Skip to main content
Tools Reference

IRONSCALES Tools

Written By Christopher Scaminaci

Last updated 7 days ago

IRONSCALES Tools

ironscales_ · 100 tools · Free 56 · Pro 44 Email security and security-awareness training for partners: nearly every path is scoped by an integer company id, discovered from the company list. The credential is a long-lived API key exchanged for a scoped token, so a company-scoped key answers 403 on the partner endpoints as normal operation. Authentication failures arrive as HTTP 400 carrying an auth message, not 401. Paging is not uniform - some reads take page with page_size, some page with items_per_page, and some page alone - and the wrong parameter is ignored silently; page size is capped at 100. A few array filters must be repeated rather than comma-joined. Rate limit is 120 calls a minute per company. Launching a campaign sends simulated phishing to real employees, the test-send tools deliver to real mailboxes, incident classification drives automatic remediation, and disabling an integration ends mail protection.

All connector tools · IRONSCALES setup guide

IRONSCALES tool groups

Companies

ToolPlanAccessSummary
ironscales_activate_auto_syncProWriteTurn on directory Auto-Sync for this company, so the protected mailbox list tracks the customer's Microsoft 365 or Google Workspace directory.
ironscales_create_companyProWriteProvision a new company under this partner.
ironscales_delete_911_email_settingsProDestructiveDESTRUCTIVE: remove the company's 911 (emergency report) email configuration.
ironscales_disable_auto_syncProDestructiveDESTRUCTIVE: stop directory Auto-Sync for this company.
ironscales_disable_companyProDestructiveDESTRUCTIVE: deactivate an entire company in IRONSCALES.
ironscales_generate_owa_manifestProWriteGenerate the Outlook on the web (OWA) add-in manifest for this company — the XML/JSON descriptor an administrator uploads to Microsoft 365 to deploy the IRONSCALES report button.
ironscales_get_911_email_settingsFreeRead-onlyGet the company's 911 (emergency report) email configuration — the mailbox employees forward suspicious mail to, and how IRONSCALES handles what arrives there.
ironscales_get_auto_sync_statusFreeRead-onlyGet whether directory Auto-Sync is active for this company, and how it is configured.
ironscales_get_companyFreeRead-onlyGet one company's profile by its numeric id, from ironscales_list_companies.
ironscales_get_company_featuresFreeRead-onlyGet which IRONSCALES product features are switched on for this company, and their access state.
ironscales_get_company_statsFreeRead-onlyGet one company's statistics and licence position — protected mailbox counts against entitlement, and the activity totals IRONSCALES reports for the company.
ironscales_list_auto_sync_groupsFreeRead-onlyList the directory groups available to Auto-Sync for this company — the groups whose members can be brought under protection automatically.
ironscales_list_auto_sync_mailboxesFreeRead-onlyList the mailboxes Auto-Sync has brought into this company from the customer's directory.
ironscales_list_companiesFreeRead-onlyList the companies this partner manages — the ENTRY POINT for this connector.
ironscales_list_companies_v2FreeRead-onlyList the partner's companies using the NEWER V2 endpoint, which adds paging to the same data.
ironscales_update_911_email_settingsProWriteSet the company's 911 (emergency report) email configuration — the mailbox employees forward suspicious messages to, and how IRONSCALES treats what arrives.
ironscales_update_companyProWriteUpdate a company's profile — its name, domains, contact and configuration attributes.
ironscales_update_company_featuresProDestructiveDESTRUCTIVE: change which IRONSCALES features are enabled for a whole company.

[IRONSCALES] Turn on directory Auto-Sync for this company, so the protected mailbox list tracks the customer's Microsoft 365 or Google Workspace directory. Provide the company's numeric id and a JSON object body naming the groups or scope to sync — discover the available groups with ironscales_list_auto_sync_groups. Additive: this brings mailboxes UNDER protection. Note that syncing a large directory can consume licences, so check ironscales_get_company_stats against the entitlement first.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body describing what to sync — typically the directory groups from ironscales_list_auto_sync_groups, plus any scope options the vendor's Auto-Sync schema accepts.

[IRONSCALES] Provision a new company under this partner. Provide a JSON object body with the company's details — at minimum its name and primary email domain; the vendor's create schema also accepts contact and plan fields. Requires a PARTNER-scoped API key. Returns the created company including the numeric id every other tool needs, so keep it. Additive: this creates a tenant and removes nothing, but note that provisioning a company generally has billing consequences with IRONSCALES.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body describing the company to create — name and primary domain at minimum, plus any contact or plan fields the IRONSCALES create schema accepts.

[IRONSCALES] DESTRUCTIVE: remove the company's 911 (emergency report) email configuration. Employees who forward suspicious mail to that address afterwards are no longer creating IRONSCALES reports, so the reporting path goes quiet without any visible error for them. Read ironscales_get_911_email_settings first and keep the values if you may need to restore them — this tool returns no backup.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] DESTRUCTIVE: stop directory Auto-Sync for this company. Mailboxes already protected stay protected, but the list stops tracking the directory — so new starters are never added and leavers are never removed, and coverage drifts silently from that point on with no error to notice. Prefer narrowing the synced groups with ironscales_activate_auto_sync over turning sync off entirely.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] DESTRUCTIVE: deactivate an entire company in IRONSCALES. This is the DELETE verb on the company resource — the vendor calls it 'disable', but it takes the whole tenant out of service, which ends protection for every mailbox in it. Requires a PARTNER-scoped API key. Confirm the numeric id against ironscales_get_company before calling: company ids are small integers and a mistyped one is a valid id for somebody else's tenant.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe numeric id of the company to disable, from ironscales_list_companies. Verify it with ironscales_get_company first — a mistyped id is still a valid id for a different company.

[IRONSCALES] Generate the Outlook on the web (OWA) add-in manifest for this company — the XML/JSON descriptor an administrator uploads to Microsoft 365 to deploy the IRONSCALES report button. Provide the company's numeric id and a JSON object body with any manifest options the vendor accepts. This only PRODUCES the document; nothing is deployed and no mailbox changes until an administrator uploads it.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the manifest generation options the IRONSCALES manifest schema accepts.

[IRONSCALES] Get the company's 911 (emergency report) email configuration — the mailbox employees forward suspicious mail to, and how IRONSCALES handles what arrives there. Returns the current configuration or an empty result when none is set.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get whether directory Auto-Sync is active for this company, and how it is configured. Auto-Sync keeps the protected mailbox list in step with the customer's Microsoft 365 or Google Workspace directory; when it is off, mailbox coverage drifts as staff join and leave. See ironscales_list_auto_sync_groups and ironscales_list_auto_sync_mailboxes for what it is currently pulling in.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get one company's profile by its numeric id, from ironscales_list_companies. Returns the company's own attributes (name, domains, contact and configuration fields) rather than its statistics — for licence consumption and protection counts use ironscales_get_company_stats.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies. This is a number, not a name or GUID.

[IRONSCALES] Get which IRONSCALES product features are switched on for this company, and their access state. Read this before ironscales_update_company_features so you know the current value of every flag — that write replaces feature states, and a flag you cannot see is a flag you can accidentally turn off.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get one company's statistics and licence position — protected mailbox counts against entitlement, and the activity totals IRONSCALES reports for the company. Use this to answer 'how many licences is this customer consuming' without walking the mailbox list. For the licence PLAN itself see ironscales_get_company_license_plan.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] List the directory groups available to Auto-Sync for this company — the groups whose members can be brought under protection automatically. Use the returned group identifiers when configuring Auto-Sync with ironscales_activate_auto_sync. For Google Workspace, gdAdminEmail scopes the lookup to one admin's directory view.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
gdAdminEmailstringnonullGoogle Workspace only: the admin email whose directory view should be used. Omit for Microsoft 365.
pageintegernonullPage number, 1-based. Omit for the first page.
querystringnonullFree-text filter on the group name. Omit for all groups.

