IRONSCALES Tools
Written By Christopher Scaminaci
Last updated 7 days ago
IRONSCALES Tools
ironscales_ · 100 tools · Free 56 · Pro 44
Email security and security-awareness training for partners: nearly every path is scoped by an integer company id, discovered from the company list. The credential is a long-lived API key exchanged for a scoped token, so a company-scoped key answers 403 on the partner endpoints as normal operation. Authentication failures arrive as HTTP 400 carrying an auth message, not 401. Paging is not uniform - some reads take page with page_size, some page with items_per_page, and some page alone - and the wrong parameter is ignored silently; page size is capped at 100. A few array filters must be repeated rather than comma-joined. Rate limit is 120 calls a minute per company. Launching a campaign sends simulated phishing to real employees, the test-send tools deliver to real mailboxes, incident classification drives automatic remediation, and disabling an integration ends mail protection.
All connector tools · IRONSCALES setup guide
IRONSCALES tool groups
- Companies — 18 tools
- Incidents — 10 tools
- Mitigation — 9 tools
- Security Awareness Training — 22 tools
- Phishing Campaigns — 3 tools
- Settings — 14 tools
- Mailboxes — 5 tools
- Licensing — 11 tools
- Integrations — 6 tools
- Threat Feeds — 2 tools
Companies
ironscales_activate_auto_sync details
ironscales_activate_auto_sync details
[IRONSCALES] Turn on directory Auto-Sync for this company, so the protected mailbox list tracks the customer's Microsoft 365 or Google Workspace directory. Provide the company's numeric id and a JSON object body naming the groups or scope to sync — discover the available groups with ironscales_list_auto_sync_groups. Additive: this brings mailboxes UNDER protection. Note that syncing a large directory can consume licences, so check ironscales_get_company_stats against the entitlement first.
ironscales_create_company details
ironscales_create_company details
[IRONSCALES] Provision a new company under this partner. Provide a JSON object body with the company's details — at minimum its name and primary email domain; the vendor's create schema also accepts contact and plan fields. Requires a PARTNER-scoped API key. Returns the created company including the numeric id every other tool needs, so keep it. Additive: this creates a tenant and removes nothing, but note that provisioning a company generally has billing consequences with IRONSCALES.
ironscales_delete_911_email_settings details
ironscales_delete_911_email_settings details
[IRONSCALES] DESTRUCTIVE: remove the company's 911 (emergency report) email configuration. Employees who forward suspicious mail to that address afterwards are no longer creating IRONSCALES reports, so the reporting path goes quiet without any visible error for them. Read ironscales_get_911_email_settings first and keep the values if you may need to restore them — this tool returns no backup.
ironscales_disable_auto_sync details
ironscales_disable_auto_sync details
[IRONSCALES] DESTRUCTIVE: stop directory Auto-Sync for this company. Mailboxes already protected stay protected, but the list stops tracking the directory — so new starters are never added and leavers are never removed, and coverage drifts silently from that point on with no error to notice. Prefer narrowing the synced groups with ironscales_activate_auto_sync over turning sync off entirely.
ironscales_disable_company details
ironscales_disable_company details
[IRONSCALES] DESTRUCTIVE: deactivate an entire company in IRONSCALES. This is the DELETE verb on the company resource — the vendor calls it 'disable', but it takes the whole tenant out of service, which ends protection for every mailbox in it. Requires a PARTNER-scoped API key. Confirm the numeric id against ironscales_get_company before calling: company ids are small integers and a mistyped one is a valid id for somebody else's tenant.
ironscales_generate_owa_manifest details
ironscales_generate_owa_manifest details
[IRONSCALES] Generate the Outlook on the web (OWA) add-in manifest for this company — the XML/JSON descriptor an administrator uploads to Microsoft 365 to deploy the IRONSCALES report button. Provide the company's numeric id and a JSON object body with any manifest options the vendor accepts. This only PRODUCES the document; nothing is deployed and no mailbox changes until an administrator uploads it.
ironscales_get_911_email_settings details
ironscales_get_911_email_settings details
[IRONSCALES] Get the company's 911 (emergency report) email configuration — the mailbox employees forward suspicious mail to, and how IRONSCALES handles what arrives there. Returns the current configuration or an empty result when none is set.
ironscales_get_auto_sync_status details
ironscales_get_auto_sync_status details
[IRONSCALES] Get whether directory Auto-Sync is active for this company, and how it is configured. Auto-Sync keeps the protected mailbox list in step with the customer's Microsoft 365 or Google Workspace directory; when it is off, mailbox coverage drifts as staff join and leave. See ironscales_list_auto_sync_groups and ironscales_list_auto_sync_mailboxes for what it is currently pulling in.
ironscales_get_company details
ironscales_get_company details
[IRONSCALES] Get one company's profile by its numeric id, from ironscales_list_companies. Returns the company's own attributes (name, domains, contact and configuration fields) rather than its statistics — for licence consumption and protection counts use ironscales_get_company_stats.
