Optimize Your WorkflowScrut API

Scrut API

Learn what you can do with the Scrut API.

The Scrut API gives you programmatic access to your compliance program in Scrut. Use it to move data between Scrut and the tools your teams already work in, and to automate work you would otherwise do one record at a time in the platform.

Developer Docs

Everything you need to build with the Scrut API, including authentication, endpoints, and code samples, lives in the Scrut Developer Docs.

SectionWhat you'll findStart here if you want to
Getting StartedAn overview of the API, a quick start, and steps to create API credentialsMake your first request
GuidesTask-based walkthroughs for common use casesSolve a specific problem
FundamenatalsHow the API works, including authentication and how Scrut data is structuredUnderstand the API before you build
API ReferenceEvery available endpoint, with parameters and example requests and responsesLook up the details of a specific call

What You Can Do With the Scrut API

Teams typically use the Scrut API to:

  • Keep compliance data in sync with internal systems. Pull the status of your controls, tests, and evidence into a data warehouse or business intelligence tool so leadership can see compliance posture alongside other operational metrics.
  • Submit evidence from systems Scrut doesn't integrate with. Send evidence from in-house tools, internal scripts, or on-premises systems directly to Scrut, so you don't have to manually export and upload files.
  • Push vulnerability findings into Scrut. Send scanner findings into Scrut from tools without a built-in integration.
  • Connect Scrut to internal workflows. Use Scrut data to trigger actions in your own tools, such as opening an internal ticket when a test fails.

Before You Start

To use the Scrut API, you need API credentials for your Scrut workspace. Follow the steps in Create API Credentials in the Developer Docs.

Important: Treat your API credentials like a password. Store them in a secrets manager, never commit them to source control, and revoke them right away if you think they've been exposed.

Scrut API vs. Scrut MCP Server

Scrut offers two ways to work with your compliance data outside the platform. Choose the one that matches how you plan to work.

Scrut APIScrut MCP Server
Best forDevelopers building automations, scripts, and integrationsAnyone who wants to query Scrut from an AI assistant
How you use itWrite code that sends requests to ScrutAsk questions in plain language from tools such as Claude or Cursor
Typical outcomeA recurring, automated workflowA quick answer or a one-off action

To set up the MCP Server, see Connect Scrut MCP.

FAQs

Reach out to support@scrut.io or contact your CSM for further assistance.