Get started
API and integrations overview
Every way to get data in and out of HumanRisk Shield, which product each belongs to, and where its reference lives.
Each HRS product has its own API, keys and permissions. Pick the row that matches what you want to do.
| You want to | Use | Product |
|---|---|---|
| Pull people, ShieldScores, training, simulation and policy data into another system | HRS Learn REST API | HRS Learn |
| Get told when something happens, such as a click, a report or a score band change | Webhooks from HRS Learn | HRS Learn |
| Keep people in sync from your identity provider | SCIM 2.0: see Bring your people in | HRS Learn |
| Send security signals from your own tools into HRS | Signal webhook (below) | HRS Learn |
| Read cases, campaigns and indicators, or record verdicts | Triage REST API | HRS Triage |
| Send Triage verdicts and remediation to a SOAR or SIEM | Triage webhooks | HRS Triage |
| Feed confirmed indicators to a SIEM, TIP or firewall | TAXII 2.1 feed | HRS Triage |
| Pull exposure findings, domains and summaries | Exposure API, reference at exposure.humanriskshield.com/docs/api | HRS Exposure |
| Export a spreadsheet for a one-off report | CSV exports: see The API and exports | HRS Learn |
Keys and scope
Every key belongs to exactly one organization and can't reach another. A request for a record outside your organization gets "not found" rather than "forbidden", so a key can't even confirm another organization's records exist.
- HRS Learn: admins create keys at Settings → Access & security → API keys. The key is shown once.
- HRS Triage: each connected tool gets its own key. See Connect your tools with the REST API.
- HRS Exposure: Exposure admins create keys in Exposure's settings, under API keys.
Treat keys like passwords. Store them in a secrets manager, give each integration its own key, and revoke a key as soon as the system or person using it no longer needs it.
Sending signals into HRS Learn
Security tools such as a DLP or SIEM can post events to HRS Learn so they count toward people's risk and can trigger reinforcement. Admins manage these at /admin/reinforcement/webhooks (Reinforcement Webhooks). Each request is signed with an HMAC-SHA256 signature over the timestamp and body, sent in X-HRS-Signature and X-HRS-Timestamp, and refused if it is more than 5 minutes old.
Built-in connections
You don't need the API for the common connections. These are set up in HRS Learn without code, most of them under Integrations:
- Microsoft 365 and Google Workspace directory sync, and SCIM.
- Microsoft and Google sign-in, and SAML 2.0 single sign-on.
- Microsoft Defender for Office 365 signals.
- Slack and Microsoft Teams messages to people, for example a short note after a practice click or a thank-you for a report.
- The Report Phishing button for Outlook.
Some integrations depend on your plan. A card that isn't included says so and links to the plans.