ironscales_get_company_features details
ironscales_get_company_features details
[IRONSCALES] Get which IRONSCALES product features are switched on for this company, and their access state. Read this before ironscales_update_company_features so you know the current value of every flag — that write replaces feature states, and a flag you cannot see is a flag you can accidentally turn off.
ironscales_get_company_stats details
ironscales_get_company_stats details
[IRONSCALES] Get one company's statistics and licence position — protected mailbox counts against entitlement, and the activity totals IRONSCALES reports for the company. Use this to answer 'how many licences is this customer consuming' without walking the mailbox list. For the licence PLAN itself see ironscales_get_company_license_plan.
ironscales_list_auto_sync_groups details
ironscales_list_auto_sync_groups details
[IRONSCALES] List the directory groups available to Auto-Sync for this company — the groups whose members can be brought under protection automatically. Use the returned group identifiers when configuring Auto-Sync with ironscales_activate_auto_sync. For Google Workspace, gdAdminEmail scopes the lookup to one admin's directory view.
ironscales_list_auto_sync_mailboxes details
ironscales_list_auto_sync_mailboxes details
[IRONSCALES] List the mailboxes Auto-Sync has brought into this company from the customer's directory. Compare this with ironscales_list_mailboxes to see which protected mailboxes are directory-managed versus added by hand — the ones added by hand are what stop being maintained if staff turnover is handled only in the directory.
ironscales_list_companies details
ironscales_list_companies details
[IRONSCALES] List the companies this partner manages — the ENTRY POINT for this connector. Each item carries the company's numeric id and name; that id is the companyId argument required by nearly every other IRONSCALES tool. Optionally filter by name or by a domain the company owns. Requires a PARTNER-scoped API key: a company-scoped key is refused with 403, which is expected rather than a fault — such a tenant already knows its one company id and can use the company-scoped tools directly. See also ironscales_list_companies_v2, the newer paginated version of this same listing.
ironscales_list_companies_v2 details
ironscales_list_companies_v2 details
[IRONSCALES] List the partner's companies using the NEWER V2 endpoint, which adds paging to the same data. Prefer this over ironscales_list_companies when the partner manages many companies; both remain live and IRONSCALES has not retired the original. Requires a PARTNER-scoped API key — a company-scoped key is refused with 403, which is expected.
ironscales_update_911_email_settings details
ironscales_update_911_email_settings details
[IRONSCALES] Set the company's 911 (emergency report) email configuration — the mailbox employees forward suspicious messages to, and how IRONSCALES treats what arrives. Provide the company's numeric id and a JSON object body with the settings. Read the current configuration with ironscales_get_911_email_settings first. Reversible: the settings can be changed again; removing the configuration entirely is ironscales_delete_911_email_settings.
ironscales_update_company details
ironscales_update_company details
[IRONSCALES] Update a company's profile — its name, domains, contact and configuration attributes. Provide the company's numeric id plus a JSON object body carrying the fields to change. Read the current values with ironscales_get_company first, because the vendor's update semantics replace the fields you send. Reversible: re-applying the previous values restores the earlier state. This does NOT change licensing (see ironscales_update_company_license) or feature access (see ironscales_update_company_features).
ironscales_update_company_features details
ironscales_update_company_features details
[IRONSCALES] DESTRUCTIVE: change which IRONSCALES features are enabled for a whole company. This can switch protections OFF for every mailbox at once, which is why it is marked destructive even though the same call can also switch them on. Read ironscales_get_company_features first and send the complete intended state — the vendor documents no request body for this operation, so StackJack sends whatever JSON object you provide and omitting a flag may reset it.
Incidents
ironscales_classify_incident details
ironscales_classify_incident details
[IRONSCALES] DESTRUCTIVE: classify an incident. This is NOT a passive label — the classification drives IRONSCALES' automatic remediation across the whole mailbox fleet, so marking a cluster malicious removes those messages from every inbox that received them, and marking a real threat safe leaves it in place. Provide the company's numeric id, the incident id and a JSON object body with the classification the vendor's schema expects. Read ironscales_get_incident first so the verdict rests on the evidence.
ironscales_create_account_takeover_remediation details
ironscales_create_account_takeover_remediation details
[IRONSCALES] DESTRUCTIVE: execute account-takeover remediation for an ATO incident. Depending on the actions requested, this can disable a real user account, force a password reset or revoke active sessions — locking a genuine person out of their mailbox if the verdict was wrong. Read ironscales_get_account_takeover_incident first and confirm the sign-in evidence. Provide the company's numeric id, the incident id and a JSON object body naming the remediation actions.
ironscales_get_account_takeover_incident details
ironscales_get_account_takeover_incident details
[IRONSCALES] Get the detail of an account-takeover (ATO) incident — the suspicious sign-in activity IRONSCALES observed for a mailbox, with the events behind the verdict. Filter the event list by title, location or source IP (each accepts several comma-separated values). Paging uses page plus itemsPerPage. Read this before ironscales_create_account_takeover_remediation, because remediation can disable or reset the real user account.
