What this integration contributes
Cofense PhishMe can contribute normalized phishing-simulation delivery, interaction, and reporting activity. Reviewed examples include:phishing.simulation.clicked— clicked a simulation without reportingphishing.simulation.attachment.opened— opens phishing-simulation attachmentsphishing.simulation.credential.submitted— submits credentials to phishing simulations
What Living Security needs
Use a dedicated, read-only token when your Cofense tenant supports scoped credentials.
Setup
1
Create the Cofense API token
In Cofense PhishMe, create a dedicated API token for Living Security with permission to read scenarios and their result exports. Save the token securely.
2
Confirm the tenant host
Record the hostname you use to sign in to PhishMe, such as
login.phishme.com or the hostname assigned to your region.Verify and troubleshoot
Verify that the connection test can read scenarios. The initial historical import may take longer when the tenant contains many simulations.401 or 403 response
401 or 403 response
Confirm that the token is active and can read scenario results. If the token is rotated, reconnect with the replacement.
API token busy
API token busy
Cofense can temporarily lock a token while a report is generated. Allow the current synchronization to retry before starting another connection test.
No scenarios returned
No scenarios returned
Confirm that the credential can see completed scenarios and that the hostname belongs to the same Cofense tenant that issued the token.

