- One id scheme
- Every object you can address is addressed by its INFIMA id, an opaque string (clients, users, admins, collections, policies, reports, and so on). v1 mixed numeric client ids with string user ids. Never parse or construct an id. Records you only read in lists, such as phishing results, training assignments, and sent emails, have no id.
- Resources, not verbs
POST /sendphishingbecomesPOST /clients/{client_id}/phishing/sends,POST /sentemailsbecomesGET /users/{user_id}/emails, and updates usePATCH.- The platform's current shape
- Human risk score and grade, framework compliance, Dark Web Monitoring, policies, collections, reported real phishing, and directory sync status are first-class. Click rate and on-track rate are still there but no longer the headline.
- Cursor pagination, date-range and
updated_sincefilters - on every list, so nightly ETL jobs pull only what changed.
- Consistent errors, request ids, and rate-limit headers
- on every response.
- Partner API v2
- Guides
- What changed from v1
Guide
What changed from v1
One id scheme, resource-style paths, cursor pagination, and the platform’s current shape.