Lookup
Lookup endpoints accept one fully qualified domain name (FQDN) as a URL path segment and return domain events as work completes.
Generate and analyze typosquatted permutations for a domain.
Scope: lookup:squat
Endpoint: GET /v2/squat/{domain}
export API_TOKEN="YOUR_API_TOKEN"domain="example.com"
curl -N "https://api.haveibeensquatted.com/v2/squat/$domain" \ -H "Authorization: Bearer $API_TOKEN" \ -H "Accept: application/x-ndjson"NXDOMAIN
Section titled “NXDOMAIN”Generate permutations and return those that do not resolve in the Domain Name System (DNS).
Scope: lookup:nxdomain
Endpoints:
GET /v2/nxdomain/{domain}GET /v2/discover/{domain}, an alias for the same operation
export API_TOKEN="YOUR_API_TOKEN"domain="example.com"
curl -N "https://api.haveibeensquatted.com/v2/nxdomain/$domain" \ -H "Authorization: Bearer $API_TOKEN" \ -H "Accept: application/x-ndjson"Response contract
Section titled “Response contract”Both lookup operations support:
Accept: application/x-ndjsonfor streamed newline-delimited JSON (NDJSON).Accept: application/jsonfor one buffered merged JSON object keyed by domain.
If neither representation is requested, the endpoint defaults to NDJSON. Domain events contain permutation, op, and operation-specific data. Signal order is not stable, fields are optional, and clients must tolerate unknown operations.
Metadata events use op: "Meta". A streaming client must:
- Fail on
data.kind: "Error". - Treat
data.kind: "Timeout"as incomplete. - Require
data.kind: "Done"before reporting success.
An HTTP 200 alone does not prove stream completion. Progress and Heartbeat are control events. StoredResult supplies a retained-result identifier when persistence applies.
Responses can include X-Hibs-Request-Id and, when a result is retained, X-Hibs-Result-Id.
For complete consumers and the merged-object shape, see handling streaming responses.
Errors and retries
Section titled “Errors and retries”| Status | Meaning | Client action |
|---|---|---|
400 |
Invalid domain or request parameters | Correct the request |
401 |
Missing or invalid authentication | Replace or restore the token |
403 |
Missing scope or authorization | Correct access before retrying |
429 |
Rate limit reached | Use bounded backoff and honor Retry-After |
503 |
The service is unavailable or at capacity | Use bounded backoff and honor Retry-After |
Do not automatically repeat a request after its response stream has started. A second invocation can duplicate work.