How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

IRONSCALES Settings API

The Settings API from IRONSCALES — 4 operation(s) for settings.

IRONSCALES Settings API is one of 10 APIs that IRONSCALES publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Settings. The published artifact set on APIs.io includes an OpenAPI specification, an API reference, API documentation, authentication docs, and rate-limit docs.

This API exposes 14 operations across 4 paths, and defines 8 schemas. It is described by OpenAPI 3.2.0, at version v1.

Requests are made against a single base URL, https://appapi.ironscales.com/appapi.

14 operations 4 paths 8 schemas 3 DELETE4 GET3 POST4 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v1
Base URL
https://appapi.ironscales.com/appapi
Authentication
API Key
Resource Areas
1

Authentication & Security 1

IRONSCALES Settings API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (JWT). By default, every request must be authenticated.

Paths & Operations 14

Across 4 paths, the API surfaces 14 operations — 3 DELETE, 4 GET, 3 POST, 4 PUT. Each is listed below with its method, path, parameters, and response codes.

Settings 14
GET
/settings/{company_id}/account-takeover/
Retrieve the account takeover sensitivity settings for the specified company. Sensitivity Options: 1 (Aggressive): Most sensitive - requires fewer alerts to trigger an incident 2 (Balanced): Default…
Get account takeover sensitivity settings 1 param → 200404403429
PUT
/settings/{company_id}/account-takeover/
Update account takeover sensitivity settings for the specified company. Sensitivity Options: 1 (Aggressive): Most sensitive - requires fewer alerts to trigger an incident 2 (Balanced): Default sensit…
Update account takeover sensitivity settings 1 param body → 200400404403429
GET
/settings/{company_id}/allow-list/
Retrieve the list of allow list settings for the specified company. Scopes: company.all company.view
Get allow list settings 7 params → 200404403400429
POST
/settings/{company_id}/allow-list/
Add a new entry to the allow list for the specified company. Scopes: company.all company.edit
Create allow list settings 1 param body → 204404403400429
PUT
/settings/{company_id}/allow-list/
Update an existing allow list entry for the specified company. Scopes: company.all company.edit
Update allow list entry 1 param body → 204404403400429
DELETE
/settings/{company_id}/allow-list/
Delete selected entries from the allow list for the specified company. Scopes: company.all company.edit
Delete allow list entries 1 param body → 204404403400429
GET
/settings/{company_id}/challenged-alerts/
Retrieve the list of email recipients configured for challenged alert notifications for the specified company. Scopes: company.all company.view
Get challenged notification settings 1 param → 200404403429
POST
/settings/{company_id}/challenged-alerts/
Set the list of email recipients configured for challenged alert notifications for the specified company. Scopes: company.all company.edit
Create challenged notification settings 1 param body → 200404403400429
PUT
/settings/{company_id}/challenged-alerts/
Append email recipients to existing challenged alert notifications, removing duplicates, returning the updated list. Scopes: company.all company.edit
Append challenged notification settings 1 param body → 200404403400429
DELETE
/settings/{company_id}/challenged-alerts/
Remove all configured email recipients for challenged alert notifications. After deletion, the recipients list will be empty. Scopes: company.all company.edit
Delete challenged notification settings 1 param → 204404403429
GET
/settings/{company_id}/incident-alerts/
Retrieve the list of email recipients configured for incident alert notifications for the specified company. Scopes: company.all company.view
Get company notification settings 1 param → 200404403429
POST
/settings/{company_id}/incident-alerts/
Set the list of email recipients for incident alert notifications, replacing any existing recipients. Scopes: company.all company.edit
Create company notification settings 1 param body → 200404403400429
PUT
/settings/{company_id}/incident-alerts/
Append email recipients to the existing notification settings list, removing duplicates, returning the updated list. Scopes: company.all company.edit
Append to company notification settings 1 param body → 200404403400429
DELETE
/settings/{company_id}/incident-alerts/
Remove all configured email recipients for incident alert notifications. After deletion, the recipients list will be empty. Scopes: company.all company.edit
Delete company notification settings 1 param → 204404403429

Schemas 8

The contract defines 8 schemas that model the data the API accepts and returns. The most detailed are WhiteListEntry (11 properties), WhitelistUpdateRow (7 properties), WhitelistAddRow (6 properties), WhiteListResponse (6 properties). Each schema is shown below with its type and property counts.

AccountTakeoverSettings
object
1 property 1 required
WhitelistUpdateRow
object
7 properties 3 required
WhiteListResponse
object
6 properties 6 required
NotificationSettings
object
1 property 1 required
WhiteListEntry
object
List of allowed entries
11 properties 11 required
ChallengedSettings
object
1 property 1 required
WhitelistAddRow
object
6 properties 2 required
WhiteListDelete
object
1 property 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

ironscales-settings-api-openapi.yml Raw ↑

Other APIs IRONSCALES publishes across the network.

IRONSCALES MCP Server
IRONSCALES Authorization API
IRONSCALES Campaigns API
IRONSCALES Deepfake API
IRONSCALES Emails API
IRONSCALES Incident API
IRONSCALES Mailboxes API
IRONSCALES Mitigation API
IRONSCALES SAT API
Where this information came from

This is an independent, third-party profile of IRONSCALES Settings API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.