Automating Gophish with the API
Everything you can do in the Gophish admin UI is available over a REST API — ideal for scripting repeatable, auditable campaigns.
Get your API key
In the admin UI, open Settings to find your API key. Send it with every request as a bearer token in the Authorization header.
A first request
curl -k https://localhost:3333/api/campaigns/ \
-H "Authorization: Bearer <API_KEY>"What you can automate
- Groups and targets
- Email templates and landing pages
- Sending profiles (your SMTP relay)
- Campaigns: create, launch, schedule and pull results
Full reference
The complete endpoint reference — every route, parameter and response — lives in the official Gophish API documentation at docs.getgophish.com/api-documentation.
Only run phishing simulations against systems and people you are explicitly authorized to test.