ironscales_get_incident details
ironscales_get_incident details
[IRONSCALES] Get the full detail of one incident — the reported message, its sender and recipients, IRONSCALES' verdict and confidence, the affected mailboxes, and the remediation state. Read this before ironscales_classify_incident so the classification is based on the evidence rather than the subject line alone.
ironscales_get_remediation_status_stats details
ironscales_get_remediation_status_stats details
[IRONSCALES] Get counts of incidents by remediation outcome over a time window — how much was removed, quarantined or left in place. Both startTime and endTime are REQUIRED by IRONSCALES. Set includeScanback true to fold in retro-scan incidents, which otherwise sit outside these totals and make remediation look less active than it was.
ironscales_list_incident_ids_by_status details
ironscales_list_incident_ids_by_status details
[IRONSCALES] Get just the incident IDs in one status — the cheapest way to answer 'what is waiting for me', IRONSCALES documents exactly one status value for this call, 'open' (its own operation title calls these the unclassified incidents; passing 'unclassified' as the status returns 404). Returns identifiers only, not incident detail; feed them to ironscales_get_incident for the full record. Prefer this over ironscales_list_incidents when you only need a count or a work queue, because it avoids paging through full incident bodies.
ironscales_list_incidents details
ironscales_list_incidents details
[IRONSCALES] List a company's phishing incidents — the main triage queue. Filter by creation or last-update time window, by classification and state (both accept several comma-separated values), by reporting type, and by free-text search across the message subject, sender name/email and recipient name/email. Returns the incident id every other incident tool needs. Paging uses page plus itemsPerPage (StackJack caps itemsPerPage at 100). For incidents raised by a retro-scan rather than by a live report, use ironscales_list_scanback_incidents.
ironscales_list_scanback_incidents details
ironscales_list_scanback_incidents details
[IRONSCALES] List incidents raised by a retro-scan (scanback) — mail already delivered that a later verdict re-flagged, rather than mail caught or reported when it arrived. These matter because the message has already been sitting in users' inboxes. Same filters as ironscales_list_incidents, minus the report-type and last-update filters. Paging uses page plus itemsPerPage (capped at 100 by StackJack).
ironscales_recluster_incident details
ironscales_recluster_incident details
[IRONSCALES] Recluster an incident — ask IRONSCALES to re-group the messages it considers part of the same campaign. This changes how the incident is presented and remediated as a unit; it does not itself remove or release any mail. Reversible: ironscales_uncluster_incident splits a cluster back apart.
ironscales_uncluster_incident details
ironscales_uncluster_incident details
[IRONSCALES] Uncluster an incident — split messages IRONSCALES grouped as one campaign back into separate incidents, so they can be judged individually. Useful when a cluster has swept up legitimate mail alongside a real threat. This does not remove or release any mail on its own; the classification does that. Reversible with ironscales_recluster_incident.
Mitigation
ironscales_get_company_mitigation_details details
ironscales_get_company_mitigation_details details
[IRONSCALES] Get company-wide mitigation detail — the incidents IRONSCALES acted on and what it did, rolled up for the company rather than per mailbox. Use the period argument for a relative window. For the per-mailbox breakdown use ironscales_get_mailbox_mitigation_details.
ironscales_get_email_stats details
ironscales_get_email_stats details
[IRONSCALES] Get email volume and verdict statistics for a company over a time window — how much mail was scanned and how it was judged. Both startTime and endTime are REQUIRED. Set includeScanback true to fold in retro-scan results, which otherwise sit outside these totals.
ironscales_get_latest_impersonation_incidents details
ironscales_get_latest_impersonation_incidents details
[IRONSCALES] Get the company's most recent impersonation incidents — mail where the sender was posing as a colleague, executive or trusted brand. The period argument is REQUIRED and sets how far back to look. This returns the latest set only; for a paged, filtered search use ironscales_search_impersonation_incidents.
ironscales_get_mailbox_mitigation_details details
ironscales_get_mailbox_mitigation_details details
[IRONSCALES] Report what IRONSCALES mitigated per mailbox for one company — which mailboxes received flagged mail and what happened to it. This is a READ even though it uses POST: the filter and paging criteria travel in the request body, and nothing is changed. Provide a JSON object body with the criteria the vendor's mitigation-details schema accepts (typically a time window plus paging).
ironscales_get_mitigation_stats details
ironscales_get_mitigation_stats details
[IRONSCALES] Get the company's mitigation statistics for a period — the headline counts of what IRONSCALES caught and removed. The period argument is REQUIRED. See also ironscales_get_mitigation_stats_v2, the newer version of this same report; both are live and return different shapes, so pick one and stay with it within a report.
ironscales_get_mitigation_stats_v2 details
ironscales_get_mitigation_stats_v2 details
[IRONSCALES] Get the company's mitigation statistics using the NEWER V2 report. Prefer this for new work; ironscales_get_mitigation_stats remains live for anything already built against it, and IRONSCALES has not retired it. The period argument is REQUIRED.