[IRONSCALES] List the mailboxes Auto-Sync has brought into this company from the customer's directory. Compare this with ironscales_list_mailboxes to see which protected mailboxes are directory-managed versus added by hand — the ones added by hand are what stop being maintained if staff turnover is handled only in the directory.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
pageintegernonullPage number, 1-based. Omit for the first page.

[IRONSCALES] List the companies this partner manages — the ENTRY POINT for this connector. Each item carries the company's numeric id and name; that id is the companyId argument required by nearly every other IRONSCALES tool. Optionally filter by name or by a domain the company owns. Requires a PARTNER-scoped API key: a company-scoped key is refused with 403, which is expected rather than a fault — such a tenant already knows its one company id and can use the company-scoped tools directly. See also ironscales_list_companies_v2, the newer paginated version of this same listing.

ParamTypeRequiredDefaultDescription
domainstringnonullFilter to the company owning this email domain (e.g. contoso.com). Omit for all.
namestringnonullFilter to companies whose name matches this value. Omit for all.

[IRONSCALES] List the partner's companies using the NEWER V2 endpoint, which adds paging to the same data. Prefer this over ironscales_list_companies when the partner manages many companies; both remain live and IRONSCALES has not retired the original. Requires a PARTNER-scoped API key — a company-scoped key is refused with 403, which is expected.

ParamTypeRequiredDefaultDescription
domainstringnonullFilter to the company owning this email domain (e.g. contoso.com). Omit for all.
namestringnonullFilter to companies whose name matches this value. Omit for all.
pageintegernonullPage number, 1-based. Omit for the first page.

[IRONSCALES] Set the company's 911 (emergency report) email configuration — the mailbox employees forward suspicious messages to, and how IRONSCALES treats what arrives. Provide the company's numeric id and a JSON object body with the settings. Read the current configuration with ironscales_get_911_email_settings first. Reversible: the settings can be changed again; removing the configuration entirely is ironscales_delete_911_email_settings.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the 911 email settings. Read ironscales_get_911_email_settings first to see the current values.

[IRONSCALES] Update a company's profile — its name, domains, contact and configuration attributes. Provide the company's numeric id plus a JSON object body carrying the fields to change. Read the current values with ironscales_get_company first, because the vendor's update semantics replace the fields you send. Reversible: re-applying the previous values restores the earlier state. This does NOT change licensing (see ironscales_update_company_license) or feature access (see ironscales_update_company_features).

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the company fields to change. Read ironscales_get_company first — the fields you send replace their current values.

[IRONSCALES] DESTRUCTIVE: change which IRONSCALES features are enabled for a whole company. This can switch protections OFF for every mailbox at once, which is why it is marked destructive even though the same call can also switch them on. Read ironscales_get_company_features first and send the complete intended state — the vendor documents no request body for this operation, so StackJack sends whatever JSON object you provide and omitting a flag may reset it.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringnonullJSON object body with the complete intended feature state, read from ironscales_get_company_features and edited. Omit entirely to send a bodiless request, which is what the vendor's own spec describes.

Incidents

ToolPlanAccessSummary
ironscales_classify_incidentProDestructiveDESTRUCTIVE: classify an incident.
ironscales_create_account_takeover_remediationProDestructiveDESTRUCTIVE: execute account-takeover remediation for an ATO incident.
ironscales_get_account_takeover_incidentFreeRead-onlyGet the detail of an account-takeover (ATO) incident — the suspicious sign-in activity IRONSCALES observed for a mailbox, with the events behind the verdict.
ironscales_get_incidentFreeRead-onlyGet the full detail of one incident — the reported message, its sender and recipients, IRONSCALES' verdict and confidence, the affected mailboxes, and the remediation state.
ironscales_get_remediation_status_statsFreeRead-onlyGet counts of incidents by remediation outcome over a time window — how much was removed, quarantined or left in place.
ironscales_list_incident_ids_by_statusFreeRead-onlyGet just the incident IDs in one status — the cheapest way to answer 'what is waiting for me', IRONSCALES documents exactly one status value for this call, 'open' (its own operation title calls these…
ironscales_list_incidentsFreeRead-onlyList a company's phishing incidents — the main triage queue.
ironscales_list_scanback_incidentsFreeRead-onlyList incidents raised by a retro-scan (scanback) — mail already delivered that a later verdict re-flagged, rather than mail caught or reported when it arrived.
ironscales_recluster_incidentProWriteRecluster an incident — ask IRONSCALES to re-group the messages it considers part of the same campaign.
ironscales_uncluster_incidentProWriteUncluster an incident — split messages IRONSCALES grouped as one campaign back into separate incidents, so they can be judged individually.

[IRONSCALES] DESTRUCTIVE: classify an incident. This is NOT a passive label — the classification drives IRONSCALES' automatic remediation across the whole mailbox fleet, so marking a cluster malicious removes those messages from every inbox that received them, and marking a real threat safe leaves it in place. Provide the company's numeric id, the incident id and a JSON object body with the classification the vendor's schema expects. Read ironscales_get_incident first so the verdict rests on the evidence.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body carrying the classification, in the shape IRONSCALES' classification schema expects.
incidentIdintegeryesThe incident id to classify, from ironscales_list_incidents.

[IRONSCALES] DESTRUCTIVE: execute account-takeover remediation for an ATO incident. Depending on the actions requested, this can disable a real user account, force a password reset or revoke active sessions — locking a genuine person out of their mailbox if the verdict was wrong. Read ironscales_get_account_takeover_incident first and confirm the sign-in evidence. Provide the company's numeric id, the incident id and a JSON object body naming the remediation actions.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the remediation actions to execute, in the shape IRONSCALES' remediation schema expects.
incidentIdintegeryesThe ATO incident id, from ironscales_list_incidents.

[IRONSCALES] Get the detail of an account-takeover (ATO) incident — the suspicious sign-in activity IRONSCALES observed for a mailbox, with the events behind the verdict. Filter the event list by title, location or source IP (each accepts several comma-separated values). Paging uses page plus itemsPerPage. Read this before ironscales_create_account_takeover_remediation, because remediation can disable or reset the real user account.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
incidentIdintegeryesThe ATO incident id, from ironscales_list_incidents.
ipstringnonullFilter events by source IP — comma-separate several values to match any of them.
itemsPerPageintegernonullEvents per page, capped at 100 by StackJack. This endpoint uses items_per_page, not page_size.
locationstringnonullFilter events by location — comma-separate several values to match any of them.
pageintegernonullPage number, 1-based. Omit for the first page.
titlestringnonullFilter events by title — comma-separate several values to match any of them.

[IRONSCALES] Get the full detail of one incident — the reported message, its sender and recipients, IRONSCALES' verdict and confidence, the affected mailboxes, and the remediation state. Read this before ironscales_classify_incident so the classification is based on the evidence rather than the subject line alone.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
incidentIdintegeryesThe incident id, from ironscales_list_incidents or ironscales_list_incident_ids_by_status.

[IRONSCALES] Get counts of incidents by remediation outcome over a time window — how much was removed, quarantined or left in place. Both startTime and endTime are REQUIRED by IRONSCALES. Set includeScanback true to fold in retro-scan incidents, which otherwise sit outside these totals and make remediation look less active than it was.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
endTimestringyesEnd of the window. REQUIRED by IRONSCALES. ISO-8601.
includeScanbackbooleannonullSet true to include retro-scan (scanback) incidents in the totals. Omit to exclude them, which is the vendor default.
startTimestringyesStart of the window. REQUIRED by IRONSCALES. ISO-8601.

[IRONSCALES] Get just the incident IDs in one status — the cheapest way to answer 'what is waiting for me', IRONSCALES documents exactly one status value for this call, 'open' (its own operation title calls these the unclassified incidents; passing 'unclassified' as the status returns 404). Returns identifiers only, not incident detail; feed them to ironscales_get_incident for the full record. Prefer this over ironscales_list_incidents when you only need a count or a work queue, because it avoids paging through full incident bodies.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
statusstringno"open"The status to filter on, as named by IRONSCALES. 'open' is the only value IRONSCALES documents for this endpoint (the open, not-yet-classified incidents); 'unclassified' is NOT a valid value and returns 404.

