# OSINT Paste Site Search (`jungle_synthesizer/osint-scraper`) Actor

Search Pastebin, GitHub Gist, Ideone, Paste.org and Textbin for public pastes mentioning your keywords - leaked credentials, API keys, hostnames, or any other exposure. Returns each match's title, URL and snippet, per keyword and site.

- **URL**: https://apify.com/jungle\_synthesizer/osint-scraper.md
- **Developed by:** [BowTiedRaccoon](https://apify.com/jungle_synthesizer) (community)
- **Categories:** Developer tools, SEO tools
- **Stats:** 3 total users, 2 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $0.80 / 1,000 record scrapeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Pastebin & Code Paste Site Scraper — Leaked Data Search

Search [Pastebin](https://pastebin.com), [GitHub Gist](https://gist.github.com), [Ideone](https://ideone.com), [Paste.org](https://paste.org) and [Textbin](https://textbin.net) for public pastes mentioning your keywords. Returns the matching page title, URL and result snippet for every hit — a leaked API key, an exposed credential, an internal hostname, or anything else you're checking for public exposure.

***

### Pastebin Paste Site Scraper Features

- Searches five paste and code-sharing sites in one run — Pastebin, GitHub Gist, Ideone, Paste.org, Textbin.
- Restrict the search to any subset of those sites, or search all five at once.
- Runs every keyword against every selected site, so a batch of terms takes one run instead of five.
- Returns the site, title, URL and snippet for each match. No page-scraping guesswork — it's the same summary a human search would return, structured into rows.

***

### Who Uses Paste Site Leak Data?

- **Security teams** — check whether a company's API keys, credentials, or internal config ever showed up on a public paste.
- **Incident responders** — confirm a suspected leak is actually indexed and pull the exact URL, instead of manually running the same search five times.
- **Bug bounty hunters** — sweep a target's known secrets patterns across paste sites as part of recon.
- **Engineering teams** — run a periodic check on internal project names or hostnames, catching an accidental `git push` of a `.env` file before someone else finds it.

***

### How Pastebin & Paste Site Scraper Works

1. Give it a list of keywords — a leaked key prefix, a company domain, a username, anything you want to check.
2. Pick which sites to search, or leave all five selected.
3. It runs a `site:`-restricted search for every keyword across every selected site and saves a row per match, up to your `maxItems` cap.

***

### Input

```json
{
  "keywords": ["example-corp-api-key"],
  "sites": ["pastebin.com", "gist.github.com"],
  "maxItems": 15
}
```

| Field      | Type    | Default                                           | Description |
|------------|---------|---------------------------------------------------|-------------------------------------------------------------------------------------------------|
| `keywords` | array   | —                                                 | Search terms to look for — a leaked API key prefix, a company domain, a username, or any string. |
| `sites`    | array   | Pastebin, GitHub Gist, Ideone, Paste.org, Textbin | Which sites to restrict the search to. Select one or more. |
| `maxItems` | integer | `15`                                              | Maximum number of results to return across all keywords and sites combined. |

***

### Pastebin & Paste Site Scraper Output Fields

```json
{
  "keyword": "example-corp-api-key",
  "site": "pastebin.com",
  "title": "config backup - Pastebin.com",
  "url": "https://pastebin.com/AbCdEfGh",
  "snippet": "... example-corp-api-key: sk_live_xxxxxxxxxxxx ...",
  "position": 1
}
```

| Field      | Type    | Description                                                          |
|------------|---------|----------------------------------------------------------------------|
| `keyword`  | string  | The search term that produced this result.                           |
| `site`     | string  | The paste/code-sharing site domain the result was found on.          |
| `title`    | string  | The result's page title.                                             |
| `url`      | string  | The full URL of the matching page.                                   |
| `snippet`  | string  | The result preview text — usually shows the matched text in context. |
| `position` | integer | The 1-based rank of this result within its keyword's result set.     |

***

### FAQ

#### How do I search Pastebin for leaked credentials?

Give Pastebin & Paste Site Scraper a keyword — an API key prefix, a company name, a username — and it returns every matching public paste it finds, with the title, URL and snippet already pulled out.

