Scrut API
Learn what you can do with the Scrut API.
The Scrut API gives you programmatic access to your compliance program in Scrut. Use it to move data between Scrut and the tools your teams already work in, and to automate work you would otherwise do one record at a time in the platform.
Developer Docs
Everything you need to build with the Scrut API, including authentication, endpoints, and code samples, lives in the Scrut Developer Docs.
| Section | What you'll find | Start here if you want to |
|---|---|---|
| Getting Started | An overview of the API, a quick start, and steps to create API credentials | Make your first request |
| Guides | Task-based walkthroughs for common use cases | Solve a specific problem |
| Fundamenatals | How the API works, including authentication and how Scrut data is structured | Understand the API before you build |
| API Reference | Every available endpoint, with parameters and example requests and responses | Look up the details of a specific call |
What You Can Do With the Scrut API
Teams typically use the Scrut API to:
- Keep compliance data in sync with internal systems. Pull the status of your controls, tests, and evidence into a data warehouse or business intelligence tool so leadership can see compliance posture alongside other operational metrics.
- Submit evidence from systems Scrut doesn't integrate with. Send evidence from in-house tools, internal scripts, or on-premises systems directly to Scrut, so you don't have to manually export and upload files.
- Push vulnerability findings into Scrut. Send scanner findings into Scrut from tools without a built-in integration.
- Connect Scrut to internal workflows. Use Scrut data to trigger actions in your own tools, such as opening an internal ticket when a test fails.
Before You Start
To use the Scrut API, you need API credentials for your Scrut workspace. Follow the steps in Create API Credentials in the Developer Docs.
Important: Treat your API credentials like a password. Store them in a secrets manager, never commit them to source control, and revoke them right away if you think they've been exposed.
Scrut API vs. Scrut MCP Server
Scrut offers two ways to work with your compliance data outside the platform. Choose the one that matches how you plan to work.
| Scrut API | Scrut MCP Server | |
|---|---|---|
| Best for | Developers building automations, scripts, and integrations | Anyone who wants to query Scrut from an AI assistant |
| How you use it | Write code that sends requests to Scrut | Ask questions in plain language from tools such as Claude or Cursor |
| Typical outcome | A recurring, automated workflow | A quick answer or a one-off action |
To set up the MCP Server, see Connect Scrut MCP.
FAQs
Reach out to support@scrut.io or contact your CSM for further assistance.