Partner API v2
Version 2 of the INFIMA Partner API gives partners, their clients' IT teams, and the vendors they work with read access to everything the INFIMA dashboard shows: clients, users, human risk, training, phishing, framework compliance, policies, Dark Web Monitoring, reports, and directory sync.
2.0 is read-only. Write endpoints and webhooks are listed under Coming in 2.x so you can plan for them; they return 404 until they ship.
v1 (/v1) keeps working unchanged for existing integrations. v1 reference
{
"data": [
{
"id": "3f2a9c1e-7b44-5d2e-9a1f-0c6d8e4b2a10",
"name": "Acme Manufacturing",
"risk": {
"average_score": 742,
"grade": "B",
"high_risk_users": 7
},
"frameworks": [
"hipaa",
"nist-csf"
]
}
],
"page": {
"next_cursor": "eyJ0IjoiMjAy…",
"has_more": true
}
}- 32
- Endpoints
- 13
- Resources
- read
- Scope needed
Quickstart
From key to client data in three requests
Everything below runs against production with a read-only key.
- 1
Get an API key
Send your API key in the
X-API-Keyheader on every request. Keys are generated in the partner dashboard under Settings → Integrations → API Keys.Settings → Integrations → API KeysPower BI nightly
ak_prod_3f2a••••••••••••
readAll clientsX-API-Key: $INFIMA_API_KEY - 2
Make your first request
Call
GET /v2/partner/api-key. Returns the title, scopes, and client access of the key used to make this request.curl "https://app.infimasecapis.com/v2/partner/api-key" \ -H "X-API-Key: $INFIMA_API_KEY" - 3
Page through your clients
Every list accepts
limit(default 100, max 500) andcursor. The response carriesdata(the page) andpage(next_cursor,has_more). Passnext_cursorback ascursorto get the next page.curl "https://app.infimasecapis.com/v2/clients?limit=100" \ -H "X-API-Key: $INFIMA_API_KEY" # Then pass page.next_cursor back as cursor until has_more is false curl "https://app.infimasecapis.com/v2/clients?limit=100&cursor=$NEXT_CURSOR" \ -H "X-API-Key: $INFIMA_API_KEY"
API reference
Resources
32 read endpoints across 13 resources, from your partner account down to a single user’s training and exposures.
Your partner account, its admins, and the key you are calling with.
- GET/v2/partner
- GET/v2/partner/admins
- GET/v2/partner/api-key
The organizations you manage. A client is a tenant in the INFIMA dashboard.
- GET/v2/clients
- GET/v2/clients/{client_id}
- GET/v2/clients/{client_id}/admins
The people enrolled in a client's program.
- GET/v2/clients/{client_id}/users
- GET/v2/users/{user_id}
Human risk score, grade, and the signals behind them.
- GET/v2/users/{user_id}/risk
- GET/v2/clients/{client_id}/risk
Curriculum, course catalog, and course assignments.
- GET/v2/users/{user_id}/training
- GET/v2/courses
- GET/v2/clients/{client_id}/training/curriculum
Admin-managed groups of users used as audiences for training, frameworks, and policies.
- GET/v2/clients/{client_id}/collections
- GET/v2/clients/{client_id}/collections/{collection_id}
- GET/v2/clients/{client_id}/collections/{collection_id}/members
Compliance frameworks assigned to a client and how the client measures against them.
- GET/v2/frameworks
- GET/v2/clients/{client_id}/frameworks
Simulation results, summaries, and the templates a client's simulations use.
- GET/v2/users/{user_id}/phishing
- GET/v2/clients/{client_id}/phishing/summary
- GET/v2/clients/{client_id}/phishing/results
Policy documents and sign-off tracking.
- GET/v2/clients/{client_id}/policies
- GET/v2/clients/{client_id}/policies/{policy_id}/acknowledgments
Dark Web Monitoring exposure data. Requires the feature to be enabled for the client.
- GET/v2/users/{user_id}/exposures
- GET/v2/clients/{client_id}/dark-web
- GET/v2/clients/{client_id}/dark-web/exposures
Generated PDF and Excel reports in the client's archive.
- GET/v2/clients/{client_id}/reports
- GET/v2/clients/{client_id}/reports/{report_id}
Directory sync status for Microsoft 365 and Google Workspace.
- GET/v2/clients/{client_id}/sync
Emails INFIMA has sent to a user (welcome, reminders, phishing simulations).
- GET/v2/users/{user_id}/emails
Guides
How the API behaves
The rules every endpoint follows, so one integration pattern covers the whole API.
Coming from v1?
What changed from v1
- One id scheme
- Resources, not verbs
- The platform's current shape
- Cursor pagination, date-range and updated_since filters
- Consistent errors, request ids, and rate-limit headers
Coming in 2.x
Specified so you can plan for them; not available in 2.0. Every operation here returns 404 until it ships. These are additive: nothing in 2.0 changes when they ship.
Writes
Create clients and users, manage collections, assign courses and frameworks, and send on-demand phishing.
Webhooks
Push notifications when things change, instead of polling.
Reported emails
The feed of real emails your clients’ users report.
MCP server
This same API, exposed to AI assistants.