API and webhooks

Manage employees, inject real security events and receive real-time notifications from your own tools.

How it works

What each surface covers

Employees API

List, create, update, delete. Campaign-event history per person. It is the program roster, not an eternal parallel directory: SCIM remains the happy path.

Custom events

An external security event is tied to an employee and hits the Human Risk Score like a simulation event. Without this door, the index only sees what Whalemate fired.

External Phishing Reports API

Phishing reports that did not come from the native button. The program can absorb a channel the SOC already has.

Webhooks, signature, retries, idempotency

Real-time outbound to your tools. Signature verification. Retries. Idempotency. Keys rotate. Generating and revoking in console is customer documentation.

The index and the events, in the tools you already use

Whalemate’s awareness API is not a promise portal

It is the declared set: Employees API (list, create, update, delete, campaign-event history), Custom Events API (external security events tied to an employee; they hit the Human Risk Score like a simulation event), External Phishing Reports API, and outbound webhooks with signature verification, retries and idempotency. Rotatable API keys. Technical documentation is the contract; here is why it exists.

The integrations hub names the API in a grid

This is the awareness API and the webhooks. We do not repeat SSO. We do not publish an invented OpenAPI or attack-payload examples.

Injecting a real event

The score does not live in a silo of “our drills only”.

What it is for

What it is for when the stack already exists

It is for IT that will not live inside Whalemate

It is for injecting the signal the SIEM already has. It is so the risk score is not a locked number. It is so you do not fake coverage of a contractor who only exists in another system: they enter through SCIM, or through API, or they do not enter.

It is not the “how to generate an API key” guide

The technical-doc link is below.

In the cycle

How it connects to integrations and analytics

Identity provisions. The API operates and notifies. The Human Risk Score — analytics pillar — consumes simulation events and injected events. We do not publish the Human Risk Score formula. It declares that a custom event counts like a campaign event. The integrations hub remains the map. Three children: identity, SCORM, API. There is no fourth URL for “webhooks” alone: they live here.

Questions

Questions about API and webhooks

Does a custom event move the Human Risk Score?
Yes. It is tied to an employee and hits like a simulation event. That is why that API exists.
Do webhooks have a signature and retries?
Yes. Signature verification, retries and idempotency are declared. Header detail is in the technical docs.
Can keys be rotated?
Yes. Rotatable. Generating and revoking in console is not documented as a marketing article.
Does it replace SCIM?
No. SCIM is the continuous roster. The API covers operation, events and reports. If the joiner can go through SCIM, it should go through SCIM.
Where is the technical documentation?
On roadmap.whalemate.com and in the material delivered at implementation. We do not clone the reference here.

Already a customer? See how it is configuredThe technical reference lives in customer documentation.

Connect the program to the tools you already have

In the demo we look at employees, events and webhooks on your case. No API-key playground here.