Get started

API and integrations overview

Every way to get data in and out of HumanRisk Shield, which product each belongs to, and where its reference lives.

PublicUpdated October 6, 2026

Each HRS product has its own API, keys and permissions. Pick the row that matches what you want to do.

You want to Use Product
Pull people, ShieldScores, training, simulation and policy data into another system HRS Learn REST API HRS Learn
Get told when something happens, such as a click, a report or a score band change Webhooks from HRS Learn HRS Learn
Keep people in sync from your identity provider SCIM 2.0: see Bring your people in HRS Learn
Send security signals from your own tools into HRS Signal webhook (below) HRS Learn
Read cases, campaigns and indicators, or record verdicts Triage REST API HRS Triage
Send Triage verdicts and remediation to a SOAR or SIEM Triage webhooks HRS Triage
Feed confirmed indicators to a SIEM, TIP or firewall TAXII 2.1 feed HRS Triage
Pull exposure findings, domains and summaries Exposure API, reference at exposure.humanriskshield.com/docs/api HRS Exposure
Export a spreadsheet for a one-off report CSV exports: see The API and exports HRS Learn

Keys and scope

Every key belongs to exactly one organization and can't reach another. A request for a record outside your organization gets "not found" rather than "forbidden", so a key can't even confirm another organization's records exist.

  • HRS Learn: admins create keys at Settings → Access & security → API keys. The key is shown once.
  • HRS Triage: each connected tool gets its own key. See Connect your tools with the REST API.
  • HRS Exposure: Exposure admins create keys in Exposure's settings, under API keys.

Treat keys like passwords. Store them in a secrets manager, give each integration its own key, and revoke a key as soon as the system or person using it no longer needs it.

Sending signals into HRS Learn

Security tools such as a DLP or SIEM can post events to HRS Learn so they count toward people's risk and can trigger reinforcement. Admins manage these at /admin/reinforcement/webhooks (Reinforcement Webhooks). Each request is signed with an HMAC-SHA256 signature over the timestamp and body, sent in X-HRS-Signature and X-HRS-Timestamp, and refused if it is more than 5 minutes old.

Built-in connections

You don't need the API for the common connections. These are set up in HRS Learn without code, most of them under Integrations:

  • Microsoft 365 and Google Workspace directory sync, and SCIM.
  • Microsoft and Google sign-in, and SAML 2.0 single sign-on.
  • Microsoft Defender for Office 365 signals.
  • Slack and Microsoft Teams messages to people, for example a short note after a practice click or a thank-you for a report.
  • The Report Phishing button for Outlook.

Some integrations depend on your plan. A card that isn't included says so and links to the plans.

Still stuck?Contact support