ironscales_get_most_targeted_departments details
ironscales_get_most_targeted_departments details
[IRONSCALES] Rank the company's departments by how much malicious mail was aimed at them over a time window — useful for deciding where to point training. Both startTime and endTime are REQUIRED. Departments come from the mailbox records, so this is only as good as the department field on ironscales_list_mailboxes.
ironscales_get_most_targeted_employees details
ironscales_get_most_targeted_employees details
[IRONSCALES] Rank the company's individual employees by how much malicious mail was aimed at them over a time window — the people worth prioritising for training or tighter controls. Both startTime and endTime are REQUIRED. Pair with ironscales_get_user_campaign_performance to see whether the most-targeted people are also the ones failing simulations.
ironscales_search_impersonation_incidents details
ironscales_search_impersonation_incidents details
[IRONSCALES] Search the company's impersonation incidents with filtering and paging. This is a READ even though it uses POST — the criteria travel in the request body and nothing is changed. Prefer this over ironscales_get_latest_impersonation_incidents when you need more than the most recent set or want to filter. Provide a JSON object body with the criteria the vendor's impersonation-details schema accepts.
Security Awareness Training
ironscales_approve_sat_campaign details
ironscales_approve_sat_campaign details
[IRONSCALES] DESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE. The vendor calls this 'approve a draft campaign', but approving LAUNCHES it: simulated phishing or training messages go out to the company's employees on the campaign's schedule, and there is no unsend. Before calling, read ironscales_get_sat_campaign to confirm what will be sent and ironscales_calculate_sat_participants to confirm who will receive it. The vendor spec declares no request body for this operation.
ironscales_calculate_sat_participants details
ironscales_calculate_sat_participants details
[IRONSCALES] Work out how many people a given audience filter would reach, without enrolling or sending anything. This is a READ despite using POST — the filter criteria travel in the request body. Run this before approving a campaign to confirm the blast radius: it is the difference between simulating on twelve people and on the whole company. Provide a JSON object body with the audience filters the vendor's participants schema accepts.
ironscales_create_sat_campaign details
ironscales_create_sat_campaign details
[IRONSCALES] Create a security-awareness campaign as a DRAFT. Nothing is sent by this call — no employee receives anything until the campaign is approved, which is a separate tool. Provide a JSON object body defining the campaign: its templates (ironscales_list_sat_templates), trainings (ironscales_list_sat_trainings), landing and call-for-action pages, schedule and audience. Read ironscales_get_sat_campaign_setup first for the options this company can use, and ironscales_calculate_sat_participants to check how many people the audience filter would reach. Returns the new campaign including its id.
ironscales_delete_sat_campaign details
ironscales_delete_sat_campaign details
[IRONSCALES] DESTRUCTIVE: delete a SAT campaign. If the campaign has already run, deleting it also takes away the results — so read ironscales_get_sat_campaign_stats first if the outcome matters for reporting or compliance evidence. Stopping a running campaign without losing its history is ironscales_stop_sat_campaign instead.
ironscales_get_sat_campaign details
ironscales_get_sat_campaign details
[IRONSCALES] Get one SAT campaign's full definition — its templates, trainings, schedule, audience and current status. Read this before approving a campaign, because approval LAUNCHES it to real employees and there is no unsend.
ironscales_get_sat_campaign_setup details
ironscales_get_sat_campaign_setup details
[IRONSCALES] Get the campaign setup options for this company — the choices available when building a campaign (flows, schedules, locales and the like). Read this before ironscales_create_sat_campaign so the draft is composed from values the company can actually use.
ironscales_get_sat_campaign_stats details
ironscales_get_sat_campaign_stats details
[IRONSCALES] Get one SAT campaign's results — delivery, open, click and report rates, and training completion. This is how you tell whether a simulation worked. For results broken down per person across campaigns, use ironscales_get_user_campaign_performance.
ironscales_get_sat_training_preview details
ironscales_get_sat_training_preview details
[IRONSCALES] Get a preview URL for one training module in a given language, so a human can review the content before it is assigned to staff. The localeId argument is REQUIRED. This returns a link only; nothing is assigned or sent.
ironscales_list_sat_campaigns details
ironscales_list_sat_campaigns details
[IRONSCALES] List the company's security-awareness campaigns with their full detail — status, schedule, flow type and locale. Filter by status, flow type, locale or scheduled date/time range, and search by name. Returns the campaign id the other SAT campaign tools need. Paging uses page plus pageSize (StackJack caps pageSize at 100). For just ids and names use the cheaper ironscales_lookup_sat_campaigns.
ironscales_list_sat_cta_pages details
ironscales_list_sat_cta_pages details
[IRONSCALES] List the call-for-action pages available to this company — the follow-up pages shown after an employee interacts with a simulation, typically the teaching moment. Search by name; paging uses page plus pageSize.
ironscales_list_sat_landing_pages details
ironscales_list_sat_landing_pages details
[IRONSCALES] List the landing pages available to this company — the pages a simulated phishing link takes an employee to when they click. Filter by locale or author, and search by name. Paging uses page plus pageSize.
