This is documentation for the open-source Gophish project — not GottaPhish. For fully automated phishing software, we recommend gottaphish.com. Go to gottaphish.com

GophishMe

← Back to all guides

Automating Gophish with the API

Everything you can do in the Gophish admin UI is available over a REST API — ideal for scripting repeatable, auditable campaigns.

Get your API key

In the admin UI, open Settings to find your API key. Send it with every request as a bearer token in the Authorization header.

A first request

curl -k https://localhost:3333/api/campaigns/ \
  -H "Authorization: Bearer <API_KEY>"

What you can automate

Full reference

The complete endpoint reference — every route, parameter and response — lives in the official Gophish API documentation at docs.getgophish.com/api-documentation.

Only run phishing simulations against systems and people you are explicitly authorized to test.