Skip to content

Lookup

Lookup endpoints accept one fully qualified domain name (FQDN) as a URL path segment and return domain events as work completes.

Generate and analyze typosquatted permutations for a domain.

Scope: lookup:squat

Endpoint: GET /v2/squat/{domain}

Terminal window
export API_TOKEN="YOUR_API_TOKEN"
domain="example.com"
curl -N "https://api.haveibeensquatted.com/v2/squat/$domain" \
-H "Authorization: Bearer $API_TOKEN" \
-H "Accept: application/x-ndjson"

Generate permutations and return those that do not resolve in the Domain Name System (DNS).

Scope: lookup:nxdomain

Endpoints:

  • GET /v2/nxdomain/{domain}
  • GET /v2/discover/{domain}, an alias for the same operation
Terminal window
export API_TOKEN="YOUR_API_TOKEN"
domain="example.com"
curl -N "https://api.haveibeensquatted.com/v2/nxdomain/$domain" \
-H "Authorization: Bearer $API_TOKEN" \
-H "Accept: application/x-ndjson"

Both lookup operations support:

  • Accept: application/x-ndjson for streamed newline-delimited JSON (NDJSON).
  • Accept: application/json for one buffered merged JSON object keyed by domain.

If neither representation is requested, the endpoint defaults to NDJSON. Domain events contain permutation, op, and operation-specific data. Signal order is not stable, fields are optional, and clients must tolerate unknown operations.

Metadata events use op: "Meta". A streaming client must:

  1. Fail on data.kind: "Error".
  2. Treat data.kind: "Timeout" as incomplete.
  3. Require data.kind: "Done" before reporting success.

An HTTP 200 alone does not prove stream completion. Progress and Heartbeat are control events. StoredResult supplies a retained-result identifier when persistence applies.

Responses can include X-Hibs-Request-Id and, when a result is retained, X-Hibs-Result-Id.

For complete consumers and the merged-object shape, see handling streaming responses.

Status Meaning Client action
400 Invalid domain or request parameters Correct the request
401 Missing or invalid authentication Replace or restore the token
403 Missing scope or authorization Correct access before retrying
429 Rate limit reached Use bounded backoff and honor Retry-After
503 The service is unavailable or at capacity Use bounded backoff and honor Retry-After

Do not automatically repeat a request after its response stream has started. A second invocation can duplicate work.