# Proofpoint > Proofpoint is an enterprise cybersecurity company focused on human-centric security: > email and collaboration security, data loss prevention, insider threat management, > digital communications governance, security awareness training and threat intelligence. > Its public API surface is substantial but gateway-shaped rather than developer-portal > shaped — seven documented APIs, every one credential-gated, and no OpenAPI, AsyncAPI, > GraphQL or MCP contract published for any of them. Generated by API Evangelist (https://apievangelist.com) on 2026-09-13 from Proofpoint's own public documentation. Proofpoint publishes no llms.txt of its own; this file was GENERATED, not fetched. Probed and 404: www.proofpoint.com/llms.txt, tap-api-v2.proofpoint.com/llms.txt, api.emergingthreats.net/llms.txt, threatprotection-api.proofpoint.com/llms.txt. ## What you need to know before calling anything - There is no self-service signup. Every credential on the estate is minted by an administrator inside an existing paid tenant. You cannot obtain access by filling in a form. - Three incompatible auth models are in production: HTTP Basic with a service principal and secret (TAP, Essentials), OAuth 2.0 client credentials via https://auth.proofpoint.com/v1/token (Threat Protection Reports, Secure Email Relay), and a raw API key in the Authorization header with no scheme prefix (ET Intelligence). - The public surface is read-only apart from Secure Email Relay email submission. There is no create, update or delete to be idempotent about, and nothing to reverse. - Rate limits are published in prose but never signalled at runtime. No X-RateLimit-*, no RateLimit-*, no Retry-After. You get a 429 with no indication of when to retry, and recovery is rolling rather than a fixed reset. - The documentation is public but not browsable: individual API articles on help.proofpoint.com return 200 anonymously while the section indexes above them redirect to a customer login. ## APIs - [Targeted Attack Protection (TAP) API v2](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation): SIEM event download, campaigns, forensics, Very Attacked People, threat summaries, URL Defense decoding. Base https://tap-api-v2.proofpoint.com/v2. HTTP Basic. - [Threat Protection Dashboard Reports API v1](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Reports_API): executive-summary, effectiveness, people, organization and threat-landscape report cards plus email-bomb events. Base https://threatprotection-api.proofpoint.com/api/v1/dash/reports. OAuth 2.0 client credentials, one-hour Bearer tokens. - [Emerging Threats (ET) Intelligence Query API v1](https://apidocs.emergingthreats.net/): 36 endpoints pivoting across domains, IPs, malware samples by MD5, Suricata SIDs, CVEs, malware families and threat actors. Base https://api.emergingthreats.net/v1. API key. 200 queries/minute. - [Security Awareness Training (ZenGuide) Results API](https://proofpoint.securityeducation.com/api/reporting/documentation/): CyberStrength assessments, PhishAlarm, ThreatSim phishing events, training, enrollments, users. Base https://results.us.securityeducation.com/api/reporting/v0.3.0. - [Secure Email Relay Email Submission API](https://api-docs.ser.proofpoint.com/docs/email-submission): authenticated transactional mail relay for applications, so a strict DMARC policy stays achievable. Base https://mail.ser.proofpoint.com. The only public write operation on the estate. - [Proofpoint Essentials Threat (SIEM) API](https://help.proofpoint.com/Essentials/Additional_Resources/API_Documentation/Essentials_Threat_API): the TAP /v2/siem shape on regional Essentials hosts. Base https://us-siem.proofpointessentials.com/v2 (EU: https://eu-siem.proofpointessentials.com). - [Proofpoint on Demand (PoD) Log API](https://help.proofpoint.com/Proofpoint_on_Demand/Log_API): WebSocket stream of filter (message) and MTA (maillog) logs at wss://logstream.proofpoint.com. The only event-shaped Proofpoint API, and the only one whose documentation is behind a customer login. ## Reference documentation - [SIEM API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API): six endpoints, syslog (RFC 5424) or JSON, one-hour maximum window, seven-day retention, no paging. - [Campaign API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Campaign_API): /v2/campaign/ids and /v2/campaign/. The only place page/size pagination appears alongside People. - [Forensics API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Forensics_API): evidence for a threatId or a campaignId. - [People API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/People_API): /v2/people/vap and /v2/people/top-clickers. - [Threats API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Threat_API): /v2/threat/summary/. Documented as having no throttle limits. - [URL Decoder API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/URL_Decoder_API): POST /v2/url/decode, and the one operation Proofpoint documents as callable without credentials. - [Email Bomb Events API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Email_Bomb_Events_API): /api/v1/dash/reports/mail-bomb-events. - [API Terms of Use](https://www.proofpoint.com/us/legal/api-terms-of-use): the terms every TAP API article points at. ## Client libraries All first-party clients are published from the pfptcommunity GitHub organization, which Proofpoint owns. There is no SDK page on proofpoint.com. - [tap-api (PyPI 1.1.1, 2025-01-27)](https://pypi.org/project/tap-api/) — TAP - [et-api (PyPI 1.0.2, 2023-09-27)](https://pypi.org/project/et-api/) — ET Intelligence - [psat-api (PyPI 4.2.0, 2026-07-24)](https://pypi.org/project/psat-api/) — ZenGuide Results - [ser-mail-api (PyPI 2.0.6, 2025-09-04)](https://pypi.org/project/ser-mail-api/) — Secure Email Relay - [ser-admin-api (PyPI 0.3.0, 2026-07-24)](https://pypi.org/project/ser-admin-api/) — SER Admin - [Proofpoint.SecureEmailRelay.Mail (NuGet 1.1.3, 2025-09-04)](https://www.nuget.org/packages/Proofpoint.SecureEmailRelay.Mail) — SER, .NET - [io.pfpt.ser:ser-mail-api (Maven Central 1.0.2, 2025-09-04)](https://repo1.maven.org/maven2/io/pfpt/ser/ser-mail-api/) — SER, Java - [et-api-php](https://github.com/pfptcommunity/et-api-php) — ET Intelligence, PHP. Not on Packagist and has no tagged release. ## Company and trust - [Proofpoint](https://www.proofpoint.com/us) - [Blog](https://www.proofpoint.com/us/blog) - [Proofpoint Trust](https://www.proofpoint.com/us/legal/trust) - [Product Certifications](https://www.proofpoint.com/us/legal/trust/product-certifications): ISO 42001, ISO 27001, SOC 2, FedRAMP, IRAP, ENS, Data Privacy Framework, PCI (Archive), FIPS validated cryptographic modules, CSA STAR. - [Vulnerability Disclosure Policy](https://www.proofpoint.com/us/security/vulnerability-disclosure-policy): security@proofpoint.com, Hall of Fame, CVE issuance. - [Privacy Policy](https://www.proofpoint.com/us/legal/privacy-policy) - [Support Services](https://www.proofpoint.com/us/support-services) - [Community](https://proofpoint.my.site.com/community/s/) - [GitHub (pfptcommunity)](https://github.com/pfptcommunity) ## Optional - [Emerging Threats API docs source](https://github.com/EmergingThreats/query-api-docs) - [ZenGuide Results API machine-readable description](https://proofpoint.securityeducation.com/api/reporting/documentation/api_data.json): an apiDoc 0.3.0 document, the only machine-readable API description Proofpoint publishes anywhere. - [Proofpoint AI MCP Security](https://www.proofpoint.com/us/products/ai-mcp-security): a product for securing OTHER organisations' MCP servers. Proofpoint runs no MCP server for its own APIs.