KnowBe4 Security Awareness Training API

KnowBe4 REST API for security awareness training and simulated phishing platform. Enables AI agents to manage phishing simulation campaign creation and scheduling, handle training enrollment and completion tracking, access user risk scoring and phishing-prone percentage (PPP) data, retrieve training content catalog and assignment management, manage user and group provisioning, handle phishing simulation results and click rate analytics, access compliance training completion for regulatory requirements, retrieve human risk score trending and improvement metrics, manage remediation training assignment for failed phishing tests, and integrate security awareness data with SIEM, HR, and security orchestration platforms.

Evaluated Mar 06, 2026 (0d ago) vcurrent
Homepage ↗ Repo ↗ Developer Tools knowbe4 security-awareness phishing-simulation compliance-training human-risk sat vishing
⚙ Agent Friendliness
64
/ 100
Can an agent use this?
🔒 Security
74
/ 100
Is it safe for agents?
⚡ Reliability
73
/ 100
Does it work consistently?

Score Breakdown

⚙ Agent Friendliness

MCP Quality
22
Documentation
80
Error Messages
75
Auth Simplicity
85
Rate Limits
70

🔒 Security

TLS Enforcement
92
Auth Strength
72
Scope Granularity
62
Dep. Hygiene
70
Secret Handling
72

Security awareness training. SOC2, ISO27001, GDPR. API token. US/EU. Employee risk scores and phishing simulation data.

⚡ Reliability

Uptime/SLA
75
Version Stability
78
Breaking Changes
70
Error Recovery
70
AF Security Reliability

Best When

An enterprise using KnowBe4 wants AI agents to automate phishing simulation scheduling, training assignment for failed tests, risk score tracking, compliance reporting, and HR integration.

Avoid When

LEGAL RISK: Phishing simulation automation must comply with employee consent and jurisdiction requirements — some countries prohibit certain simulated phishing techniques. Automated remediation training triggers must not create punitive patterns without HR policy review.

Use Cases

  • Automating phishing simulation campaigns from security awareness agents
  • Tracking training completion from security compliance agents
  • Accessing user risk scores from human risk management agents
  • Integrating SAT data with SIEM from security operations agents

Not For

  • Technical security controls without human risk and training focus
  • Customer-facing education without employee security awareness context
  • Enterprise email security gateway without training and simulation component

Interface

REST API
Yes
GraphQL
Yes
gRPC
No
MCP Server
No
SDK
No
Webhooks
No

Authentication

Methods: apikey
OAuth: No Scopes: No

KnowBe4 uses API token authentication. Account-level tokens from admin console. REST and GraphQL APIs available. Developer documentation at developer.knowbe4.com. No native webhooks — polling for event data. User provisioning via SCIM and AD sync. SIEM integration guides for Splunk and QRadar.

Pricing

Model: enterprise
Free tier: No
Requires CC: No

Tampa, Florida. Founded 2010 by Kevin Mitnick. KKR-backed (private). Largest security awareness training company. 65,000+ customers. 12M+ active learners. Strong SMB and mid-market focus. PhishFlip for real phishing email training. Competes with Proofpoint SAT and Cofense for phishing simulation.

Agent Metadata

Pagination
cursor
Idempotent
Partial
Retry Guidance
Not documented

Known Gotchas

  • LEGAL RISK: Phishing simulation campaigns may require employee notification in some EU jurisdictions — verify works council or consent requirements before automated scheduling
  • GraphQL and REST both available — prefer GraphQL for complex reporting queries (risk scores, completion rates)
  • API token only — no OAuth; single account-level token requires careful storage
  • No native webhooks — poll for campaign completion and training events
  • Remediation training triggers must align with HR policy — automated punitive training creates employee relations issues
  • Phishing simulation IP allow-listing — phishing emails may need IP allow-listing by email security gateways

Alternatives

Full Evaluation Report

Comprehensive deep-dive: security analysis, reliability audit, agent experience review, cost modeling, competitive positioning, and improvement roadmap for KnowBe4 Security Awareness Training API.

AI-powered analysis · PDF + markdown · Delivered within 30 minutes

$99

Package Brief

Quick verdict, integration guide, cost projections, gotchas with workarounds, and alternatives comparison.

Delivered within 10 minutes

$3

Score Monitoring

Get alerted when this package's AF, security, or reliability scores change significantly. Stay ahead of regressions.

Continuous monitoring

$3/mo

Scores are editorial opinions as of 2026-03-06.

5726
Packages Evaluated
26151
Need Evaluation
173
Need Re-evaluation
Community Powered