[IRONSCALES] List a company's phishing incidents — the main triage queue. Filter by creation or last-update time window, by classification and state (both accept several comma-separated values), by reporting type, and by free-text search across the message subject, sender name/email and recipient name/email. Returns the incident id every other incident tool needs. Paging uses page plus itemsPerPage (StackJack caps itemsPerPage at 100). For incidents raised by a retro-scan rather than by a live report, use ironscales_list_scanback_incidents.

ParamTypeRequiredDefaultDescription
challengedEndDatestringnonullOnly incidents challenged at or before this date.
challengedStartDatestringnonullOnly incidents challenged at or after this date.
challengedTypestringnonullFilter by challenged type, as named by IRONSCALES.
classificationstringnonullFilter by classification — comma-separate several values to match any of them (e.g. 'phishing,spam').
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
createdEndTimestringnonullOnly incidents created at or before this time. ISO-8601.
createdStartTimestringnonullOnly incidents created at or after this time. ISO-8601.
incidentIdintegernonullReturn only this specific incident id. Usually easier to use ironscales_get_incident.
itemsPerPageintegernonullResults per page, capped at 100 by StackJack (IRONSCALES declares no maximum). Note this parameter is items_per_page on this endpoint, not page_size.
lastUpdateEndTimestringnonullOnly incidents last updated at or before this time. ISO-8601.
lastUpdateStartTimestringnonullOnly incidents last updated at or after this time. ISO-8601.
orderstringnonullSort direction, typically asc or desc.
pageintegernonullPage number, 1-based. Omit for the first page.
periodintegernonullRelative period in days, as an alternative to explicit start/end times.
reportTypestringnonullFilter by report type, as named by IRONSCALES.
searchEmailSubjectstringnonullFree-text search across the reported message's subject.
searchRecipientEmailstringnonullFree-text search across the recipient's email address.
searchRecipientNamestringnonullFree-text search across the recipient's display name.
searchSenderEmailstringnonullFree-text search across the sender's email address.
searchSenderNamestringnonullFree-text search across the sender's display name.
sortstringnonullField to sort by, as named by IRONSCALES (e.g. a creation-time or severity field).
statestringnonullFilter by incident state — comma-separate several values to match any of them.

[IRONSCALES] List incidents raised by a retro-scan (scanback) — mail already delivered that a later verdict re-flagged, rather than mail caught or reported when it arrived. These matter because the message has already been sitting in users' inboxes. Same filters as ironscales_list_incidents, minus the report-type and last-update filters. Paging uses page plus itemsPerPage (capped at 100 by StackJack).

ParamTypeRequiredDefaultDescription
challengedEndDatestringnonullOnly incidents challenged at or before this date.
challengedStartDatestringnonullOnly incidents challenged at or after this date.
challengedTypestringnonullFilter by challenged type, as named by IRONSCALES.
classificationstringnonullFilter by classification — comma-separate several values to match any of them.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
createdEndTimestringnonullOnly incidents created at or before this time. ISO-8601.
createdStartTimestringnonullOnly incidents created at or after this time. ISO-8601.
incidentIdintegernonullReturn only this specific incident id.
itemsPerPageintegernonullResults per page, capped at 100 by StackJack. This endpoint uses items_per_page, not page_size.
orderstringnonullSort direction, typically asc or desc.
pageintegernonullPage number, 1-based. Omit for the first page.
searchEmailSubjectstringnonullFree-text search across the reported message's subject.
searchRecipientEmailstringnonullFree-text search across the recipient's email address.
searchRecipientNamestringnonullFree-text search across the recipient's display name.
searchSenderEmailstringnonullFree-text search across the sender's email address.
searchSenderNamestringnonullFree-text search across the sender's display name.
sortstringnonullField to sort by, as named by IRONSCALES.
statestringnonullFilter by incident state — comma-separate several values to match any of them.

[IRONSCALES] Recluster an incident — ask IRONSCALES to re-group the messages it considers part of the same campaign. This changes how the incident is presented and remediated as a unit; it does not itself remove or release any mail. Reversible: ironscales_uncluster_incident splits a cluster back apart.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the reclustering options the vendor's schema expects.
incidentIdintegeryesThe incident id to recluster, from ironscales_list_incidents.

[IRONSCALES] Uncluster an incident — split messages IRONSCALES grouped as one campaign back into separate incidents, so they can be judged individually. Useful when a cluster has swept up legitimate mail alongside a real threat. This does not remove or release any mail on its own; the classification does that. Reversible with ironscales_recluster_incident.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the unclustering options the vendor's schema expects.
incidentIdintegeryesThe incident id to uncluster, from ironscales_list_incidents.

Mitigation

ToolPlanAccessSummary
ironscales_get_company_mitigation_detailsFreeRead-onlyGet company-wide mitigation detail — the incidents IRONSCALES acted on and what it did, rolled up for the company rather than per mailbox.
ironscales_get_email_statsFreeRead-onlyGet email volume and verdict statistics for a company over a time window — how much mail was scanned and how it was judged.
ironscales_get_latest_impersonation_incidentsFreeRead-onlyGet the company's most recent impersonation incidents — mail where the sender was posing as a colleague, executive or trusted brand.
ironscales_get_mailbox_mitigation_detailsFreeRead-onlyReport what IRONSCALES mitigated per mailbox for one company — which mailboxes received flagged mail and what happened to it.
ironscales_get_mitigation_statsFreeRead-onlyGet the company's mitigation statistics for a period — the headline counts of what IRONSCALES caught and removed.
ironscales_get_mitigation_stats_v2FreeRead-onlyGet the company's mitigation statistics using the NEWER V2 report.
ironscales_get_most_targeted_departmentsFreeRead-onlyRank the company's departments by how much malicious mail was aimed at them over a time window — useful for deciding where to point training.
ironscales_get_most_targeted_employeesFreeRead-onlyRank the company's individual employees by how much malicious mail was aimed at them over a time window — the people worth prioritising for training or tighter controls.
ironscales_search_impersonation_incidentsFreeRead-onlySearch the company's impersonation incidents with filtering and paging.

[IRONSCALES] Get company-wide mitigation detail — the incidents IRONSCALES acted on and what it did, rolled up for the company rather than per mailbox. Use the period argument for a relative window. For the per-mailbox breakdown use ironscales_get_mailbox_mitigation_details.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
pageintegernonullPage number, 1-based. Omit for the first page.
periodstringnonullRelative reporting period, as accepted by IRONSCALES (typically a number of days).

[IRONSCALES] Get email volume and verdict statistics for a company over a time window — how much mail was scanned and how it was judged. Both startTime and endTime are REQUIRED. Set includeScanback true to fold in retro-scan results, which otherwise sit outside these totals.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
endTimestringyesEnd of the window. REQUIRED by IRONSCALES. ISO-8601.
includeScanbackbooleannonullSet true to include retro-scan (scanback) results in the totals. Omit to exclude them, which is the vendor default.
startTimestringyesStart of the window. REQUIRED by IRONSCALES. ISO-8601.

[IRONSCALES] Get the company's most recent impersonation incidents — mail where the sender was posing as a colleague, executive or trusted brand. The period argument is REQUIRED and sets how far back to look. This returns the latest set only; for a paged, filtered search use ironscales_search_impersonation_incidents.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
periodintegeryesHow far back to look, in the period units IRONSCALES uses (typically days). REQUIRED.

[IRONSCALES] Report what IRONSCALES mitigated per mailbox for one company — which mailboxes received flagged mail and what happened to it. This is a READ even though it uses POST: the filter and paging criteria travel in the request body, and nothing is changed. Provide a JSON object body with the criteria the vendor's mitigation-details schema accepts (typically a time window plus paging).

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body carrying the filter and paging criteria — typically a time window and page settings, in the shape IRONSCALES' mitigation-details schema expects.

