Abnormal AI Employee Insights API

API to manage employees

Operations 3

GET /employee/{email_address} Get employee information #
GET /employee/{email_address}/identity Get employee identity analysis (Genome) data #
GET /employee/{email_address}/logins Get employee login information for last 30 days in csv format #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/abnormal-employee-insights-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

abnormal-employee-insights-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Abnormal Security Client Employee Insights API
  version: 1.4.3
  description: This is the specification for Abnormal Security Client API which can be used for managing security threats detected by Abnormal Security.
  termsOfService: https://legal.abnormalsecurity.com/legal-hub/abnormal-security-api-terms-of-service-6feee5e3
  contact:
    name: Abnormal Security Support
    email: support@abnormalsecurity.com
servers:
- url: https://api.abnormalplatform.com/v1
  description: Production Server for managing threats
- url: https://eu.rest.abnormalsecurity.com/v1
  description: EU Production Server for managing threats.
security:
- BearerAuth: []
tags:
- name: Employee Insights
  description: API to manage employees
paths:
  /employee/{email_address}:
    get:
      operationId: v1_employee_retrieve
      summary: Get employee information
      parameters:
      - in: header
        name: mock-data
        schema:
          type: string
          default: 'False'
          enum:
          - 'False'
          - 'True'
        description: Returns test data if set to `True`
      - in: path
        name: email_address
        schema:
          type: string
        description: Email address of the employee you want to retrieve data for
        required: true
      tags:
      - Employee Insights
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EmployeeDetails'
          description: Employee information for provided email address
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '403':
          $ref: '#/components/responses/ForbiddenError'
        '404':
          $ref: '#/components/responses/NotFoundError'
        '429':
          $ref: '#/components/responses/TooManyRequestsError'
  /employee/{email_address}/identity:
    get:
      operationId: v1_employee_identity_retrieve
      summary: Get employee identity analysis (Genome) data
      parameters:
      - in: header
        name: mock-data
        schema:
          type: string
          default: 'False'
          enum:
          - 'False'
          - 'True'
        description: Returns test data if set to `True`
      - in: path
        name: email_address
        schema:
          type: string
        description: Email address of the employee you want to retrieve data for
        required: true
      tags:
      - Employee Insights
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EmployeeIdentityDetails'
          description: Employee identity analysis data derived from employee login data.
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '403':
          $ref: '#/components/responses/ForbiddenError'
        '404':
          $ref: '#/components/responses/NotFoundError'
        '429':
          $ref: '#/components/responses/TooManyRequestsError'
  /employee/{email_address}/logins:
    get:
      operationId: v1_employee_logins_retrieve
      summary: Get employee login information for last 30 days in csv format
      parameters:
      - in: path
        name: email_address
        schema:
          type: string
        description: Email address of the employee you want to retrieve data for
        required: true
      - in: header
        name: mock-data
        schema:
          type: string
          default: 'False'
          enum:
          - 'False'
          - 'True'
        description: Returns test data if set to `True`
      tags:
      - Employee Insights
      responses:
        '200':
          content:
            text/csv:
              schema:
                type: string
                example: Timestamp,User Principal Name,User Display Name,Status,IP Address,City,State,Country or Region,Latitude,Longitude,App Display Name,App ID,Client App Used,Browser,Operating System,Device ID,Resource Display Name
          description: A csv list of employee login information. Headers of the csv include the following in order:<br />- Timestamp<br />- User Principal Name<br />- User Display Name<br />- Status<br />- IP Address<br />- City<br />- State<br />- Country or Region<br />- Latitude<br />- Longitude<br />- App Display Name<br />- App ID<br />- Client App Used<br />- Browser<br />- Operating System<br />- Device ID<br />- Resource Display Name
        '401':
          content:
            text/csv:
              schema:
                $ref: '#/components/responses/UnauthorizedError'
          description: ''
        '403':
          content:
            text/csv:
              schema:
                $ref: '#/components/responses/ForbiddenError'
          description: ''
        '404':
          content:
            text/csv:
              schema:
                $ref: '#/components/responses/NotFoundError'
          description: ''
        '429':
          content:
            text/csv:
              schema:
                $ref: '#/components/responses/TooManyRequestsError'
          description: ''
components:
  responses:
    TooManyRequestsError:
      description: Request count exceeds allowed number of concurrent requests for this resource type
    ForbiddenError:
      description: Access to the resource is forbidden (e.g. IP not in allowlist)
    UnauthorizedError:
      description: Access token is missing or invalid
    NotFoundError:
      description: Invalid user input when using the filter query parameter. Will return various error messages
  schemas:
    EmployeeIdentityDetails:
      type: object
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/EmployeeGenomeDetails'
      required:
      - data
    EmployeeDetails:
      type: object
      properties:
        name:
          type: string
          description: Name of the employee.
          example: Tom
        email:
          type: string
          description: Email of the employee.
          example: example@example.com
        title:
          type: string
          description: Job title of the employee.
          example: General Manager
        manager:
          type: string
          description: Email address of the employee's manager
          example: manager_email@example.com
      required:
      - email
      - manager
      - name
      - title
    EmployeeGenomeCategory:
      type: object
      properties:
        value:
          type: string
          description: Category value
          example: 203.12.172.182
        percentage:
          type: number
          format: double
          description: Ratio of this category relative to others
          example: 0.9
        total_count:
          type: integer
          description: Number of occurences for this category
          example: 9
      required:
      - percentage
      - total_count
      - value
    EmployeeGenomeDetails:
      type: object
      properties:
        key:
          type: string
          description: Genome key name
          example: ip_address
        name:
          type: string
          description: Genome title
          example: Common IP Addresses
        description:
          type: string
          description: Description of genome object
          example: Common IP Addresses for user logins
        values:
          type: array
          items:
            $ref: '#/components/schemas/EmployeeGenomeCategory'
      required:
      - description
      - key
      - name
      - values
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer