How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

IRONSCALES Incident API

The Incident API from IRONSCALES — 10 operation(s) for incident.

IRONSCALES Incident API is one of 10 APIs that IRONSCALES publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Incident. The published artifact set on APIs.io includes an OpenAPI specification, an API reference, API documentation, authentication docs, and rate-limit docs.

This API exposes 10 operations across 10 paths, and defines 28 schemas. It is described by OpenAPI 3.2.0, at version v1.

Requests are made against a single base URL, https://appapi.ironscales.com/appapi.

10 operations 10 paths 28 schemas 6 GET4 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v1
Base URL
https://appapi.ironscales.com/appapi
Authentication
API Key
Resource Areas
1

Authentication & Security 1

IRONSCALES Incident API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (JWT). By default, every request must be authenticated.

Paths & Operations 10

Across 10 paths, the API surfaces 10 operations — 6 GET, 4 POST. Each is listed below with its method, path, parameters, and response codes.

Incident 10
GET
/incident/{company_id}/account-takeover/{incident_id}/details/
Retrieve detailed information about a specific Account Takeover incident. Query Parameters: page: Page number for pagination (default: 1) itemsperpage: Number of items per page (min: 1, max: 500, def…
Get Account Takeover incident details 7 params → 200400403404
POST
/incident/{company_id}/account-takeover/{incident_id}/remediation/
Create remediation for the specified Account Takeover incident. State Options: 2 (Safe): Mark the incident as safe/false positive 3 (Compromised): Mark the incident as compromised and apply remediati…
Create Account Takeover remediation 2 params body → 200400404403429
POST
/incident/{company_id}/classify/{incident_id}
Classify specific incident Scopes: partner.company.classify company.classify
Classify specific incident 4 params body → 200400404403
GET
/incident/{company_id}/details/{incident_id}
Get details of specific incident Scopes: partner.all partner.company.view company.view
Get details of specific incident 4 params → 200404403
GET
/incident/{company_id}/list/
List of Incidents Scopes: partner.all company.all partner.company.view company.view
Get list of Incidents 23 params → 200400404403
POST
/incident/{company_id}/recluster/{incident_id}
Recluster (revert) mitigations back to the original incident they were unclustered from. This reverses a previous uncluster operation by moving mitigations back to their original incident. Scopes: pa…
Recluster incident 4 params body → 200400404403
GET
/incident/{company_id}/scanback-list/
List of Incidents Scopes: partner.all company.all partner.company.view company.view
Get list of Scanback Incidents 19 params → 200400404403
GET
/incident/{company_id}/stats/remediation-statuses/
Rate Limit : 20 requests per second Scopes: company.view
Remediation statuses stats 4 params → 200400404403429
POST
/incident/{company_id}/uncluster/{incident_id}
Uncluster mitigations from an incident to create a new incident with a different classification. Scopes: partner.company.classify company.classify
Uncluster incident 4 params body → 200400404403
GET
/incident/{company_id}/{status}/
Get ids of open incidents Scopes: partner.all partner.company.view company.view Status: open
Get IDs list of unclassified incidents 3 params → 200404403

Schemas 28

The contract defines 28 schemas that model the data the API accepts and returns. The most detailed are IncidentDetails (41 properties), IncidentList (22 properties), ScanBackList (16 properties), AccountTakeoverIncidentDetails (9 properties). Each schema is shown below with its type and property counts.

AccountTakeoverDetailsResponse
object
5 properties 5 required
AccountTakeoverRemediation
object
2 properties 1 required
AccountTakeoverRemediationResponse
object
1 property 1 required
ScanBackPage
object
4 properties 4 required
FederationDetails
object
6 properties 6 required
IncidentDetails
object
41 properties 41 required
AffectedMailbox
object
List of affected mailboxes (mitigations) for this incident
7 properties 7 required
Header
object
2 properties 2 required
IncidentListPage
object
4 properties 4 required
IncidentClassification
object
3 properties 3 required
ReportedEmail
object
6 properties 6 required
FilterOptions
object
Available filter options
3 properties 3 required
AccountTakeoverIncidentDetails
object
Account takeover incident details
9 properties 9 required
AlertDetail
object
List of alert details
3 properties 3 required
IncidentList
object
22 properties 22 required
Attachment
object
4 properties 4 required
Alert
object
List of security alerts
6 properties 6 required
ReclusterIncident
object
5 properties
MailServer
object
2 properties 2 required
IncidentComment
object
Comments on the incident, across the internal and community threads.
5 properties 5 required
Assignee
object
Assigned user information
4 properties 4 required
ScanBackList
object
16 properties 16 required
RemediationStatusStats
object
2 properties 2 required
AccountTakeoverRemediationError
object
1 property 1 required
AccountDetails
object
Account information
6 properties 6 required
RemediationStatusesStats
object
4 properties 4 required
Link
object
3 properties 3 required
UnclusterIncident
object
6 properties 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

ironscales-incident-api-openapi.yml Raw ↑

Other APIs IRONSCALES publishes across the network.

IRONSCALES MCP Server
IRONSCALES Authorization API
IRONSCALES Campaigns API
IRONSCALES Deepfake API
IRONSCALES Emails API
IRONSCALES Mailboxes API
IRONSCALES Mitigation API
IRONSCALES SAT API
IRONSCALES Settings API
Where this information came from

This is an independent, third-party profile of IRONSCALES Incident API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.