[IRONSCALES] Get the company's mitigation statistics for a period — the headline counts of what IRONSCALES caught and removed. The period argument is REQUIRED. See also ironscales_get_mitigation_stats_v2, the newer version of this same report; both are live and return different shapes, so pick one and stay with it within a report.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
periodintegeryesReporting period, in the units IRONSCALES uses (typically days). REQUIRED.

[IRONSCALES] Get the company's mitigation statistics using the NEWER V2 report. Prefer this for new work; ironscales_get_mitigation_stats remains live for anything already built against it, and IRONSCALES has not retired it. The period argument is REQUIRED.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
periodintegeryesReporting period, in the units IRONSCALES uses (typically days). REQUIRED.

[IRONSCALES] Rank the company's departments by how much malicious mail was aimed at them over a time window — useful for deciding where to point training. Both startTime and endTime are REQUIRED. Departments come from the mailbox records, so this is only as good as the department field on ironscales_list_mailboxes.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
endTimestringyesEnd of the window. REQUIRED by IRONSCALES. ISO-8601.
includeScanbackbooleannonullSet true to include retro-scan (scanback) results in the totals. Omit to exclude them.
startTimestringyesStart of the window. REQUIRED by IRONSCALES. ISO-8601.

[IRONSCALES] Rank the company's individual employees by how much malicious mail was aimed at them over a time window — the people worth prioritising for training or tighter controls. Both startTime and endTime are REQUIRED. Pair with ironscales_get_user_campaign_performance to see whether the most-targeted people are also the ones failing simulations.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
endTimestringyesEnd of the window. REQUIRED by IRONSCALES. ISO-8601.
includeScanbackbooleannonullSet true to include retro-scan (scanback) results in the totals. Omit to exclude them.
startTimestringyesStart of the window. REQUIRED by IRONSCALES. ISO-8601.

[IRONSCALES] Search the company's impersonation incidents with filtering and paging. This is a READ even though it uses POST — the criteria travel in the request body and nothing is changed. Prefer this over ironscales_get_latest_impersonation_incidents when you need more than the most recent set or want to filter. Provide a JSON object body with the criteria the vendor's impersonation-details schema accepts.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body carrying the filter and paging criteria, in the shape IRONSCALES' impersonation-details schema expects.

Security Awareness Training

ToolPlanAccessSummary
ironscales_approve_sat_campaignProDestructiveDESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE.
ironscales_calculate_sat_participantsFreeRead-onlyWork out how many people a given audience filter would reach, without enrolling or sending anything.
ironscales_create_sat_campaignProWriteCreate a security-awareness campaign as a DRAFT.
ironscales_delete_sat_campaignProDestructiveDESTRUCTIVE: delete a SAT campaign.
ironscales_get_sat_campaignFreeRead-onlyGet one SAT campaign's full definition — its templates, trainings, schedule, audience and current status.
ironscales_get_sat_campaign_setupFreeRead-onlyGet the campaign setup options for this company — the choices available when building a campaign (flows, schedules, locales and the like).
ironscales_get_sat_campaign_statsFreeRead-onlyGet one SAT campaign's results — delivery, open, click and report rates, and training completion.
ironscales_get_sat_training_previewFreeRead-onlyGet a preview URL for one training module in a given language, so a human can review the content before it is assigned to staff.
ironscales_list_sat_campaignsFreeRead-onlyList the company's security-awareness campaigns with their full detail — status, schedule, flow type and locale.
ironscales_list_sat_cta_pagesFreeRead-onlyList the call-for-action pages available to this company — the follow-up pages shown after an employee interacts with a simulation, typically the teaching moment.
ironscales_list_sat_landing_pagesFreeRead-onlyList the landing pages available to this company — the pages a simulated phishing link takes an employee to when they click.
ironscales_list_sat_participantsFreeRead-onlyList the company's training participants grouped by category — who is eligible to receive campaigns, organised the way IRONSCALES groups them.
ironscales_list_sat_template_categoriesFreeRead-onlyList the template categories available to this company.
ironscales_list_sat_templatesFreeRead-onlyList the phishing-simulation and training templates available to this company.
ironscales_list_sat_training_providersFreeRead-onlyList the training providers available to this company.
ironscales_list_sat_trainingsFreeRead-onlyList the training modules available from one provider.
ironscales_lookup_sat_campaignsFreeRead-onlyGet a lightweight id-and-name list of the company's SAT campaigns — the cheap way to resolve a campaign name to the id the other tools need, without pulling full campaign records.
ironscales_search_sat_participantsFreeRead-onlySearch the company's training participants.
ironscales_send_sat_campaign_simulation_testProDestructiveDESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE.
ironscales_send_sat_campaign_training_testProDestructiveDESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE.
ironscales_send_sat_template_testProDestructiveDESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE.
ironscales_stop_sat_campaignProWriteStop an active SAT campaign, halting any sends that have not gone out yet.

[IRONSCALES] DESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE. The vendor calls this 'approve a draft campaign', but approving LAUNCHES it: simulated phishing or training messages go out to the company's employees on the campaign's schedule, and there is no unsend. Before calling, read ironscales_get_sat_campaign to confirm what will be sent and ironscales_calculate_sat_participants to confirm who will receive it. The vendor spec declares no request body for this operation.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe id of the DRAFT campaign to launch, from ironscales_list_sat_campaigns. Verify it with ironscales_get_sat_campaign first — this cannot be undone once mail is sent.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringnonullOptional JSON object body. The vendor spec declares none, so omit this unless you know the undocumented shape.

[IRONSCALES] Work out how many people a given audience filter would reach, without enrolling or sending anything. This is a READ despite using POST — the filter criteria travel in the request body. Run this before approving a campaign to confirm the blast radius: it is the difference between simulating on twelve people and on the whole company. Provide a JSON object body with the audience filters the vendor's participants schema accepts.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the audience filter criteria, in the shape IRONSCALES' participants schema expects.

[IRONSCALES] Create a security-awareness campaign as a DRAFT. Nothing is sent by this call — no employee receives anything until the campaign is approved, which is a separate tool. Provide a JSON object body defining the campaign: its templates (ironscales_list_sat_templates), trainings (ironscales_list_sat_trainings), landing and call-for-action pages, schedule and audience. Read ironscales_get_sat_campaign_setup first for the options this company can use, and ironscales_calculate_sat_participants to check how many people the audience filter would reach. Returns the new campaign including its id.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body defining the campaign — templates, trainings, pages, schedule and audience, in the shape IRONSCALES' campaign schema expects.

[IRONSCALES] DESTRUCTIVE: delete a SAT campaign. If the campaign has already run, deleting it also takes away the results — so read ironscales_get_sat_campaign_stats first if the outcome matters for reporting or compliance evidence. Stopping a running campaign without losing its history is ironscales_stop_sat_campaign instead.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe id of the campaign to delete, from ironscales_list_sat_campaigns.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get one SAT campaign's full definition — its templates, trainings, schedule, audience and current status. Read this before approving a campaign, because approval LAUNCHES it to real employees and there is no unsend.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe campaign id, from ironscales_list_sat_campaigns or ironscales_lookup_sat_campaigns.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get the campaign setup options for this company — the choices available when building a campaign (flows, schedules, locales and the like). Read this before ironscales_create_sat_campaign so the draft is composed from values the company can actually use.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get one SAT campaign's results — delivery, open, click and report rates, and training completion. This is how you tell whether a simulation worked. For results broken down per person across campaigns, use ironscales_get_user_campaign_performance.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe campaign id, from ironscales_list_sat_campaigns.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get a preview URL for one training module in a given language, so a human can review the content before it is assigned to staff. The localeId argument is REQUIRED. This returns a link only; nothing is assigned or sent.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
localeIdintegeryesThe locale id to preview in. REQUIRED.
trainingIdintegeryesThe training module id, from ironscales_list_sat_trainings.

