datafetch.wtf

Documentation

API reference

The datafetch.wtf REST API returns structured intelligence for emails, phones, usernames, domains, IPs and gaming identifiers. Every request is authenticated with an API key and metered against your plan.

Upstream reference: domain intelligence and the extended endpoint reference are documented at coresint.xyz.

Open coresint API docs

Authentication

Send your key on every request. Keys are created in the console and shown once.

# curl
curl -s https://api.datafetch.wtf/api/v1/health

# authenticated search
curl -s -X POST https://api.datafetch.wtf/api/v1/search \
  -H "Content-Type: application/json" \
  -H "X-Api-Key: $DATAFETCH_API_KEY" \
  -d '{"module":"email","query":"[email protected]"}'

Always call the API over HTTPS. Keys are stored hashed — rotate them from Dashboard → API keys if one leaks.

Endpoints

MethodPathDescription
GET /api/v1/health Liveness probe. Returns service status and version.
GET /api/v1/status Authenticated status for the calling key, including remaining quota.
POST /api/v1/search Run a lookup. Accepts module + query, or stream:true for NDJSON.
GET /api/v1/search?q= Convenience lookup with automatic module detection.
POST /api/v1/analyze Enrich an existing report with correlation and scoring.
GET /api/v1/analytics Usage analytics for the calling key or account.
GET /api/v1/horus/modules List available query modules and their metadata.
GET /api/v1/account/ip-whitelist Read the IP allow-list bound to your key.

Domain lookup

Domain and infrastructure intelligence (WHOIS, DNS, subdomains, certificates and hosting history) is provided through the coresint upstream. The console's Domain lookup module targets it directly.

# console → Network & domains → Domain lookup
https://coresint.xyz/api-docs

Rate limits & errors

429

Too many requests. Honour Retry-After before retrying.

401

Missing or invalid API key.

402

Quota exhausted for the current billing period.

403

Key not permitted from this IP address.

422

Query could not be parsed into a supported module.

500

Upstream error. Logged with a request id for support.

Errors use a consistent envelope: { "error": { "code": "…", "message": "…" } }.