How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

IRONSCALES Mitigation API

The Mitigation API from IRONSCALES — 8 operation(s) for mitigation.

IRONSCALES Mitigation API is one of 10 APIs that IRONSCALES publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Mitigation. The published artifact set on APIs.io includes an OpenAPI specification, an API reference, API documentation, authentication docs, and rate-limit docs.

This API exposes 9 operations across 8 paths, and defines 21 schemas. It is described by OpenAPI 3.2.0, at version v1.

Requests are made against a single base URL, https://appapi.ironscales.com/appapi.

9 operations 8 paths 21 schemas 7 GET2 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v1
Base URL
https://appapi.ironscales.com/appapi
Authentication
API Key
Resource Areas
1

Authentication & Security 1

IRONSCALES Mitigation API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (JWT). By default, every request must be authenticated.

Paths & Operations 9

Across 8 paths, the API surfaces 9 operations — 7 GET, 2 POST. Each is listed below with its method, path, parameters, and response codes.

Mitigation 9
POST
/mitigation/{company_id}/details/
Get details of mitigations per mailbox Scopes: partner.all partner.company.view company.view Period values: 0 - Last 24 hours 1 - Last 7 days 2 - Last 90 days 3 - Last 180 days 4 - Last 360 days 5 -…
Get details of mitigations per mailbox 2 params body → 200400404403
GET
/mitigation/{company_id}/impersonation/details/
Get the latest company impersonation incidents Results are limited to the latest 1000 incidents, a message will appear displaying if the amount of incidents in the period is over this limit Please no…
Get the latest company impersonation incidents 3 params → 200400404403
POST
/mitigation/{company_id}/impersonation/details/
Get the latest company impersonation paginated incidents Please note that the IDs returned here are of impersonation attempts, not incidents or reports, so searching these IDs in other endpoints will…
Get the latest company impersonation paginated incidents 2 params body → 200400404403
GET
/mitigation/{company_id}/incidents/details/
Get a company mitigation details Scopes: partner.all partner.company.view company.view Period values: 0 - Last 24 hours 1 - Last 7 days 2 - Last 90 days 3 - Last 180 days 4 - Last 360 days 5 - Curren…
Get a company mitigation details 4 params → 200400404403
GET
/mitigation/{company_id}/stats/
Get a company mitigation statistics Scopes: partner.all partner.company.view company.view Period values: 0 - Last 24 hours 1 - Last 7 days 2 - Last 90 days 3 - Last 180 days 4 - Last 360 days 5 - Cur…
Get a company mitigation statistics 3 params → 200400404403
GET
/mitigation/{company_id}/stats/emails/
Rate Limit : 20 requests per second Scopes: company.view
Get emails stats 4 params → 200400404403429
GET
/mitigation/{company_id}/stats/most-targeted-departments/
Returns top 5 most targeted departments within requested timeframe Rate Limit : 20 requests per second Scopes: company.view
Most targeted departments 4 params → 200400404403429
GET
/mitigation/{company_id}/stats/most-targeted-employees/
Returns top 5 most targeted employees within requested timeframe Rate Limit : 20 requests per second Scopes: company.view
Most targeted employees 4 params → 200400404403429
GET
/mitigation/{company_id}/stats/v2/
Get a company mitigation statistics V2 Scopes: partner.all partner.company.view company.view Period values: 0 - Last 24 hours 1 - Last 7 days 2 - Last 90 days 3 - Last 180 days 4 - Last 360 days 5 -…
Get a company mitigation statistics V2 3 params → 200400404403

Schemas 21

The contract defines 21 schemas that model the data the API accepts and returns. The most detailed are MailboxesDetails (14 properties), MitigationDetails (12 properties), MitigationIncidentDetails (11 properties), ImpersonationDetails (10 properties). Each schema is shown below with its type and property counts.

MitigationStats
object
8 properties 8 required
MitigationPageDetails
object
4 properties 4 required
MostTargetedEmployees
object
1 property 1 required
ResolvedByAnalyst
object
6 properties
IncidentPageDetails
object
4 properties 4 required
ImpersonationDetails
object
10 properties 10 required
IncidentDetailsRequest
object
3 properties 1 required
EmailsStats
object
5 properties 5 required
MitigationStatsV2View
object
4 properties
ImpersonationDetailsRequest
object
2 properties
MostTargetedEmployee
object
2 properties
InspectedEmails
object
5 properties 5 required
MailboxesDetails
object
14 properties 13 required
MostTargetedDepartment
object
2 properties 2 required
MostTargetedDepartments
object
1 property 1 required
MitigationIncidentDetails
object
11 properties 11 required
ResolvedAutomatically
object
8 properties 8 required
EmailPhishingThreatTypeStats
object
2 properties 2 required
ImpersonationDetailsPage
object
4 properties 2 required
MaliciousContentIncidents
object
4 properties 4 required
MitigationDetails
object
12 properties 12 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

ironscales-mitigation-api-openapi.yml Raw ↑

Other APIs IRONSCALES publishes across the network.

IRONSCALES MCP Server
IRONSCALES Authorization API
IRONSCALES Campaigns API
IRONSCALES Deepfake API
IRONSCALES Emails API
IRONSCALES Incident API
IRONSCALES Mailboxes API
IRONSCALES SAT API
IRONSCALES Settings API
Where this information came from

This is an independent, third-party profile of IRONSCALES Mitigation API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.