[IRONSCALES] List the company's security-awareness campaigns with their full detail — status, schedule, flow type and locale. Filter by status, flow type, locale or scheduled date/time range, and search by name. Returns the campaign id the other SAT campaign tools need. Paging uses page plus pageSize (StackJack caps pageSize at 100). For just ids and names use the cheaper ironscales_lookup_sat_campaigns.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
flowTypesstringnonullFilter by flow type — comma-separate several values to match any of them.
localeIdsstringnonullFilter by locale id — comma-separate several values.
pageintegernonullPage number, 1-based. Omit for the first page.
pageSizeintegernonullResults per page, capped at 100 by StackJack. This family uses page_size, not items_per_page.
scheduledDateFromstringnonullOnly campaigns scheduled on or after this date.
scheduledDateTostringnonullOnly campaigns scheduled on or before this date.
scheduledTimeFromstringnonullOnly campaigns scheduled at or after this time of day.
scheduledTimeTostringnonullOnly campaigns scheduled at or before this time of day.
searchstringnonullFree-text search across campaign names.
statusesstringnonullFilter by campaign status — comma-separate several values.

[IRONSCALES] List the call-for-action pages available to this company — the follow-up pages shown after an employee interacts with a simulation, typically the teaching moment. Search by name; paging uses page plus pageSize.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
pageintegernonullPage number, 1-based. Omit for the first page.
pageSizeintegernonullResults per page, capped at 100 by StackJack.
searchstringnonullFree-text search across page names.

[IRONSCALES] List the landing pages available to this company — the pages a simulated phishing link takes an employee to when they click. Filter by locale or author, and search by name. Paging uses page plus pageSize.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
createdBystringnonullFilter by author — comma-separate several values.
localeIdsstringnonullFilter by locale id — comma-separate several values.
pageintegernonullPage number, 1-based. Omit for the first page.
pageSizeintegernonullResults per page, capped at 100 by StackJack.
searchstringnonullFree-text search across landing-page names.

[IRONSCALES] List the company's training participants grouped by category — who is eligible to receive campaigns, organised the way IRONSCALES groups them. Use ironscales_calculate_sat_participants to find out how many people a specific filter set would actually reach before launching anything.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] List the template categories available to this company. The returned category ids are the categoryIds filter on ironscales_list_sat_templates — call this first when you want to find, say, every credential-harvesting template.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] List the phishing-simulation and training templates available to this company. Filter by category, locale, type, difficulty level or author, and search by name. The returned template id is what ironscales_send_sat_template_test takes, and what campaign definitions reference. Paging uses page plus pageSize.

ParamTypeRequiredDefaultDescription
categoryIdsstringnonullFilter by category id, from ironscales_list_sat_template_categories — comma-separate several values.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
createdBystringnonullFilter by author — comma-separate several values.
levelstringnonullFilter by difficulty level — comma-separate several values.
localeIdsstringnonullFilter by locale id — comma-separate several values.
orderstringnonullSort direction, typically asc or desc.
pageintegernonullPage number, 1-based. Omit for the first page.
pageSizeintegernonullResults per page, capped at 100 by StackJack.
searchstringnonullFree-text search across template names.
sortstringnonullField to sort by, as named by IRONSCALES.
typestringnonullFilter by template type — comma-separate several values.

[IRONSCALES] List the training providers available to this company. The returned provider id is the REQUIRED vendor argument on ironscales_list_sat_trainings, so call this first when browsing training content.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] List the training modules available from one provider. The vendor argument is REQUIRED and identifies the training provider — get the valid values from ironscales_list_sat_training_providers first. Filter by locale. Paging uses page plus pageSize.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
localeIdsstringnonullFilter by locale id — comma-separate several values.
pageintegernonullPage number, 1-based. Omit for the first page.
pageSizeintegernonullResults per page, capped at 100 by StackJack.
vendorintegeryesThe training provider's numeric id. REQUIRED — get it from ironscales_list_sat_training_providers.

[IRONSCALES] Get a lightweight id-and-name list of the company's SAT campaigns — the cheap way to resolve a campaign name to the id the other tools need, without pulling full campaign records. Accepts the same filters as ironscales_list_sat_campaigns. Prefer this when you only need to find a campaign.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
flowTypesstringnonullFilter by flow type — comma-separate several values.
localeIdsstringnonullFilter by locale id — comma-separate several values.
pageintegernonullPage number, 1-based. Omit for the first page.
pageSizeintegernonullResults per page, capped at 100 by StackJack.
scheduledDateFromstringnonullOnly campaigns scheduled on or after this date.
scheduledDateTostringnonullOnly campaigns scheduled on or before this date.
scheduledTimeFromstringnonullOnly campaigns scheduled at or after this time of day.
scheduledTimeTostringnonullOnly campaigns scheduled at or before this time of day.
searchstringnonullFree-text search across campaign names.
statusesstringnonullFilter by campaign status — comma-separate several values.

[IRONSCALES] Search the company's training participants. This is a READ despite using POST — the search criteria travel in the request body and nothing is changed. Provide a JSON object body with the search criteria the vendor's participant-search schema accepts.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the participant search criteria, in the shape IRONSCALES' participant-search schema expects.

[IRONSCALES] DESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE. Sends this campaign's phishing simulation to up to ten company mailboxes. In IRONSCALES a 'test send' is a small LIVE send, not a rehearsal: the named recipients receive an actual simulated phishing message and it cannot be unsent. Provide a JSON object body naming the recipients, which must be real mailboxes in the company. Use this to check rendering with willing colleagues before ironscales_approve_sat_campaign goes to everyone.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe campaign id, from ironscales_list_sat_campaigns.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the recipients (maximum ten) who will receive the live simulation, in the shape IRONSCALES' test-send schema expects. These are real mailboxes and they will receive real mail.

[IRONSCALES] DESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE. Sends this campaign's TRAINING message to up to ten company mailboxes. As with the simulation test, 'test' here means a small live send rather than a rehearsal, and the named recipients are assigned the training for real. Provide a JSON object body naming the recipients.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe campaign id, from ironscales_list_sat_campaigns.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the recipients (maximum ten) who will receive the live training message, in the shape IRONSCALES' test-send schema expects.

[IRONSCALES] DESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE. Sends one template to up to ten real recipients so a human can see how it renders. This needs no campaign, which makes it the quickest way to put a simulated phishing message in somebody's inbox — treat it accordingly. Provide the template id from ironscales_list_sat_templates and a JSON object body naming the recipients. To preview training content WITHOUT sending anything, use ironscales_get_sat_training_preview instead.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the recipients (maximum ten) who will receive the live message, in the shape IRONSCALES' test-send schema expects.
templateIdintegeryesThe template id to send, from ironscales_list_sat_templates.

[IRONSCALES] Stop an active SAT campaign, halting any sends that have not gone out yet. This is strictly risk-reducing — it means less mail reaches employees, never more — which is why it is not marked destructive. Messages already delivered stay delivered; use this when a simulation is landing badly or was aimed at the wrong audience. The vendor spec declares no request body.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe id of the active campaign to stop, from ironscales_list_sat_campaigns.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringnonullOptional JSON object body. The vendor spec declares none, so omit this unless you know the undocumented shape.

Phishing Campaigns

ToolPlanAccessSummary
ironscales_get_campaign_detailsFreeRead-onlyGet the company's phishing-simulation campaigns and their delivery detail over a period.
ironscales_get_campaign_participantsFreeRead-onlyGet the per-participant detail for one phishing-simulation campaign — who received it and what each person did (opened, clicked, reported, or nothing).
ironscales_perform_campaign_participant_actionProDestructiveDESTRUCTIVE — REACHES REAL PEOPLE.

[IRONSCALES] Get the company's phishing-simulation campaigns and their delivery detail over a period. The period argument is REQUIRED. Filter by status (comma-separate several values) or by campaign name. Note this is the /campaigns/ family, which reports on simulation delivery — the security-awareness campaign definitions live under ironscales_list_sat_campaigns.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
namestringnonullFilter by campaign name.
pageintegernonullPage number, 1-based. Omit for the first page.
periodintegeryesReporting period, in the units IRONSCALES uses (typically days). REQUIRED.
statusstringnonullFilter by campaign status — comma-separate several values to match any of them.

