IRONSCALES
IRONSCALES is an AI-powered, API-based email security platform protecting organizations against phishing, business email compromise (BEC), account takeover (ATO), VIP impersonation, QR-code phishing, malicious URLs and attachments, and deepfake-assisted social engineering. Rather than sitting inline as a secure email gateway, IRONSCALES connects to Microsoft 365 and Google Workspace through their APIs and operates at the mailbox level — no MX record changes — combining adaptive AI detection, computer-vision analysis, automated multi-mailbox remediation, a crowdsourced threat-intelligence network, phishing simulation testing, and security awareness training in one platform. The public IRONSCALES Management API (appapi.ironscales.com) exposes incidents, mitigation statistics, escalated emails, mailbox management, deepfake SIEM events, phishing-simulation campaigns, SAT training campaigns, and tenant security settings, and is the surface behind the company's SIEM/SOAR/XDR integrations. IRONSCALES also operates an OAuth-protected remote MCP server for agent-based access.
IRONSCALES publishes 9 APIs on the APIs.io network, including Authorization API, Campaigns API, Deepfake API, and 6 more. Tagged areas include email-security, cybersecurity, phishing, anti-phishing, and business-email-compromise.
IRONSCALES’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, signup flow, and 28 more developer resources.
Kin Score
APIs 10
Individual APIs this provider publishes, each with its own machine-readable definition.
IRONSCALES MCP Server
Remote Model Context Protocol server operated by IRONSCALES at mcp.ironscales.com, served over streamable HTTP at /mcp/. Access is OAuth 2.0 protected — an unauthenticated tools...
IRONSCALES Authorization API
The Authorization API from IRONSCALES — 1 operation(s) for authorization.
IRONSCALES Campaigns API
The Campaigns API from IRONSCALES — 3 operation(s) for campaigns.
IRONSCALES Deepfake API
The Deepfake API from IRONSCALES — 1 operation(s) for deepfake.
IRONSCALES Emails API
The Emails API from IRONSCALES — 1 operation(s) for emails.
IRONSCALES Incident API
The Incident API from IRONSCALES — 10 operation(s) for incident.
IRONSCALES Mailboxes API
The Mailboxes API from IRONSCALES — 3 operation(s) for mailboxes.
IRONSCALES Mitigation API
The Mitigation API from IRONSCALES — 8 operation(s) for mitigation.
IRONSCALES SAT API
The SAT API from IRONSCALES — 15 operation(s) for sat.
IRONSCALES Settings API
The Settings API from IRONSCALES — 4 operation(s) for settings.
Scroll for all 10
Open Collections 10
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONIRONSCALES Management Authorization API
OPEN COLLECTIONIRONSCALES Management Campaigns API
OPEN COLLECTIONIRONSCALES Management Deepfake API
OPEN COLLECTIONIRONSCALES Management Emails API
OPEN COLLECTIONIRONSCALES Management Incident API
OPEN COLLECTIONIRONSCALES Management Mailboxes API
OPEN COLLECTIONIRONSCALES Management Mitigation API
OPEN COLLECTIONIRONSCALES Management SAT API
OPEN COLLECTIONIRONSCALES Management Settings API
OPEN COLLECTIONScroll for all 10
MCP Servers 2
Model Context Protocol servers that expose these APIs to AI agents.
ironscales-mcp.yml
MCP SERVERmcp
MCP SERVERRate Limits 1
Documented rate limits and quota policies.
Ironscales Rate Limits
RATE LIMITSSecurity Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 5
Pagination, idempotency, versioning, errors, and events
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 7
Authentication, authorization, and security posture
Scroll for all 7
Operate 6
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type