ironscales_list_sat_participants details
ironscales_list_sat_participants details
[IRONSCALES] List the company's training participants grouped by category — who is eligible to receive campaigns, organised the way IRONSCALES groups them. Use ironscales_calculate_sat_participants to find out how many people a specific filter set would actually reach before launching anything.
ironscales_list_sat_template_categories details
ironscales_list_sat_template_categories details
[IRONSCALES] List the template categories available to this company. The returned category ids are the categoryIds filter on ironscales_list_sat_templates — call this first when you want to find, say, every credential-harvesting template.
ironscales_list_sat_templates details
ironscales_list_sat_templates details
[IRONSCALES] List the phishing-simulation and training templates available to this company. Filter by category, locale, type, difficulty level or author, and search by name. The returned template id is what ironscales_send_sat_template_test takes, and what campaign definitions reference. Paging uses page plus pageSize.
ironscales_list_sat_training_providers details
ironscales_list_sat_training_providers details
[IRONSCALES] List the training providers available to this company. The returned provider id is the REQUIRED vendor argument on ironscales_list_sat_trainings, so call this first when browsing training content.
ironscales_list_sat_trainings details
ironscales_list_sat_trainings details
[IRONSCALES] List the training modules available from one provider. The vendor argument is REQUIRED and identifies the training provider — get the valid values from ironscales_list_sat_training_providers first. Filter by locale. Paging uses page plus pageSize.
ironscales_lookup_sat_campaigns details
ironscales_lookup_sat_campaigns details
[IRONSCALES] Get a lightweight id-and-name list of the company's SAT campaigns — the cheap way to resolve a campaign name to the id the other tools need, without pulling full campaign records. Accepts the same filters as ironscales_list_sat_campaigns. Prefer this when you only need to find a campaign.
ironscales_search_sat_participants details
ironscales_search_sat_participants details
[IRONSCALES] Search the company's training participants. This is a READ despite using POST — the search criteria travel in the request body and nothing is changed. Provide a JSON object body with the search criteria the vendor's participant-search schema accepts.
ironscales_send_sat_campaign_simulation_test details
ironscales_send_sat_campaign_simulation_test details
[IRONSCALES] DESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE. Sends this campaign's phishing simulation to up to ten company mailboxes. In IRONSCALES a 'test send' is a small LIVE send, not a rehearsal: the named recipients receive an actual simulated phishing message and it cannot be unsent. Provide a JSON object body naming the recipients, which must be real mailboxes in the company. Use this to check rendering with willing colleagues before ironscales_approve_sat_campaign goes to everyone.
ironscales_send_sat_campaign_training_test details
ironscales_send_sat_campaign_training_test details
[IRONSCALES] DESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE. Sends this campaign's TRAINING message to up to ten company mailboxes. As with the simulation test, 'test' here means a small live send rather than a rehearsal, and the named recipients are assigned the training for real. Provide a JSON object body naming the recipients.
ironscales_send_sat_template_test details
ironscales_send_sat_template_test details
[IRONSCALES] DESTRUCTIVE — SENDS REAL EMAIL TO REAL PEOPLE. Sends one template to up to ten real recipients so a human can see how it renders. This needs no campaign, which makes it the quickest way to put a simulated phishing message in somebody's inbox — treat it accordingly. Provide the template id from ironscales_list_sat_templates and a JSON object body naming the recipients. To preview training content WITHOUT sending anything, use ironscales_get_sat_training_preview instead.
ironscales_stop_sat_campaign details
ironscales_stop_sat_campaign details
[IRONSCALES] Stop an active SAT campaign, halting any sends that have not gone out yet. This is strictly risk-reducing — it means less mail reaches employees, never more — which is why it is not marked destructive. Messages already delivered stay delivered; use this when a simulation is landing badly or was aimed at the wrong audience. The vendor spec declares no request body.
Phishing Campaigns
ironscales_get_campaign_details details
ironscales_get_campaign_details details
[IRONSCALES] Get the company's phishing-simulation campaigns and their delivery detail over a period. The period argument is REQUIRED. Filter by status (comma-separate several values) or by campaign name. Note this is the /campaigns/ family, which reports on simulation delivery — the security-awareness campaign definitions live under ironscales_list_sat_campaigns.
ironscales_get_campaign_participants details
ironscales_get_campaign_participants details
[IRONSCALES] Get the per-participant detail for one phishing-simulation campaign — who received it and what each person did (opened, clicked, reported, or nothing). This is the evidence behind the campaign's headline numbers, and the list you would use to decide who needs follow-up training.
ironscales_perform_campaign_participant_action details
ironscales_perform_campaign_participant_action details
[IRONSCALES] DESTRUCTIVE — REACHES REAL PEOPLE. Perform an action on named participants in a phishing-simulation campaign, typically enrolling them in follow-up training or notifying them about their result. The effect lands on identified employees rather than on data, and depending on the action they may receive email. Read ironscales_get_campaign_participants first to confirm exactly who is in scope. Provide a JSON object body naming the participants and the action.