[IRONSCALES] Get the per-participant detail for one phishing-simulation campaign — who received it and what each person did (opened, clicked, reported, or nothing). This is the evidence behind the campaign's headline numbers, and the list you would use to decide who needs follow-up training.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe campaign id, from ironscales_get_campaign_details. REQUIRED by IRONSCALES.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
pageintegernonullPage number, 1-based. Omit for the first page.

[IRONSCALES] DESTRUCTIVE — REACHES REAL PEOPLE. Perform an action on named participants in a phishing-simulation campaign, typically enrolling them in follow-up training or notifying them about their result. The effect lands on identified employees rather than on data, and depending on the action they may receive email. Read ironscales_get_campaign_participants first to confirm exactly who is in scope. Provide a JSON object body naming the participants and the action.

ParamTypeRequiredDefaultDescription
campaignIdintegeryesThe campaign id, from ironscales_get_campaign_details. REQUIRED by IRONSCALES.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the participants and the action to perform, in the shape IRONSCALES' participants-action schema expects. These are real people.

Settings

ToolPlanAccessSummary
ironscales_append_challenged_alert_settingsProWriteAppend to the company's challenged-alert notification settings — add recipients or options without disturbing the existing configuration.
ironscales_append_incident_alert_settingsProWriteAppend to the company's incident notification settings — add recipients or options without disturbing what is already configured.
ironscales_create_allow_list_entryProWriteAdd entries to the company's allow-list, telling IRONSCALES to treat those senders, domains or addresses as safe.
ironscales_create_challenged_alert_settingsProWriteCreate the company's challenged-alert notification settings — establish who is told when IRONSCALES challenges a message.
ironscales_create_incident_alert_settingsProWriteCreate the company's incident notification settings — establish who is alerted when IRONSCALES raises an incident.
ironscales_delete_allow_list_entriesProDestructiveDESTRUCTIVE: remove entries from the company's allow-list.
ironscales_delete_challenged_alert_settingsProDestructiveDESTRUCTIVE: remove the company's challenged-alert notification settings.
ironscales_delete_incident_alert_settingsProDestructiveDESTRUCTIVE: remove the company's incident notification settings.
ironscales_get_account_takeover_settingsFreeRead-onlyGet the company's account-takeover (ATO) detection sensitivity — how aggressively IRONSCALES flags suspicious sign-in behaviour.
ironscales_get_challenged_alert_settingsFreeRead-onlyGet the company's challenged-alert notification settings — who is told when IRONSCALES challenges a message and how.
ironscales_get_incident_alert_settingsFreeRead-onlyGet the company's incident notification settings — who is told when IRONSCALES raises an incident, and how.
ironscales_list_allow_list_entriesFreeRead-onlyList the company's allow-list entries — the senders, domains and addresses IRONSCALES is told to treat as safe.
ironscales_update_account_takeover_settingsProWriteSet the company's account-takeover detection sensitivity.
ironscales_update_allow_list_entryProWriteUpdate an existing allow-list entry.

[IRONSCALES] Append to the company's challenged-alert notification settings — add recipients or options without disturbing the existing configuration. Safe by construction: it cannot drop recipients that are already there. Provide a JSON object body with what to add.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the recipients or options to add, in the shape IRONSCALES' alert-settings schema expects.

[IRONSCALES] Append to the company's incident notification settings — add recipients or options without disturbing what is already configured. This is the safe way to add someone to an alert list, because it cannot silently drop the existing recipients the way a full replacement could. Provide a JSON object body with what to add.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the recipients or options to add, in the shape IRONSCALES' alert-settings schema expects.

[IRONSCALES] Add entries to the company's allow-list, telling IRONSCALES to treat those senders, domains or addresses as safe. Additive — existing entries are untouched — but understand what it means: each entry is a deliberate gap in protection, and allow-listing a whole domain is much broader than allow-listing one sender. Provide a JSON object body with the entries in the shape IRONSCALES' allow-list schema expects.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the allow-list entries to add, in the shape IRONSCALES' allow-list schema expects.

[IRONSCALES] Create the company's challenged-alert notification settings — establish who is told when IRONSCALES challenges a message. Additive: this turns that alerting on. To add recipients to existing settings use ironscales_append_challenged_alert_settings instead. Provide a JSON object body with the recipients and options.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the notification recipients and options, in the shape IRONSCALES' alert-settings schema expects.

[IRONSCALES] Create the company's incident notification settings — establish who is alerted when IRONSCALES raises an incident. Additive: this turns alerting ON. To add recipients to settings that already exist without disturbing the current ones, use ironscales_append_incident_alert_settings instead. Provide a JSON object body with the recipients and options.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the notification recipients and options, in the shape IRONSCALES' alert-settings schema expects.

[IRONSCALES] DESTRUCTIVE: remove entries from the company's allow-list. Mail from those senders is subject to full inspection again, which is usually the safer state — but if the entry existed to stop a business-critical sender being quarantined, removing it can start blocking mail the customer depends on. Read ironscales_list_allow_list_entries first and keep a note of what you remove. Provide a JSON object body naming the entries to delete.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the allow-list entries to remove, in the shape IRONSCALES' allow-list schema expects.

[IRONSCALES] DESTRUCTIVE: remove the company's challenged-alert notification settings. Challenging still happens, but nobody is notified about it — another failure that presents as silence rather than an error. Read ironscales_get_challenged_alert_settings first and keep the recipients if you may need to restore them. The vendor spec declares no request body.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringnonullOptional JSON object body. The vendor spec declares none, so omit this unless you know the undocumented shape.

[IRONSCALES] DESTRUCTIVE: remove the company's incident notification settings. Detection keeps working, but nobody is told when an incident is raised — and an alerting path that has gone quiet looks exactly like a quiet week, so this failure is unusually hard to notice. Read ironscales_get_incident_alert_settings first and keep the recipients if you may need to restore them. The vendor spec declares no request body.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringnonullOptional JSON object body. The vendor spec declares none, so omit this unless you know the undocumented shape.

[IRONSCALES] Get the company's account-takeover (ATO) detection sensitivity — how aggressively IRONSCALES flags suspicious sign-in behaviour. Read this when tuning false positives, and pair it with the ATO incidents from ironscales_list_incidents to judge whether the current setting is right for the customer.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get the company's challenged-alert notification settings — who is told when IRONSCALES challenges a message and how. These are separate from incident alerts (ironscales_get_incident_alert_settings); a company can have one configured and not the other.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get the company's incident notification settings — who is told when IRONSCALES raises an incident, and how. Read this before changing alerting so you know who is currently on the list; a company whose only alert recipient has left is a common and silent failure.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] List the company's allow-list entries — the senders, domains and addresses IRONSCALES is told to treat as safe. Worth auditing: every entry here is a deliberate hole in the company's protection, and stale entries are a common way a real phish gets through. Filter by entry type and search text; paging uses page plus itemsPerPage (capped at 100 by StackJack).

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
itemsPerPageintegernonullResults per page, capped at 100 by StackJack. This endpoint uses items_per_page, not page_size.
orderstringnonullSort direction, typically asc or desc.
pageintegernonullPage number, 1-based. Omit for the first page.
searchstringnonullFree-text search across the entries.
sortstringnonullField to sort by, as named by IRONSCALES.
typestringnonullFilter by entry type, as named by IRONSCALES (e.g. sender or domain).

[IRONSCALES] Set the company's account-takeover detection sensitivity. Reversible — it is a dial, and the previous value can simply be set again — but be aware of the direction of risk: loosening it means fewer false positives and fewer genuine takeovers caught. Read ironscales_get_account_takeover_settings first. Provide a JSON object body with the sensitivity settings.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body with the ATO sensitivity settings, in the shape IRONSCALES' account-takeover settings schema expects.

