias for Invoke-WebRequest).
curl.exe -s "https://api.datafetch.wtf/api/v1/health"
# → {"status":"ok","service":"datafetch-api"}

External automation should call https://api.datafetch.wtf/api/v1/… with an API key. The web console uses session cookies and verifies Cloudflare Turnstile before each search.

Query modules

Each identifier type activates a dedicated pipeline. Queries are routed automatically by format detection, or pass module explicitly.

Email

[email protected]

BreachHub · Seekria · OpenArchive · Ithil · CoreSint · DataHound · OathNet · BreachVIP · SeekKnow · Syntrax · Godseye · IntelX · DeepScan · Local Breach · Horus · Account Recovery · Email Enrichment · Email to Profile · Snusbase · Minerva · SEON · LeakOSINT · AI OSINT · Auto Cascade

Phone

+39 333 1234567

DataHound · Horus · OathNet · LeakOSINT · Seekria · DeepScan · CoreSint · Phone Intel · Account Recovery · Partial Recovery · Shadow Partial · FiveM Link · Syntrax Phone · OpenArchive · Ithil · Local Breach · Snusbase · SEON

Telegram

@username or 123456789

DeepScan · DataHound · Horus Telegram · Phone Intel · Seekria

Ruin.tf

username

Ruin.tf RPC

Doxbin

username

Doxbin Leak DB · Local Breach DB · Doxbin Live

Dox Search

First Last or nickname

Doxbin Leak DB · Local Breach DB · Doxbin Search

Fiscal Code

RSSMRA85M01H501Z

CF Decoder · Belfiore · Local Breach DB · OathNet · LeakOSINT · BreachVIP · SeekNow

VAT Search

12345678901 or DE123456789

VIES EU · VATComply · OpenAPI IT · Local Breach DB · OathNet · LeakOSINT

Business Search

Acme Srl or P.IVA

OpenCorporates · Companies House · OpenAPI IT · VIES · Local Breach DB · OathNet

Business

John Smith / email / phone / company

Business Breach DB · USA B2B · Local Breach · OpenCorporates

IBAN Intel

IT60X0542811101000000123456

OpenIBAN · IBAN Checksum · Local Breach DB · OathNet · LeakOSINT · BreachVIP

VIN Lookup

1HGCM82633A004352

NHTSA vPIC · VIN Decode

Tax ID Search

CF, P.IVA, EIN, VAT or IBAN

Auto-detect · VIES · OpenIBAN · CF Decoder · Local Breach DB · OathNet · LeakOSINT

Partial Recovery

email or +39...

Instagram · Battle.net · Epic · EA · Apple · Google · PayPal · Uber · Twitter/X

Phone → Email

+39 333 1234567

Amazon · Apple · Google · Microsoft · Twitter/X · WhatsApp · Telegram · PayPal

Email → Phone

[email protected]

Amazon · Apple · Google · Microsoft · Twitter/X · PayPal · Steam · Epic

Shadow Leak

email, phone or username

Shadow Partial DB · Local Breach DB

FiveM Hunter

username, steam, license, discord id

FiveM Link DB · CFX Dumps · EvoLife · MoonLife

Discord Grave

username, email or discord id

Discord Scrape DB · Local Breach DB

PayPal Trace

email, username or IP

PayPal Logs · Buycraft · Tebex

DoorDash

email

DoorDash Recovery

PayPal

email

PayPal Recovery

DataAvoid

email

DataAvoid Recovery

Stripe

[email protected]

Stripe Dashboard

Discord

123456789012345678

CordCat · BreachVIP · OathNet · Syntrax Discord ID · datafetch.wtf Discord · BreachHub Discord Pack · Seekria Discord · Discord Graveyard · FiveM Link · DataHound · GodsEye · OpenArchive · Local Breach DB · SeekKnow · IntelX · Ithil · LeakOSINT · CoreSint

IP

192.168.1.1

OathNet · BreachVIP · Seekria · Local Breach DB · Syntrax IP · CoreSint · Shodan · SEON

Domain

example.com

DataHound · Seekria · Syntrax Domain

IntelX

domain, email or phone

IntelX Search

Folder

breach/subfolder

Folder Intel · Local Breach DB · Horus

Username

handle

DataHound · OathNet · LeakOSINT · BreachVIP · SeekKnow · Seekria · CSINT · CoreSint · Shadow Partial · FiveM Link · Discord Graveyard · PayPal Trace · Syntrax Username

GitHub

username or github.com/owner/repo

GitHub OSINT · Commit Scraper

Minecraft

Steve123

Seekria MC · Reconly · Local Breach DB · BreachVIP

FiveM

license:abc123 or username

Reconly FiveM · Local Breach DB · BreachVIP · Seekria

Xbox Network

MajorNelson or XUID

PlayerDB · xboxgamertag · TrueAchievements · BreachHub Xbox · Local Breach · CoreSint

PlayStation Network

OnlineId or psn:handle

PSNProfiles · TrueTrophies · BreachHub · Local Breach · CoreSint

Steam Lattice

7656119… or steamcommunity.com/id/…

Steam Community XML · BreachHub Steam · FiveM Link · Local Breach · CoreSint

Geolocation

Upload photo

EXIF GPS · OCR · Local Breach DB · Offline Geocoder · Satellite Map

Web console

Sign in with email and password. Overview shortcuts, streaming search, breach cards, Tools (Xbox Network, PlayStation Network, WolfLocate, stealer logs, VIN), history, tickets, and API keys for REST.

