# Which Services Use the Login Endpoint Detection Method in Holehe?

> Discover which services use login endpoint detection. Holehe scans for login modules and checks authentication endpoints across 19 platforms like Snapchat, Amazon, and WordPress.

- Repository: [Palenath/holehe](https://github.com/megadose/holehe)
- Tags: deep-dive
- Published: 2026-08-29

---

**Holehe identifies services employing the login endpoint detection method by scanning for modules that declare `method = "login"`, triggering probes that check authentication endpoints for leaked login URLs across 19 platforms including Snapchat, Amazon, and WordPress.**

The open-source OSINT tool **Holehe** (maintained in the `megadose/holehe` repository) maps each supported service to a specific detection strategy to identify account correlations via email addresses. When a module utilizes the **login endpoint detection method**, it instructs the core engine to issue targeted requests to authentication endpoints and analyze HTTP responses for exposed login pathways.

## How the Login Endpoint Detection Method Works

Holehe’s modular architecture relies on a **method** attribute defined in each service module. When a python file contains `method = "login"`, the central engine in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) dispatches a specialized probe workflow rather than generic registration or password-reset checks.

The detection follows a four-step process:

1. **Construct** a request targeting the service’s hard-coded or derived login URL.
2. **Send** the request using Holehe’s async HTTP client defined in [`holehe/instruments.py`](https://github.com/megadose/holehe/blob/main/holehe/instruments.py).
3. **Inspect** the response for indicators of exposed endpoints, such as HTTP 302 redirects to `/login` locations, JSON fields where `type` contains "login", or specific authentication headers.
4. **Report** a positive finding if the response confirms the login endpoint is accessible or leaked.

## Services Using the Login Endpoint Detection Method

The current `master` branch contains 19 modules that declare `method = "login"`. These services span social media, e-commerce, productivity suites, and content management systems.

### Social Media Platforms

- **Snapchat** — [`holehe/modules/social_media/snapchat.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/snapchat.py)
- **Patreon** — [`holehe/modules/social_media/patreon.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/patreon.py)
- **Parler** — [`holehe/modules/social_media/parler.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/parler.py)
- **Bitmoji** — [`holehe/modules/social_media/bitmoji.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/bitmoji.py)

### E-Commerce and Shopping

- **Amazon** — [`holehe/modules/shopping/amazon.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/shopping/amazon.py)
- **eBay** — [`holehe/modules/shopping/ebay.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/shopping/ebay.py)
- **Vivino** — [`holehe/modules/shopping/vivino.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/shopping/vivino.py)

### Productivity and Business Tools

- **Evernote** — [`holehe/modules/productivity/evernote.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/productivity/evernote.py)
- **Any.do** — [`holehe/modules/productivity/anydo.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/productivity/anydo.py)
- **Eventbrite** — [`holehe/modules/products/eventbrite.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/products/eventbrite.py)

### Media and Content Management Systems

- **Flickr** — [`holehe/modules/medias/flickr.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/medias/flickr.py)
- **Komoot** — [`holehe/modules/medias/komoot.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/medias/komoot.py)
- **WordPress CMS** — [`holehe/modules/cms/wordpress.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/cms/wordpress.py)
- **Vox Media CMS** — [`holehe/modules/cms/voxmedia.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/cms/voxmedia.py)
- **Atlassian (ID)** — [`holehe/modules/cms/atlassian.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/cms/atlassian.py)

### Customer Relationship Management (CRM)

- **HubSpot CRM** — [`holehe/modules/crm/hubspot.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/crm/hubspot.py)
- **Axonaut CRM** — [`holehe/modules/crm/axonaut.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/crm/axonaut.py)
- **AmoCRM** — [`holehe/modules/crm/amocrm.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/crm/amocrm.py)

### Email Services

- **Yahoo Mail** — [`holehe/modules/mails/yahoo.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/yahoo.py)

## Technical Implementation and Code Structure

The login endpoint detection logic is orchestrated by **[`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py)**, which imports each module and checks its `method` attribute before executing the appropriate probe. Helper functions for constructing requests and parsing responses reside in **[`holehe/instruments.py`](https://github.com/megadose/holehe/blob/main/holehe/instruments.py)**.

Below is a minimal example demonstrating how the core engine runs the login-endpoint detection for a service like Snapchat:

```python
import asyncio
from holehe.core import Holehe
from holehe.modules.social_media.snapchat import method, url

async def check_snapchat(email):
    scanner = Holehe()
    # The core knows that `method == "login"` → call the module’s login check

    result = await scanner.run_module(email, "snapchat")
    return result

# Example usage

if __name__ == "__main__":
    email = "example@domain.com"
    print(asyncio.run(check_snapchat(email)))

```

When executed with a valid email address, this script triggers the probe defined in [`snapchat.py`](https://github.com/megadose/holehe/blob/main/snapchat.py), which examines the authentication response for login endpoint leaks and returns a dictionary indicating whether the endpoint was discovered.

## Summary

- **19 services** in the `megadose/holehe` repository use the login endpoint detection method by declaring `method = "login"` in their respective modules.
- **Core dispatch logic** resides in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py), which routes requests based on the method attribute.
- **Detection relies** on analyzing HTTP 302 redirects, JSON response tokens, and authentication headers for signs of exposed login URLs.
- **Modular structure** allows each service to define specific endpoints in `holehe/modules/` subdirectories (e.g., `social_media/`, `shopping/`, `crm/`).

## Frequently Asked Questions

### What triggers the login endpoint detection method in Holehe?

The core engine checks the `method` variable in each service module; when set to `"login"`, it triggers the specialized login-endpoint probe instead of registration or recovery checks. This attribute is defined at the module level in files like [`holehe/modules/social_media/snapchat.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/snapchat.py).

### How does Holehe determine if a login endpoint is leaked?

Holehe inspects HTTP responses for specific indicators including 302 redirects pointing to `/login` paths, JSON payloads where fields such as `type` contain the string "login", or distinctive authentication headers that expose the endpoint structure. These checks are implemented within each module’s response parsing logic.

### Can I add a new service using the login endpoint detection method?

Yes, create a new Python file in the appropriate `holehe/modules/` subdirectory (e.g., `social_media/` or `shopping/`) and set `method = "login"` at the module level. Define the target URL and response validation logic following the pattern established in existing modules like [`amazon.py`](https://github.com/megadose/holehe/blob/main/amazon.py) or [`evernote.py`](https://github.com/megadose/holehe/blob/main/evernote.py).

### Is the login endpoint detection method different from other Holehe detection methods?

Yes, unlike methods that probe registration forms or password_reset endpoints, the login-specific approach targets the authentication gateway directly. It searches for scenarios where the service inadvertently exposes the login URL through response metadata, distinguishing it from methods that check for existing account disclosures via registration errors.