[IRONSCALES] Update an existing allow-list entry. Read ironscales_list_allow_list_entries first to identify the entry and see its current value — this replaces the fields you send. Reversible: re-applying the previous values restores it. To remove entries entirely use ironscales_delete_allow_list_entries.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body identifying the entry and carrying the values to change, in the shape IRONSCALES' allow-list schema expects.

Mailboxes

ToolPlanAccessSummary
ironscales_add_mailboxesProWriteAdd mailboxes to a company so IRONSCALES protects them.
ironscales_bulk_edit_mailboxesProDestructiveDESTRUCTIVE: change many mailboxes in one call.
ironscales_get_mailbox_compliance_reportFreeRead-onlyGet the company's training compliance report — who has completed their assigned security-awareness training and who has not, over a period.
ironscales_get_user_campaign_performanceFreeRead-onlyGet per-user phishing-simulation performance across campaigns — how each person has been doing over time, rather than the result of a single campaign.
ironscales_list_mailboxesFreeRead-onlyList a company's mailboxes with rich filtering — by enabled and protected state, tags, awareness level, department, title, language, name or email, or by explicit id sets.

[IRONSCALES] Add mailboxes to a company so IRONSCALES protects them. Additive — nothing existing is changed — but each mailbox consumes licence entitlement, so check ironscales_get_company_stats against the plan before adding in bulk. For companies using directory Auto-Sync, prefer widening the synced groups (ironscales_activate_auto_sync) so the list stays maintained on its own. Provide a JSON object body with the mailboxes to add.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the mailboxes to add, in the shape IRONSCALES' mailbox schema expects.

[IRONSCALES] DESTRUCTIVE: change many mailboxes in one call. The danger is scale rather than the edit itself — a selector that matches more mailboxes than intended applies the change to all of them, and among the properties this can set is whether a mailbox is protected, so a mistake here silently drops coverage across a company. Run the same filters through ironscales_list_mailboxes first and confirm the returned set is exactly what you mean to change. Provide a JSON object body with the selection and the changes.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body identifying the mailboxes and the changes to apply, in the shape IRONSCALES' bulk-edit schema expects. Verify the selection with ironscales_list_mailboxes first.

[IRONSCALES] Get the company's training compliance report — who has completed their assigned security-awareness training and who has not, over a period. Use period for a relative window, or customPeriodFrom and customPeriodTo for an explicit one. This is the report most often needed for a customer's compliance evidence.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
customPeriodFromstringnonullStart of an explicit reporting range. Omit if using period.
customPeriodTostringnonullEnd of an explicit reporting range. Omit if using period.
pageintegernonullPage number, 1-based. Omit for the first page.
periodintegernonullRelative reporting period, in the units IRONSCALES uses (typically days). Omit if using an explicit range.

[IRONSCALES] Get per-user phishing-simulation performance across campaigns — how each person has been doing over time, rather than the result of a single campaign. Filter by country, department or campaign type (comma-separate several campaign types). Pair with ironscales_get_most_targeted_employees to find the people who are both heavily targeted and struggling, who are the ones worth acting on first.

ParamTypeRequiredDefaultDescription
campaignTypestringnonullFilter by campaign type — comma-separate several values to match any of them.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
countrystringnonullFilter by country.
customPeriodFromstringnonullStart of an explicit reporting range. Omit if using period.
customPeriodTostringnonullEnd of an explicit reporting range. Omit if using period.
departmentstringnonullFilter by department.
pageintegernonullPage number, 1-based. Omit for the first page.
periodintegernonullRelative reporting period, in the units IRONSCALES uses (typically days). Omit if using an explicit range.

[IRONSCALES] List a company's mailboxes with rich filtering — by enabled and protected state, tags, awareness level, department, title, language, name or email, or by explicit id sets. This is the authoritative view of what IRONSCALES is actually protecting, and comparing isProtected against the licence position from ironscales_get_company_stats is how you spot coverage gaps. Paging uses page plus itemsPerPage (capped at 100 by StackJack); note this endpoint uses items_per_page, not page_size.

ParamTypeRequiredDefaultDescription
awarenessstringnonullFilter by security-awareness level — comma-separate several values.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
departmentstringnonullFilter by department. This is the same field the most-targeted-departments report groups on.
emailstringnonullFilter by email address.
excludeIdsstringnonullExclude these mailbox ids — comma-separate several values.
firstNamestringnonullFilter by first name.
idsstringnonullRestrict to these mailbox ids — comma-separate several values.
isEnabledbooleannonullFilter by whether the mailbox is enabled.
isProtectedbooleannonullFilter by whether the mailbox is protected. The key coverage question.
itemsPerPageintegernonullResults per page, capped at 100 by StackJack. This endpoint uses items_per_page, not page_size.
languagestringnonullFilter by language.
lastNamestringnonullFilter by last name.
orderstringnonullSort direction, typically asc or desc.
pageintegernonullPage number, 1-based. Omit for the first page.
searchstringnonullFree-text search across the mailboxes.
sortstringnonullField to sort by, as named by IRONSCALES.
tagsstringnonullFilter by tag — comma-separate several values.
titlestringnonullFilter by job title.

Licensing

ToolPlanAccessSummary
ironscales_add_licensed_domainsProWriteAdd licensed domains to a company, so IRONSCALES will protect mailboxes on them.
ironscales_add_licensed_domains_pdProWriteAdd licensed domains through the PLANS DETAILS family — the vendor's parallel path to the same outcome as ironscales_add_licensed_domains.
ironscales_cancel_company_licensesProDestructiveDESTRUCTIVE — MONEY AND PROTECTION.
ironscales_delete_licensed_domainsProDestructiveDESTRUCTIVE: remove licensed domains from a company.
ironscales_delete_licensed_domains_pdProDestructiveDESTRUCTIVE: remove licensed domains through the PLANS DETAILS family — same outcome as ironscales_delete_licensed_domains, via the vendor's parallel path.
ironscales_get_company_license_pdFreeRead-onlyGet a company's licence through the PLANS DETAILS family — IRONSCALES' second, parallel view of the same concept, which the vendor's own summaries mark 'PD'.
ironscales_get_company_license_planFreeRead-onlyGet a company's licence plan — the entitlement it is on and what that covers.
ironscales_get_domain_mailbox_statsFreeRead-onlyGet mailbox counts broken down by licensed domain for a company — how many mailboxes sit on each domain, and therefore where the licence consumption actually is.
ironscales_list_licensed_domainsFreeRead-onlyList the email domains licensed for a company — the domains IRONSCALES will protect mailboxes on.
ironscales_list_licensed_domains_pdFreeRead-onlyList a company's licensed domains through the PLANS DETAILS family — the vendor's parallel view of the same data, marked 'PD' in its own summaries.
ironscales_update_company_licenseProWriteChange a company's licence — move it to a different plan or adjust its entitlement.

[IRONSCALES] Add licensed domains to a company, so IRONSCALES will protect mailboxes on them. Additive and coverage-widening. Note it may consume entitlement — check ironscales_get_company_license_plan against ironscales_get_domain_mailbox_stats if the domain carries many mailboxes. Provide a JSON object body naming the domains.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the domains to add, in the shape IRONSCALES' licensed-domains schema expects.

[IRONSCALES] Add licensed domains through the PLANS DETAILS family — the vendor's parallel path to the same outcome as ironscales_add_licensed_domains. Additive and coverage-widening. Use whichever family matches the one you read the current domains from, to avoid confusing shapes.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the domains to add, in the shape IRONSCALES' licensed-domains schema expects.

[IRONSCALES] DESTRUCTIVE — MONEY AND PROTECTION. Cancel a company's IRONSCALES licences. This ends the commercial arrangement and, with it, the protection those licences pay for; restoring it is a purchasing conversation, not an API call. Confirm the company id and the current plan with ironscales_get_company_license_plan before calling. Provide a JSON object body with the cancellation details the vendor's schema expects.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies. Verify it with ironscales_get_company first — a mistyped id is still a valid id for a different customer.
fieldsJsonstringyesJSON object body with the cancellation details, in the shape IRONSCALES' cancellation schema expects.

