Riot
Riot is a Paris-based employee security posture management (human risk management) platform that helps companies reduce the human attack surface. The product suite spans phishing and smishing simulation, security awareness training courses, credential breach monitoring, employee-reported email triage (Inbox), inbound email protection (Slash), and third-party SaaS/drive exposure monitoring (Sonar), fronted by a chat assistant that runs in Slack, Microsoft Teams and the web portal. Riot publishes a public REST API (OpenAPI 3.1.1, x-api-key authentication, cursor pagination, scoped keys) that exposes organization, employee, group, course, campaign, attack, breach and inbox data, a SCIM 2.0 provisioning surface for user and group lifecycle, and Standard-Webhooks server-to-server events whose payloads follow the OCSF Detection Finding schema so they can be ingested by a SIEM or SOAR without custom mapping.
Riot publishes 14 APIs on the APIs.io network, including Awareness API, Breaches API, General API, and 11 more. Tagged areas include cybersecurity, security-awareness, human-risk-management, phishing-simulation, and employee-security.
The Riot catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Riot’s developer surface includes documentation, API reference, engineering blog, support, pricing, changelog, authentication, and 29 more developer resources.
Kin Score
APIs 14
Individual APIs this provider publishes, each with its own machine-readable definition.
Riot Awareness API
Provides data about courses, their settings within the workspace and employees' learning progress.
Riot Breaches API
The Breaches API from Riot — 3 operation(s) for breaches.
Riot General API
Provides an overview of the organization and employees' data.
Riot Groups API
The Groups API from Riot — 2 operation(s) for groups.
Riot Inbox API
The Inbox API from Riot — 3 operation(s) for inbox.
Riot SCIM API
The SCIM API from Riot — 9 operation(s) for scim.
Riot Simulation API
Provides data about phishing campaigns, corresponding attacks and related events.
Riot Slash API
The Slash API from Riot — 2 operation(s) for slash.
Riot Sonar API
The Sonar API from Riot — 0 operation(s) for sonar.
Riot Team awareness API
The Team awareness API from Riot — 4 operation(s) for team awareness.
Riot Team inbox API
The Team inbox API from Riot — 5 operation(s) for team inbox.
Riot Team platform API
The Team platform API from Riot — 15 operation(s) for team platform.
Riot Team simulation API
The Team simulation API from Riot — 8 operation(s) for team simulation.
Riot Webhook Events API
Server-to-server events Riot sends to customer-configured endpoints.
Scroll for all 14
MCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
riot-mcp.yml
MCP SERVERRate Limits 1
Documented rate limits and quota policies.
Riot Rate Limits
RATE LIMITSEvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Riot Webhooks
ASYNCAPISecurity Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes governing access to this provider's APIs.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 2
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 7
Pagination, idempotency, versioning, errors, and events
Scroll for all 7
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 8
Authentication, authorization, and security posture
Scroll for all 8
Operate 5
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type