How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Riot Inbox API

The Inbox API from Riot — 3 operation(s) for inbox.

Riot Inbox API is one of 9 APIs that Riot publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Inbox. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, and rate-limit docs.

This API exposes 3 operations across 3 paths, and defines 38 schemas. It is described by OpenAPI 3.2.0, at version v1.

Requests are made against a single base URL, https://public-api.tryriot.com/.

3 operations 3 paths 38 schemas 2 GET1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v1
Base URL
https://public-api.tryriot.com/v1
Authentication
API Key
Resource Areas
1

Authentication & Security 1

Riot Inbox API declares 1 security scheme for authenticating requests. An API key is passed in the header as x-api-key (apiKeyAuth). By default, every request must be authenticated.

Paths & Operations 3

Across 3 paths, the API surfaces 3 operations — 2 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Inbox 3
POST
/v1/email_reports/report_attack_from_message_id
Report a phishing simulation attack by Message-ID
reports_report_attack_from_message_id_DO4XYPA body → 200401403422429
GET
/v1/inbox_tickets/list_employees_with_email_reports
List employees with email reports statistics
inbox_tickets_list_employees_with_email_reports_QHKH7RI 7 params → 200401403404422429
GET
/v1/inbox_tickets/statistics
Get inbox statistics
inbox_tickets_get_inbox_statistics_QHKH7RI 3 params → 200401403404422429

Schemas 38

The contract defines 38 schemas that model the data the API accepts and returns. The most detailed are InboxEmailAnalysisClassifiedData (20 properties), TicketsStatistics (6 properties), InboxEmailAnalysisClassifiedUnmappedRiot (6 properties), InboxEmailAnalysisClassifiedExplanation (6 properties). Each schema is shown below with its type and property counts.

SeverityName
string
OCSF severity name.
ReportsStatistics
object
3 properties 3 required
PaginatedEmployeeWithReportsPayload
object
2 properties 2 required
ReportSource
string
How the email was reported.
InboxEmailAnalysisClassifiedAnalytic
object
2 properties 2 required
InboxEmailAnalysisClassifiedProductFeature
object
1 property 1 required
WorkspaceNotFoundErrorResponse
object
1 property 1 required
DetectionType
string
Detection type derived from the verdict.
InboxEmailAnalysisClassifiedFindingInfo
object
4 properties 4 required
ObservableType
string
OCSF observable type name.
InboxEmailAnalysisClassifiedUnmappedRiot
object
6 properties 4 required
ForbiddenErrorResponse
object
1 property 1 required
SeverityId
integer
OCSF severity id derived from the verdict: 1 (safe), 2 (spam), 4 (fraudulent).
InboxEmailAnalysisClassifiedExplanation
object
6 properties 6 required
ExplanationSource
string
Signal source identifier.
InboxEmailAnalysisClassifiedUser
object
2 properties 1 required
GetInboxStatisticsResponse
object
2 properties 2 required
ReportAttackFromMessageIdRequest
object
1 property 1 required
InboxEmailAnalysisClassifiedEmail
object
3 properties
InboxEmailAnalysisClassifiedEvidence
object
1 property 1 required
UnauthorizedErrorResponse
object
1 property 1 required
ObservableTypeId
integer
OCSF observable type id. 5 for Email Address, 7 for File.
InboxEmailAnalysisClassifiedMetadata
object
4 properties 4 required
InboxEmailAnalysisClassifiedActor
object
1 property 1 required
InboxEmailAnalysisClassifiedObservable
object
3 properties 3 required
RateLimitExceededErrorResponse
object
1 property 1 required
InboxEmailAnalysisClassifiedProduct
object
3 properties 3 required
InboxEmailAnalysisClassifiedEvent
object
3 properties 3 required
EmployeeOverviewSchema
object
4 properties 4 required
FraudulentTicketsStatistics
object
5 properties 5 required
UnprocessableContentErrorResponse
object
1 property 1 required
TicketsStatistics
object
6 properties 5 required
InboxEmailAnalysisClassifiedData
object
20 properties 17 required
EmailsReportedStatsSchema
object
4 properties 4 required
InboxEmailAnalysisClassifiedUnmapped
object
1 property 1 required
AnalysisStatus
string
Final verdict assigned to the email.
ReportAttackFromMessageIdResponse
object
3 properties 3 required
ExplanationSentiment
string
Sentiment carried by the signal.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

riot-inbox-api-openapi.yml Raw ↑

Other APIs Riot publishes across the network.

Riot Awareness API
Riot Breaches API
Riot General API
Riot Groups API
Riot SCIM API
Riot Simulation API
Riot Slash API
Riot Sonar API
Where this information came from

This is an independent, third-party profile of Riot Inbox API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.