Skip to main content
A temporary search runs exactly like a normal search: the same modules, leak sources, and account checks, executed the same way, with results arriving as soon as each one is found. The difference is that results stream directly in the HTTP response. Osintly does not create a search record, store the results, read or write result caches, or keep a replay of the stream. When the response ends, Osintly has nothing left to return: save what you need in your own system as it arrives. Use it when an investigation should leave no searchable trace on Osintly’s side, or when your integration already processes results as they stream. Send the same body as Create Search to POST /search/temporary, and keep the connection open:
Temporary searches only run through this endpoint. POST /search rejects a temporary field with 400 USE_TEMPORARY_ENDPOINT, so a request meant to be temporary can never be stored by mistake. The request goes through the same authentication, plan limits, concurrency check, and blocklist as a normal search, and counts toward your API usage in the same way. Search options behave as they do on POST /search. For example, features.registered_accounts: "only" runs only the registered-account check, without modules, leak sources, or breached accounts, and leaks.custom_mapping selects the leak record format.

Response

A successful request returns 200 with a Server-Sent Events stream instead of a JSON body.

Events

Events have the same names and fields as in the normal stream, with two additions for results that cannot be fetched later: As in the normal stream, search.finished is the last event. If some modules failed, it still has status completed, with an error such as partial failures: 3 module(s). status is failed only when the search could not run. Because nothing is stored, leak records arrive inside the stream. Each temporary.leak.page event carries one page of up to 500 records:

Differences from the normal stream

  • There is no leak.page.ready event, since leak pages arrive as temporary.leak.page, and no BYOK event, since temporary searches do not accept byok.
  • Events have no SSE id:, and the stream cannot be resumed. If the connection drops, the search stops and its results are lost; start a new search to try again.
  • GET /search/{id}, /results, /results/leaks, and /stream do not know temporary searches, and the search cannot be deleted because it was never stored.

What Osintly does not keep

  • No search record, history entry, or search ID that can be fetched later
  • No stored module results, leak records, registered accounts, or breached accounts
  • No result cache: the cache option is ignored, every provider is queried fresh, and nothing is written for later searches
  • No module output in runner logs for the search
Usage accounting records the search type and the leak sources you requested, so your plan usage stays accurate. It does not record the searched value.

Limits and errors

Other errors, such as an invalid API key or an exceeded plan limit, are the same as for POST /search. Sending temporary to POST /search instead returns 400 USE_TEMPORARY_ENDPOINT and starts no search.
In the Osintly app, temporary search is a separate option on the Search page. See Temporary search.