Command Palette
Search for a command to run...
Identity Linking
Understand rarity-weighted identity evidence, graph traversal, safeguards, and API usage.
What the tool does
Start with an email, international phone number, or a username. LeakZero examines existing breach records for rare shared credential evidence, discovers service context internally, scores each connection, and follows only strong email or phone links. No extra profile fields are created and the breach database schema is not changed.
How a connection is discovered
Passwords are bridges, but their value depends on rarity. Multiple independent shared passwords are substantially stronger evidence than one. A matching service domain and a similar identifier name can support a link, but a domain never creates a link by itself.
Score and expansion rules
| Evidence | Effect | Can bridge alone? |
|---|---|---|
| Very rare shared password | Strong | Sometimes |
| Several distinct shared passwords | Very strong | Yes |
| Shared service domain | Supporting | No |
| Similar identifier name | Supporting | No |
| Common password | Ignored | No |
Safety limits and edge cases
Dashboard, Telegram, and API
The feature requires the breach_advanced_identity_linking subscription entitlement in every interface. Dashboard and Telegram searches consume one normal search row per returned candidate. Public API searches bill one API unit per returned candidate. Internal evidence rows are visible in metadata but are not billed.
curl -X POST https://api.leakzero.io/api/v1/public/search/identity-linking \
-H "x-api-key: lz_..." \
-H "x-timestamp: 2026-09-05T12:00:00Z" \
-H "content-type: application/json" \
-d '{
"field": "email",
"value": "[email protected]",
"maxDepth": 2,
"minConfidence": 0.35,
"maxResults": 50,
"includePossible": true
}'