Settings
ironscales_append_challenged_alert_settings details
ironscales_append_challenged_alert_settings details
[IRONSCALES] Append to the company's challenged-alert notification settings — add recipients or options without disturbing the existing configuration. Safe by construction: it cannot drop recipients that are already there. Provide a JSON object body with what to add.
ironscales_append_incident_alert_settings details
ironscales_append_incident_alert_settings details
[IRONSCALES] Append to the company's incident notification settings — add recipients or options without disturbing what is already configured. This is the safe way to add someone to an alert list, because it cannot silently drop the existing recipients the way a full replacement could. Provide a JSON object body with what to add.
ironscales_create_allow_list_entry details
ironscales_create_allow_list_entry details
[IRONSCALES] Add entries to the company's allow-list, telling IRONSCALES to treat those senders, domains or addresses as safe. Additive — existing entries are untouched — but understand what it means: each entry is a deliberate gap in protection, and allow-listing a whole domain is much broader than allow-listing one sender. Provide a JSON object body with the entries in the shape IRONSCALES' allow-list schema expects.
ironscales_create_challenged_alert_settings details
ironscales_create_challenged_alert_settings details
[IRONSCALES] Create the company's challenged-alert notification settings — establish who is told when IRONSCALES challenges a message. Additive: this turns that alerting on. To add recipients to existing settings use ironscales_append_challenged_alert_settings instead. Provide a JSON object body with the recipients and options.
ironscales_create_incident_alert_settings details
ironscales_create_incident_alert_settings details
[IRONSCALES] Create the company's incident notification settings — establish who is alerted when IRONSCALES raises an incident. Additive: this turns alerting ON. To add recipients to settings that already exist without disturbing the current ones, use ironscales_append_incident_alert_settings instead. Provide a JSON object body with the recipients and options.
ironscales_delete_allow_list_entries details
ironscales_delete_allow_list_entries details
[IRONSCALES] DESTRUCTIVE: remove entries from the company's allow-list. Mail from those senders is subject to full inspection again, which is usually the safer state — but if the entry existed to stop a business-critical sender being quarantined, removing it can start blocking mail the customer depends on. Read ironscales_list_allow_list_entries first and keep a note of what you remove. Provide a JSON object body naming the entries to delete.
ironscales_delete_challenged_alert_settings details
ironscales_delete_challenged_alert_settings details
[IRONSCALES] DESTRUCTIVE: remove the company's challenged-alert notification settings. Challenging still happens, but nobody is notified about it — another failure that presents as silence rather than an error. Read ironscales_get_challenged_alert_settings first and keep the recipients if you may need to restore them. The vendor spec declares no request body.
ironscales_delete_incident_alert_settings details
ironscales_delete_incident_alert_settings details
[IRONSCALES] DESTRUCTIVE: remove the company's incident notification settings. Detection keeps working, but nobody is told when an incident is raised — and an alerting path that has gone quiet looks exactly like a quiet week, so this failure is unusually hard to notice. Read ironscales_get_incident_alert_settings first and keep the recipients if you may need to restore them. The vendor spec declares no request body.
ironscales_get_account_takeover_settings details
ironscales_get_account_takeover_settings details
[IRONSCALES] Get the company's account-takeover (ATO) detection sensitivity — how aggressively IRONSCALES flags suspicious sign-in behaviour. Read this when tuning false positives, and pair it with the ATO incidents from ironscales_list_incidents to judge whether the current setting is right for the customer.
ironscales_get_challenged_alert_settings details
ironscales_get_challenged_alert_settings details
[IRONSCALES] Get the company's challenged-alert notification settings — who is told when IRONSCALES challenges a message and how. These are separate from incident alerts (ironscales_get_incident_alert_settings); a company can have one configured and not the other.
ironscales_get_incident_alert_settings details
ironscales_get_incident_alert_settings details
[IRONSCALES] Get the company's incident notification settings — who is told when IRONSCALES raises an incident, and how. Read this before changing alerting so you know who is currently on the list; a company whose only alert recipient has left is a common and silent failure.
ironscales_list_allow_list_entries details
ironscales_list_allow_list_entries details
[IRONSCALES] List the company's allow-list entries — the senders, domains and addresses IRONSCALES is told to treat as safe. Worth auditing: every entry here is a deliberate hole in the company's protection, and stale entries are a common way a real phish gets through. Filter by entry type and search text; paging uses page plus itemsPerPage (capped at 100 by StackJack).
ironscales_update_account_takeover_settings details
ironscales_update_account_takeover_settings details
[IRONSCALES] Set the company's account-takeover detection sensitivity. Reversible — it is a dial, and the previous value can simply be set again — but be aware of the direction of risk: loosening it means fewer false positives and fewer genuine takeovers caught. Read ironscales_get_account_takeover_settings first. Provide a JSON object body with the sensitivity settings.
ironscales_update_allow_list_entry details
ironscales_update_allow_list_entry details
[IRONSCALES] Update an existing allow-list entry. Read ironscales_list_allow_list_entries first to identify the entry and see its current value — this replaces the fields you send. Reversible: re-applying the previous values restores it. To remove entries entirely use ironscales_delete_allow_list_entries.