#### Can I search GitHub Gist, Ideone, Paste.org and Textbin at the same time?

Yes. Select any combination of the five supported sites in the `sites` input, or leave it at the default to search all of them in one run.

#### Does this need an account or API key for the paste sites?

No. You give it keywords and a site list, and it returns results — nothing to sign up for on Pastebin, Gist, or any of the other four sites.

#### How much does Pastebin & Paste Site Scraper cost to run?

Billing is per result row saved to your dataset, plus a small per-run start fee. Check the current pricing on this actor's Apify Store page.

#### Can I check multiple keywords in one run?

Yes. Pass as many keywords as you want in the `keywords` array — the actor searches every keyword against every selected site and returns everything it finds, up to `maxItems`.

***

### Need More Features?

Need custom fields, a different site, or filtering options? [File an issue](https://console.apify.com/actors/issues) or get in touch.

### Why Use Pastebin & Paste Site Scraper?

- **Covers five sites, not one** — Pastebin, GitHub Gist, Ideone, Paste.org and Textbin in a single run, instead of running the same search five times by hand.
- **Structured, not screenshots** — returns clean rows with the site, title, URL and snippet already separated out, so you can pipe results straight into a spreadsheet or a ticket instead of copying text out of a browser tab.
- **Batch keywords in one run** — a whole list of terms runs together, which matters when you're sweeping more than one credential pattern.

# Actor input Schema

## `sp_intended_usage` (type: `string`):

What will this data feed? E.g. lead lists, KYB checks, price tracking.

## `sp_improvement_suggestions` (type: `string`):

Provide any feedback or suggestions for improvements.

## `sp_contact` (type: `string`):

We'll personally help with your use case. No spam.

## `keywords` (type: `array`):

Search terms to look for across the selected sites — a leaked API key prefix, a company domain, a username, or any other string you want to check for public exposure. One run searches every keyword against every selected site.

## `sites` (type: `array`):

Which paste / code-sharing sites to restrict the search to.

## `maxItems` (type: `integer`):

Maximum number of results to return across all keywords and sites combined.

## Actor input object example

```json
{
  "sp_intended_usage": "Describe your intended use...",
  "sp_improvement_suggestions": "Share your suggestions here...",
  "sp_contact": "Share your email here...",
  "keywords": [
    "example-leaked-api-key"
  ],
  "sites": [
    "pastebin.com",
    "gist.github.com",
    "ideone.com",
    "paste.org",
    "textbin.net"
  ],
  "maxItems": 15
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "sp_intended_usage": "Describe your intended use...",
    "sp_improvement_suggestions": "Share your suggestions here...",
    "sp_contact": "Share your email here...",
    "keywords": [
        "example-leaked-api-key"
    ],
    "sites": [
        "pastebin.com",
        "gist.github.com",
        "ideone.com",
        "paste.org",
        "textbin.net"
    ],
    "maxItems": 15
};

// Run the Actor and wait for it to finish
const run = await client.actor("jungle_synthesizer/osint-scraper").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "sp_intended_usage": "Describe your intended use...",
    "sp_improvement_suggestions": "Share your suggestions here...",
    "sp_contact": "Share your email here...",
    "keywords": ["example-leaked-api-key"],
    "sites": [
        "pastebin.com",
        "gist.github.com",
        "ideone.com",
        "paste.org",
        "textbin.net",
    ],
    "maxItems": 15,
}

# Run the Actor and wait for it to finish
run = client.actor("jungle_synthesizer/osint-scraper").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "sp_intended_usage": "Describe your intended use...",
  "sp_improvement_suggestions": "Share your suggestions here...",
  "sp_contact": "Share your email here...",
  "keywords": [
    "example-leaked-api-key"
  ],
  "sites": [
    "pastebin.com",
    "gist.github.com",
    "ideone.com",
    "paste.org",
    "textbin.net"
  ],
  "maxItems": 15
}' |
apify call jungle_synthesizer/osint-scraper --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,jungle_synthesizer/osint-scraper"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/usZOL7YsOFfC3Ep2f/builds/Hj7cr6tg3Pn1RGghQ/openapi.json
