MailThreatZero Public API: PSA and RMM integrations
For MSP technicians who connect MailThreatZero to a PSA or RMM: the Public API v1 base URL and self-description, API keys and their two headers, narrow scopes and the single write, tenancy and why another tenant's domain returns 404, the 120-requests-per-minute limit, each endpoint and the silent-domain alert, compatibility rules, the unauthenticated status endpoints for off-site monitoring, and why the Monitor Mode evaluation report is not a detection rate.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- MailThreatZero
Skills you'll practise
- Create a key with the narrowest scopes an integration needs and send it in a documented header
- Interpret 401, 403, 404 and 429 responses from the API and fix the cause
- Build an RMM alert for silent domains from the summary endpoint
- Choose between the authenticated API and the unauthenticated status endpoints for a monitoring job
- Present a Monitor Mode evaluation report accurately, without turning it into a detection rate
Course outline
- 1.MailThreatZero Public API: PSA and RMM integrationsVideo · 2 min
- 2.Keys, scopes and tenancyLesson · 17 min
- 3.Endpoints and the silent-domain alertLesson · 17 min
- 4.Status endpoints and the evaluation reportLesson · 16 min
- 5.MailThreatZero Public API: PSA and RMM integrations: knowledge checkKnowledge check · 18 questions
- 6.MailThreatZero: the domain that went quietScenario
- 7.Final exam9 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.