Mailboxes
ironscales_add_mailboxes details
ironscales_add_mailboxes details
[IRONSCALES] Add mailboxes to a company so IRONSCALES protects them. Additive — nothing existing is changed — but each mailbox consumes licence entitlement, so check ironscales_get_company_stats against the plan before adding in bulk. For companies using directory Auto-Sync, prefer widening the synced groups (ironscales_activate_auto_sync) so the list stays maintained on its own. Provide a JSON object body with the mailboxes to add.
ironscales_bulk_edit_mailboxes details
ironscales_bulk_edit_mailboxes details
[IRONSCALES] DESTRUCTIVE: change many mailboxes in one call. The danger is scale rather than the edit itself — a selector that matches more mailboxes than intended applies the change to all of them, and among the properties this can set is whether a mailbox is protected, so a mistake here silently drops coverage across a company. Run the same filters through ironscales_list_mailboxes first and confirm the returned set is exactly what you mean to change. Provide a JSON object body with the selection and the changes.
ironscales_get_mailbox_compliance_report details
ironscales_get_mailbox_compliance_report details
[IRONSCALES] Get the company's training compliance report — who has completed their assigned security-awareness training and who has not, over a period. Use period for a relative window, or customPeriodFrom and customPeriodTo for an explicit one. This is the report most often needed for a customer's compliance evidence.
ironscales_get_user_campaign_performance details
ironscales_get_user_campaign_performance details
[IRONSCALES] Get per-user phishing-simulation performance across campaigns — how each person has been doing over time, rather than the result of a single campaign. Filter by country, department or campaign type (comma-separate several campaign types). Pair with ironscales_get_most_targeted_employees to find the people who are both heavily targeted and struggling, who are the ones worth acting on first.
ironscales_list_mailboxes details
ironscales_list_mailboxes details
[IRONSCALES] List a company's mailboxes with rich filtering — by enabled and protected state, tags, awareness level, department, title, language, name or email, or by explicit id sets. This is the authoritative view of what IRONSCALES is actually protecting, and comparing isProtected against the licence position from ironscales_get_company_stats is how you spot coverage gaps. Paging uses page plus itemsPerPage (capped at 100 by StackJack); note this endpoint uses items_per_page, not page_size.
Licensing
ironscales_add_licensed_domains details
ironscales_add_licensed_domains details
[IRONSCALES] Add licensed domains to a company, so IRONSCALES will protect mailboxes on them. Additive and coverage-widening. Note it may consume entitlement — check ironscales_get_company_license_plan against ironscales_get_domain_mailbox_stats if the domain carries many mailboxes. Provide a JSON object body naming the domains.
ironscales_add_licensed_domains_pd details
ironscales_add_licensed_domains_pd details
[IRONSCALES] Add licensed domains through the PLANS DETAILS family — the vendor's parallel path to the same outcome as ironscales_add_licensed_domains. Additive and coverage-widening. Use whichever family matches the one you read the current domains from, to avoid confusing shapes.
ironscales_cancel_company_licenses details
ironscales_cancel_company_licenses details
[IRONSCALES] DESTRUCTIVE — MONEY AND PROTECTION. Cancel a company's IRONSCALES licences. This ends the commercial arrangement and, with it, the protection those licences pay for; restoring it is a purchasing conversation, not an API call. Confirm the company id and the current plan with ironscales_get_company_license_plan before calling. Provide a JSON object body with the cancellation details the vendor's schema expects.
ironscales_delete_licensed_domains details
ironscales_delete_licensed_domains details
[IRONSCALES] DESTRUCTIVE: remove licensed domains from a company. Mailboxes on those domains stop being protected — mail keeps flowing, it simply stops being inspected, so this fails quietly rather than visibly. Run ironscales_get_domain_mailbox_stats first to see exactly how many mailboxes each domain covers. Provide a JSON object body naming the domains to remove.
ironscales_delete_licensed_domains_pd details
ironscales_delete_licensed_domains_pd details
[IRONSCALES] DESTRUCTIVE: remove licensed domains through the PLANS DETAILS family — same outcome as ironscales_delete_licensed_domains, via the vendor's parallel path. Mailboxes on those domains stop being protected, quietly. Run ironscales_get_domain_mailbox_stats first to see what each domain covers.
ironscales_get_company_license_pd details
ironscales_get_company_license_pd details
[IRONSCALES] Get a company's licence through the PLANS DETAILS family — IRONSCALES' second, parallel view of the same concept, which the vendor's own summaries mark 'PD'. Both this and ironscales_get_company_license_plan are live and return different shapes; pick one and stay with it within a report rather than mixing them.
