Skip to main content
Adaptive Security provides programmatic access to resources such as users, groups, training campaigns, and phishing simulations for reporting and security workflows.AirMDR authenticates to Adaptive Security by using an API token generated from the Adaptive Security Admin Portal. The token is supplied as a Bearer token when AirMDR sends API requests.
Adaptive Security is a cloud service rather than a locally installed product with traditional software-version requirements. Current published API resources use the v2 endpoint family; for example, user information is available through /v2/users.
Always refer to the current Adaptive Security API documentation when validating individual endpoint availability because API resources can change independently of the AirMDR integration.
Adaptive Security uses token-based authentication for its Public API. Requests include the generated token in the HTTP Authorization header using the Bearer authentication scheme. APIs.io
Credential ReferenceThe actual token must be entered into AirMDR without adding Bearer manually unless the AirMDR field specifically requests it. AirMDR handles the authorization header when making requests.Token lifecycleThe AirMDR connection configuration indicates that Adaptive Security tokens:
  • can have an expiration date selected when they are created;
  • can be revoked;
  • become unusable after expiration; and
  • cause authentication requests to fail when an expired or invalid token remains configured.
Public API specifications also describe Bearer-token authentication and token revocation/expiration behavior.
Adaptive Security states that access to its Public API is governed by role-based access controls (RBAC).Use an account that is permitted to generate API credentials and access the resources required by the integration.
Adaptive Security’s publicly available documentation does not currently identify a specific built-in role name that must be assigned for AirMDR. Avoid documenting an unverified role such as “API Administrator.” Instead, ensure that the account can access Settings → API and that the resulting token can access the required endpoints.

Pre-requisites

An active Adaptive Security tenant with Public API access.
Access to Adaptive Security Admin Portal athttps://admin.adaptivesecurity.com.
Copy the API token when it is generated. The AirMDR connection UI indicates that Adaptive Security displays the token only once.

Setup Steps

1

Sign in to Adaptive Security

  1. Open a supported web browser.
  2. Navigate to https://admin.adaptivesecurity.com.
  3. Sign in using an Adaptive Security administrator account.
2

Open the API settings

From the Adaptive Security Admin Portal:
  1. Open Settings.
  2. Select API.
    Use the following navigation path: Settings → API.
3

Generate an API token

On the API page:
  1. Select the option to create or generate an API token.
  2. Enter the requested token information, if prompted.
  3. Configure an appropriate expiration for the token.
  4. Review the access configuration displayed in the Adaptive Security UI.
  5. Generate the token.
    Exact button names can change as Adaptive Security updates its Admin Portal. The verified navigation path is Settings → API.
  6. Copy the generated API token.
    Store it in an approved secrets-management system until it is added to AirMDR.
    Do not add Bearer, quotation marks, or additional spaces.
    For Example: <ADAPTIVE_SECURITY_API_TOKEN>
    Never include an actual Adaptive Security token in documentation, Jira tickets, screenshots, email, Slack messages, or source-code repositories.

Adaptive Security Credential Reference Table

Validate Connectivity

You can optionally validate the credential before adding it to AirMDR. Adaptive Security documents the following base URL: https://api.adaptivesecurity.com
A successful request returns HTTP:
If the token is invalid or expired, the API can return:

Configure Adaptive Security in AirMDR Integrations Dashboard

  1. Navigate to AirMDR, provide the credentials and click Login
  2. Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select ADMIN → Integrations.
  3. Use the search option, enter the keyword “Adaptive Security”, select the Connections tab, and click + New Connection button.
  4. Use the following values in the AirMDR integration configuration screen:
    1. In Remote Agent, select an AirMDR Remote Agent only when the Adaptive Security tenant must be accessed through an approved private network route, proxy, or controlled network environment. If the Adaptive Security API is directly accessible from AirMDR over the public internet, leave this field unselected unless instructed otherwise by your AirMDR administrator.
    2. In Expiry, select the date on which AirMDR should treat the stored Adaptive Security credentials as expired, according to your organization’s credential-rotation policy.
    The Expiry date controls credential validity in AirMDR. It does not automatically rotate, extend, or revoke the API token in Adaptive Security. Generate a replacement token in Adaptive Security, update the AirMDR connection with the new Api_token, validate the connection, and then revoke the previous token when it is no longer required.
  5. Click Save.

