The Human VectorSign in

API Documentation

The Human Vector has a REST API for phishing simulation and security awareness training: read people, groups and results, run directory syncs, create and send campaigns, draft templates with AI, register webhooks, and, for MSPs, manage client organizations. The REST API is part of the Pro plan.

Base URL

https://thehumanvector.io/api/v1

Authentication

Every request carries an API key as a Bearer token. Create a key in the console: gear menu → API Keys → Create Key, choose its permissions, and copy it (it is shown once).

curl -H "Authorization: Bearer $THV_API_KEY" https://thehumanvector.io/api/v1/campaigns

Errors are JSON: {"error": "code", "message": "..."}. A missing or revoked key returns 401, a key without the needed permission 403, an organization not on Pro 403 plan_required, too many requests 429 with Retry-After.

Specification

The full OpenAPI 3.1 specification, with every endpoint, parameter and response: https://thehumanvector.io/openapi.yaml. Most API tools and AI assistants can load it directly.

Permissions (scopes)

ScopeAllows
employees:readList people and their details.
employees:writeAdd, update and disable people, run directory syncs.
groups:readList groups and their members.
campaigns:readTemplates, campaigns and results.
campaigns:writeCreate, schedule and send campaigns, draft templates.
webhooks:readList webhook endpoints.
webhooks:writeAdd and remove webhook endpoints.
clients:readMSPs: list client organizations.
clients:writeMSPs: create client organizations.
keys:readList this organization's keys.
keys:writeCreate and revoke keys.

Endpoints

EndpointWhat it does
GET /employeesList people.
GET /groupsList groups.
GET /templatesList simulation templates.
POST /templates/generateDraft a simulation template with AI (a person reviews it before use).
GET /campaigns, POST /campaignsList and create campaigns.
GET /campaigns/{id}One campaign.
POST /campaigns/{id}/sendSend a campaign now.
POST /campaigns/{id}/scheduleSchedule a campaign.
GET /campaigns/{id}/statsOpens, clicks, submissions, reports and training.
POST /directory/syncSync people and groups from the connected directory.
GET /clients, POST /clientsMSPs: list and create client organizations.
GET /webhooks, POST /webhooksList and register webhook endpoints for events such as clicks and reports.
GET /api-keys, POST /api-keysList and create keys.

Paths are relative to the base URL. The specification is the complete, authoritative list.