[IRONSCALES] DESTRUCTIVE: remove licensed domains from a company. Mailboxes on those domains stop being protected — mail keeps flowing, it simply stops being inspected, so this fails quietly rather than visibly. Run ironscales_get_domain_mailbox_stats first to see exactly how many mailboxes each domain covers. Provide a JSON object body naming the domains to remove.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the domains to remove, in the shape IRONSCALES' licensed-domains schema expects.

[IRONSCALES] DESTRUCTIVE: remove licensed domains through the PLANS DETAILS family — same outcome as ironscales_delete_licensed_domains, via the vendor's parallel path. Mailboxes on those domains stop being protected, quietly. Run ironscales_get_domain_mailbox_stats first to see what each domain covers.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body naming the domains to remove, in the shape IRONSCALES' licensed-domains schema expects.

[IRONSCALES] Get a company's licence through the PLANS DETAILS family — IRONSCALES' second, parallel view of the same concept, which the vendor's own summaries mark 'PD'. Both this and ironscales_get_company_license_plan are live and return different shapes; pick one and stay with it within a report rather than mixing them.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get a company's licence plan — the entitlement it is on and what that covers. Pair with ironscales_get_company_stats to compare entitlement against actual consumption. See also ironscales_get_company_license_pd, the same concept via the parallel Plans Details family, which returns a different shape.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Get mailbox counts broken down by licensed domain for a company — how many mailboxes sit on each domain, and therefore where the licence consumption actually is. Useful before removing a licensed domain, because it tells you how many mailboxes that removal would stop protecting.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] List the email domains licensed for a company — the domains IRONSCALES will protect mailboxes on. A mailbox on a domain that is not listed here is not covered, which makes this the first thing to check when a customer reports that some of their mail is not being inspected.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] List a company's licensed domains through the PLANS DETAILS family — the vendor's parallel view of the same data, marked 'PD' in its own summaries. Equivalent in purpose to ironscales_list_licensed_domains; both are live.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

[IRONSCALES] Change a company's licence — move it to a different plan or adjust its entitlement. This has BILLING consequences with IRONSCALES even though it is technically reversible, so treat it as a commercial action rather than a configuration tweak. Read ironscales_get_company_license_plan and ironscales_get_company_stats first so the new entitlement covers actual consumption. Provide a JSON object body with the licence change.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringyesJSON object body describing the licence change, in the shape IRONSCALES' plan schema expects.

Integrations

ToolPlanAccessSummary
ironscales_authorize_gws_integrationProWriteComplete the Google Workspace authorization handshake after a Super Admin has consented, connecting IRONSCALES to the customer's mail tenant.
ironscales_authorize_o365_integrationProWriteComplete the Microsoft 365 authorization handshake after an administrator has consented, connecting IRONSCALES to the customer's mail tenant.
ironscales_disable_integrationProDestructiveDESTRUCTIVE — ENDS MAIL PROTECTION.
ironscales_generate_gws_consent_urlProWriteGenerate the Google Workspace admin-consent URL for a company — the link a customer's Super Admin visits to grant IRONSCALES access to their mail tenant.
ironscales_generate_o365_consent_urlProWriteGenerate the Microsoft 365 admin-consent URL for a company — the link a customer's Global Administrator visits to grant IRONSCALES access to their mail tenant.
ironscales_get_integration_statusFreeRead-onlyGet the health of a company's mail-platform integration — whether IRONSCALES is currently connected to their Microsoft 365 or Google Workspace tenant, and in what state.

[IRONSCALES] Complete the Google Workspace authorization handshake after a Super Admin has consented, connecting IRONSCALES to the customer's mail tenant. Additive — this turns protection on. The vendor spec declares no request body for this operation.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
fieldsJsonstringnonullOptional JSON object body. The vendor spec declares none, so omit this unless you know the undocumented shape.

[IRONSCALES] Complete the Microsoft 365 authorization handshake after an administrator has consented, connecting IRONSCALES to the customer's mail tenant. Additive — this TURNS protection on. Note this endpoint carries no company id in its path, unlike every other integration operation: the company is identified by the authorization payload itself. Provide a JSON object body with the authorization details returned by the consent flow.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body with the authorization details from the Microsoft consent flow, in the shape IRONSCALES' authorize schema expects. Unlike the other integration tools, this endpoint takes no company id — the company comes from this payload.

[IRONSCALES] DESTRUCTIVE — ENDS MAIL PROTECTION. Disconnect IRONSCALES from the company's Microsoft 365 or Google Workspace tenant. Every mailbox in the company stops being inspected from that moment, and mail continues to flow, so nothing looks broken to the customer. Reconnecting is NOT an API call you can make on your own: it needs the customer's own administrator to go through the consent flow again. Confirm with ironscales_get_integration_status first, and be certain this is the company you mean. The vendor spec declares no request body.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies. Verify it with ironscales_get_company first — a mistyped id is still a valid id for a different customer, whose protection you would be ending.
fieldsJsonstringnonullOptional JSON object body. The vendor spec declares none, so omit this unless you know the undocumented shape.

[IRONSCALES] Get the health of a company's mail-platform integration — whether IRONSCALES is currently connected to their Microsoft 365 or Google Workspace tenant, and in what state. This is the first thing to check when a company shows no incidents at all: a broken or never-completed integration looks exactly like a quiet mailbox.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.

Threat Feeds

ToolPlanAccessSummary
ironscales_list_deepfake_eventsFreeRead-onlyList a company's deepfake SIEM events — IRONSCALES' detections of synthetic voice or video impersonation, in the shape a SIEM forwarder wants.
ironscales_list_escalated_emailsFreeRead-onlyList a company's escalated emails — individual messages raised for attention, at message granularity rather than the incident granularity of ironscales_list_incidents.

[IRONSCALES] List a company's deepfake SIEM events — IRONSCALES' detections of synthetic voice or video impersonation, in the shape a SIEM forwarder wants. This feed CURSORS rather than pages: pass the highest id you have already seen as sinceId to get only what is new, which is what makes it safe to poll repeatedly. Alternatively filter by createdAfter. StackJack caps limit at 100.

ParamTypeRequiredDefaultDescription
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
createdAfterstringnonullReturn only events created after this time. ISO-8601. An alternative to sinceId.
limitintegernonullMaximum events to return, capped at 100 by StackJack (IRONSCALES declares no maximum).
sinceIdintegernonullReturn only events with an id greater than this — the high-water mark from your last poll. This is how to follow the feed without re-reading what you already have.

[IRONSCALES] List a company's escalated emails — individual messages raised for attention, at message granularity rather than the incident granularity of ironscales_list_incidents. Filter by time window, recipient, threat type, classification (comma-separate several values for either) or the incident a message belongs to, and set isScanbackReport to isolate messages surfaced by a retro-scan. Paging uses page plus pageSize (capped at 100 by StackJack).

ParamTypeRequiredDefaultDescription
challengedTypestringnonullFilter by challenged type, as named by IRONSCALES.
classificationstringnonullFilter by classification — comma-separate several values to match any of them.
companyIdintegeryesThe company's numeric id, from ironscales_list_companies.
endTimestringnonullOnly messages at or before this time. ISO-8601.
incidentIdintegernonullFilter to messages belonging to this incident id, from ironscales_list_incidents.
isScanbackReportbooleannonullSet true to return only messages surfaced by a retro-scan (scanback) report.
pageintegernonullPage number, 1-based. Omit for the first page.
pageSizeintegernonullResults per page, capped at 100 by StackJack. This endpoint uses page_size, not items_per_page.
recipientstringnonullFilter to messages sent to this recipient.
startTimestringnonullOnly messages at or after this time. ISO-8601.
threatTypestringnonullFilter by threat type — comma-separate several values to match any of them.