ironscales_get_company_license_plan details
ironscales_get_company_license_plan details
[IRONSCALES] Get a company's licence plan — the entitlement it is on and what that covers. Pair with ironscales_get_company_stats to compare entitlement against actual consumption. See also ironscales_get_company_license_pd, the same concept via the parallel Plans Details family, which returns a different shape.
ironscales_get_domain_mailbox_stats details
ironscales_get_domain_mailbox_stats details
[IRONSCALES] Get mailbox counts broken down by licensed domain for a company — how many mailboxes sit on each domain, and therefore where the licence consumption actually is. Useful before removing a licensed domain, because it tells you how many mailboxes that removal would stop protecting.
ironscales_list_licensed_domains details
ironscales_list_licensed_domains details
[IRONSCALES] List the email domains licensed for a company — the domains IRONSCALES will protect mailboxes on. A mailbox on a domain that is not listed here is not covered, which makes this the first thing to check when a customer reports that some of their mail is not being inspected.
ironscales_list_licensed_domains_pd details
ironscales_list_licensed_domains_pd details
[IRONSCALES] List a company's licensed domains through the PLANS DETAILS family — the vendor's parallel view of the same data, marked 'PD' in its own summaries. Equivalent in purpose to ironscales_list_licensed_domains; both are live.
ironscales_update_company_license details
ironscales_update_company_license details
[IRONSCALES] Change a company's licence — move it to a different plan or adjust its entitlement. This has BILLING consequences with IRONSCALES even though it is technically reversible, so treat it as a commercial action rather than a configuration tweak. Read ironscales_get_company_license_plan and ironscales_get_company_stats first so the new entitlement covers actual consumption. Provide a JSON object body with the licence change.
Integrations
ironscales_authorize_gws_integration details
ironscales_authorize_gws_integration details
[IRONSCALES] Complete the Google Workspace authorization handshake after a Super Admin has consented, connecting IRONSCALES to the customer's mail tenant. Additive — this turns protection on. The vendor spec declares no request body for this operation.
ironscales_authorize_o365_integration details
ironscales_authorize_o365_integration details
[IRONSCALES] Complete the Microsoft 365 authorization handshake after an administrator has consented, connecting IRONSCALES to the customer's mail tenant. Additive — this TURNS protection on. Note this endpoint carries no company id in its path, unlike every other integration operation: the company is identified by the authorization payload itself. Provide a JSON object body with the authorization details returned by the consent flow.
ironscales_disable_integration details
ironscales_disable_integration details
[IRONSCALES] DESTRUCTIVE — ENDS MAIL PROTECTION. Disconnect IRONSCALES from the company's Microsoft 365 or Google Workspace tenant. Every mailbox in the company stops being inspected from that moment, and mail continues to flow, so nothing looks broken to the customer. Reconnecting is NOT an API call you can make on your own: it needs the customer's own administrator to go through the consent flow again. Confirm with ironscales_get_integration_status first, and be certain this is the company you mean. The vendor spec declares no request body.
ironscales_generate_gws_consent_url details
ironscales_generate_gws_consent_url details
[IRONSCALES] Generate the Google Workspace admin-consent URL for a company — the link a customer's Super Admin visits to grant IRONSCALES access to their mail tenant. Produces a link only; nothing is connected until that person consents. The vendor spec declares no request body for this operation.
ironscales_generate_o365_consent_url details
ironscales_generate_o365_consent_url details
[IRONSCALES] Generate the Microsoft 365 admin-consent URL for a company — the link a customer's Global Administrator visits to grant IRONSCALES access to their mail tenant. This only PRODUCES a link: nothing is connected and no permission is granted until that person visits it and consents. Note this is the customer's Microsoft consent, not StackJack's own authentication to IRONSCALES, which is a separate API key. Provide a JSON object body with the redirect options the vendor's schema expects.
ironscales_get_integration_status details
ironscales_get_integration_status details
[IRONSCALES] Get the health of a company's mail-platform integration — whether IRONSCALES is currently connected to their Microsoft 365 or Google Workspace tenant, and in what state. This is the first thing to check when a company shows no incidents at all: a broken or never-completed integration looks exactly like a quiet mailbox.
Threat Feeds
ironscales_list_deepfake_events details
ironscales_list_deepfake_events details
[IRONSCALES] List a company's deepfake SIEM events — IRONSCALES' detections of synthetic voice or video impersonation, in the shape a SIEM forwarder wants. This feed CURSORS rather than pages: pass the highest id you have already seen as sinceId to get only what is new, which is what makes it safe to poll repeatedly. Alternatively filter by createdAfter. StackJack caps limit at 100.
ironscales_list_escalated_emails details
ironscales_list_escalated_emails details
[IRONSCALES] List a company's escalated emails — individual messages raised for attention, at message granularity rather than the incident granularity of ironscales_list_incidents. Filter by time window, recipient, threat type, classification (comma-separate several values for either) or the incident a message belongs to, and set isScanbackReport to isolate messages surfaced by a retro-scan. Paging uses page plus pageSize (capped at 100 by StackJack).
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team