Dashboard/dashboard
Search (BFF)POST /api/search — body: { query, module?, horus?, stream?, turnstileToken }
Bot challengeCloudflare Turnstile on site entry + before each search
StreamingNDJSON stream for auto / email / Discord modules
API keysDashboard → API keys — for REST only, not console login

REST API

Base URL: https://api.datafetch.wtf

Authenticate with X-Api-Key header. Requires Pro, Ultra, or Owner plan. Device binding applies to dashboard login.

AuthX-Api-Key header (required for API calls)
Device bindX-Device-Id header (web console)
TurnstileBot protection on web console
FormatJSON — POST bodies application/json
QuotaPlan-based lookup limit (429 when exceeded)
CORSEnabled for datafetch.wtf and API subdomain
# Quick test
curl.exe -s "https://api.datafetch.wtf/api/v1/health"
curl.exe -s "https://api.datafetch.wtf/api/v1/status" -H "X-Api-Key: YOUR_API_KEY"

Security

Defense in depth: Edge protection (DDoS, OWASP WAF, bot filtering) plus strict origin controls. The database is never reachable over HTTP.

Edge protection

DDoSProtection against volumetric attacks
Bot Fight ModeBlocks automated abuse while allowing legitimate API clients
OWASP managed rulesSQLi, XSS, RCE probes blocked at edge
Custom WAFBlocks malicious path patterns and scanners
Rate limitsPer-IP and per-key rate limiting enforced
TunnelOrigin access restricted via edge headers

API origin

Origin protectionDirect IP access blocked without edge headers
Path whitelist/api/v1/* only — probes blocked
Rate limitsPer-IP and per-API-key rate limiting
Auth hardeningConstant-time key validation
Injection filterSQLi/XSS patterns in query/path rejected
Scanner blockKnown scanner User-Agents denied
Payload capMaximum POST body size enforced
HeadersHSTS, nosniff, frame protection, no-store
Key transportX-Api-Key header required

Web console

TurnstileBot protection on entry and sensitive actions
MiddlewareSecurity headers on all pages + API routes
Edge rate limitsPer-IP rate limiting enforced
CookiesHttpOnly, Secure, SameSite=Lax, .datafetch.wtf
CSPconnect-src includes api.datafetch.wtf + challenges.cloudflare.com

Your checklist

  • Run bash deploy/security-setup.sh and apply every rule.
  • Enable IP whitelist for production API keys.
  • Never expose keys in frontend JavaScript or public repos.
  • Regenerate key immediately if leaked.

Endpoints

Authenticated endpoints require X-Api-Key header unless logged in via the web console.

GET/api/v1/health

Health check. No authentication. Minimal public response.

curl.exe "https://api.datafetch.wtf/api/v1/health"
GET/api/v1/status

Returns plan, usage count, and remaining lookups.

curl.exe "https://api.datafetch.wtf/api/v1/status" -H "X-Api-Key: YOUR_API_KEY"
GET/api/v1/search

Execute OSINT search via query string. Consumes one lookup.

curl.exe "https://api.datafetch.wtf/api/v1/[email protected]" \
  -H "X-Api-Key: YOUR_API_KEY"
POST/api/v1/search

Recommended. JSON body with query, optional module, stream: true for NDJSON, turnstileToken when Turnstile is enabled, and horus: true for Horus OSINT (€0.10/search).

curl.exe -X POST "https://api.datafetch.wtf/api/v1/search" \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"query":"+393331234567","module":"phone","horus":false,"stream":true}'
GET/api/v1/analytics

Search statistics, recent history, wallet balance, Horus config.

curl.exe "https://api.datafetch.wtf/api/v1/analytics" -H "X-Api-Key: YOUR_API_KEY"
GET/api/v1/horus/modules

List Horus modules permitted for your API key.

curl.exe "https://api.datafetch.wtf/api/v1/horus/modules" -H "X-Api-Key: YOUR_API_KEY"
POST/api/v1/analyze

Folder or file analysis — scan breach dumps for identifiers.

curl.exe -X POST "https://api.datafetch.wtf/api/v1/analyze" \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"folder":"breach/subfolder"}'
POST/api/v1/account/ip-whitelist

Set allowed IPs for your API key (empty list = allow all).

curl.exe -X POST "https://api.datafetch.wtf/api/v1/account/ip-whitelist" \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"ips":["203.0.113.10","198.51.100.5"]}'

Response shape

pages[]Paginated result sections
data.sections{}Raw source payloads keyed by module
metaduration_ms, source_count, horus_used, wallet_cents
402Insufficient Horus wallet balance

Error codes

400Missing query or malformed request
401Invalid or missing API key
402Insufficient Horus balance
403Plan insufficient, banned, device/IP blocked, or Turnstile failed
404Unknown path (non-API routes blocked)
429Lookup limit or rate limit exceeded
500Search execution error

Support

Contact @spyharver_help on Telegram for payments, activation, and technical support.