Skills provided by this Integration

Use these skills to review security-awareness campaigns and determine whether users have completed assigned training.Adaptive Security documents both training-campaign and training-enrollment endpoints as authenticated GET operations.
Use these skills to investigate simulated phishing campaigns and understand how users interacted with simulated phishing messages.Adaptive Security documents these phishing campaign, simulation, and enrollment resources as Bearer-authenticated API endpoints. 
For Get Adaptive Security phishing enrollments, AirMDR can derive the user outcome from the interaction timestamps returned by Adaptive Security. The integration should not imply that Adaptive Security returns an AirMDR-specific verdict field.
Use this skill to review administrative changes made within the Adaptive Security tenant.Individual audit-log entries can also be retrieved through:
Adaptive Security’s API documentation shows that audit-log information can include the acting administrator, action, category, affected entities, timestamp-related information, and success status.
Use these skills to retrieve information about Adaptive Security users and the groups to which they belong.
To view the details of Input Parameters and Output for the respective skills

Additional Information

Adaptive Security provides structured JSON errors containing fields such as error_code, message, status_code, and request_id.**Troubleshoot **INVALID_TOKENIf AirMDR returns 401 or INVALID_TOKEN:
  1. Open the Adaptive Security Admin Portal.
  2. Navigate to Settings → API.
  3. Verify whether the token has expired or been revoked.
  4. Generate a replacement token if necessary.
  5. Copy the new token.
  6. Open the Adaptive Security connection in AirMDR.
  7. Replace the value in Api_token.
  8. Update Expiry to match the new token lifecycle.
  9. Select Save.
  10. Run an Adaptive Security skill again and confirm that the request succeeds.
Troubleshoot connectivity failuresIf AirMDR cannot reach Adaptive Security:
  1. Verify DNS resolution for:
  1. Confirm outbound HTTPS connectivity.
  2. Ensure TCP 443 is permitted.
  3. Verify proxy or firewall configuration.
  4. If a Remote Agent is selected, verify that the agent is online and has outbound access.
  5. Retest the integration.
Troubleshoot rate limitingIf Adaptive Security returns:
reduce API request frequency and retry after an appropriate delay.Several Adaptive API list endpoints document 429 as the response when the request rate is exceeded.
Monitor both AirMDR connection execution and the Adaptive Security credential lifecycle.For troubleshooting, capture:
  • execution timestamp;
  • AirMDR skill name;
  • HTTP status code;
  • API endpoint;
  • request ID, when returned;
  • error code; and
  • error message.
Do not record the API token in application logs.

Example diagnostic log

Authentication failure example

Public API specifications identify INVALID_TOKEN as an authentication error associated with an invalid or expired token. APIs.ioFor normal operation, record:
For troubleshooting, temporarily capture more detailed request metadata where supported, but never log:
✅ DoUse a dedicated integration tokenWhere your Adaptive Security configuration permits multiple API tokens, use a token dedicated to the AirMDR integration. This makes credential rotation and audit tracking easier.Follow least privilegeGrant only the access required by the Adaptive Security skills supported in AirMDR.Set an appropriate expirationAdaptive Security allows API tokens to have a user-configured expiration. Configure an expiry period that aligns with your organization’s credential policy. Adaptive SecurityRotate tokens before expirationReplace the Adaptive Security token in AirMDR before the existing credential becomes invalid.Treat API tokens as passwordsStore tokens in approved secrets-management systems and restrict access to authorized administrators.Use HTTPSSend Adaptive Security API requests only to: https://api.adaptivesecurity.comMonitor credential activityWhere appropriate, use Adaptive Security audit information to monitor API-key creation, updates, and deletion.Preserve request IDsRecord request_id or X-Request-ID values when troubleshooting API failures because they can help Adaptive Security Support investigate the problem.❌ Don’tDon’t expose tokensNever place a real API token in:
Don’t add Bearer to the AirMDR fieldEnter only: <API_TOKEN>not: Bearer <API_TOKEN>in Api_token.Don’t use expired tokensReplace an expired or revoked token immediately.Don’t document unsupported permissionsDo not state that a particular Adaptive Security role or permission is mandatory unless it is verified through the tenant UI or Adaptive Security documentation.Don’t make unverified encryption claimsAvoid statements such as:
unless Adaptive Security formally documents those controls for the applicable service.Don’t state that the complete Adaptive API is read-onlyThe current API documentation contains functionality beyond the original reporting endpoints, including webhooks and API-key-related administration/audit capabilities. Document the behavior of the AirMDR integration and its implemented skills, rather than describing the entire Adaptive API as read-only
  • 📧 Contact AirMDR Support through your designated support channel.
  • 🔁 Rotate credentials regularly. Recommended cadence: Every 90 days or as per internal security policy
  • 🔄 Reconnect in AirMDR immediately when API Keys are changed.
Data flowA simplified request flow is:Air MDR Adaptive Security Integration Flow
Network Requirements
Data exchangedDepending on the AirMDR skill being executed, API responses can include information associated with:
  • Adaptive Security users
  • groups
  • training campaigns and training progress
  • phishing simulations
  • related reporting information
Adaptive Security describes its Public API as supporting reporting and integration workflows across these resource areas.API access behaviorThe current AirMDR integration screen describes the Adaptive Security API as read-only, meaning that the configured token is used for retrieving data rather than launching campaigns, enrolling users, or modifying training through this integration.