# Riot

**Canonical:** https://apis.io/providers/riot/  
**Website:** https://tryriot.com/  
**APIs profiled:** 14

Riot is a Paris-based employee security posture management (human risk management) platform that helps companies reduce the human attack surface. The product suite spans phishing and smishing simulation, security awareness training courses, credential breach monitoring, employee-reported email triage (Inbox), inbound email protection (Slash), and third-party SaaS/drive exposure monitoring (Sonar), fronted by a chat assistant that runs in Slack, Microsoft Teams and the web portal. Riot publishes a public REST API (OpenAPI 3.1.1, x-api-key authentication, cursor pagination, scoped keys) that exposes organization, employee, group, course, campaign, attack, breach and inbox data, a SCIM 2.0 provisioning surface for user and group lifecycle, and Standard-Webhooks server-to-server events whose payloads follow the OCSF Detection Finding schema so they can be ingested by a SIEM or SOAR without custom mapping.

## Kin Score — 56.6 / 100 (strong)

Scored 2026-08-12 under rubric 0.11.0. Trend: flat (+0.0 from 56.6).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 66.0 |
| Governance | 20.8 |
| Operational Transparency | 55.3 |
| Developer Ergonomics | 45.1 |
| Commercial Clarity | 60.5 |

## Agent readiness — 57.0 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | documented |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (14)

- **Riot Awareness API** — Provides data about courses, their settings within the workspace and employees' learning progress.
- **Riot Breaches API** — The Breaches API from Riot — 3 operation(s) for breaches.
- **Riot General API** — Provides an overview of the organization and employees' data.
- **Riot Groups API** — The Groups API from Riot — 2 operation(s) for groups.
- **Riot Inbox API** — The Inbox API from Riot — 3 operation(s) for inbox.
- **Riot SCIM API** — The SCIM API from Riot — 9 operation(s) for scim.
- **Riot Simulation API** — Provides data about phishing campaigns, corresponding attacks and related events.
- **Riot Slash API** — The Slash API from Riot — 2 operation(s) for slash.
- **Riot Sonar API** — The Sonar API from Riot — 0 operation(s) for sonar.
- **Riot Team awareness API** — The Team awareness API from Riot — 4 operation(s) for team awareness.
- **Riot Team inbox API** — The Team inbox API from Riot — 5 operation(s) for team inbox.
- **Riot Team platform API** — The Team platform API from Riot — 15 operation(s) for team platform.
- **Riot Team simulation API** — The Team simulation API from Riot — 8 operation(s) for team simulation.
- **Riot Webhook Events API** — Server-to-server events Riot sends to customer-configured endpoints.

## MCP servers (1)

- **riot-mcp.yml**

## Agentic access (1)

- **Riot Agentic Access** — 40 operations · 9 acting

## Security (4)

- **Riot Authentication** — apiKey · 1 scheme
- **Riot Domain Security** — TLSv1.3 · HSTS · DMARC
- **Riot Vulnerability Disclosure** — security.txt · contact published
- **Riot Trust Center** — AICPA SOC 2 Type II, GDPR

## Tags

cybersecurity, security-awareness, human-risk-management, phishing-simulation, employee-security, security-posture-management, breach-detection, email-security, saas-security, scim, webhooks, ocsf, france

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/riot/). Scores are computed from the provider's own public artifacts under a published rubric.
