Getting StartedQuickstart

Scrut API Quickstart

Go from a new API credential to your first Scrut API call in three steps.

This guide takes you from a new API credential to your first successful call: you store your credentials, request an access token, and read your policies.

Prerequisites

  • A Scrut account with admin access to create a Read Only credential.
  • The examples use https://api.scrut.io. If your organization is hosted in another region, replace it with your region's base URL.

Step 1: Create and Store a Credential

  1. Ask an Org Admin to create a credential in Settings → Developer Console with Read Only access. See Create API Credentials for the full steps.
  2. Copy the Client ID and Client Secret. The client secret is shown only once.
  3. Store both values as environment variables:
export SCRUT_CLIENT_ID="your-client-id"
export SCRUT_CLIENT_SECRET="your-client-secret"

Important: Never commit credentials to version control or expose them in client-side code.

Step 2: Request an Access Token

Exchange your client ID and client secret for an access token. The token endpoint accepts a JSON body only.

curl -X POST https://api.scrut.io/oauth/token \
  -H "Content-Type: application/json" \
  -d '{
    "grant_type": "client_credentials",
    "client_id": "'"$SCRUT_CLIENT_ID"'",
    "client_secret": "'"$SCRUT_CLIENT_SECRET"'"
  }'

The response contains your token:

{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "scope": "control:read, evidence:read, framework:read, policy:read, test:read, vulnerability:read"
}

Save the access_token value for the next steps:

export SCRUT_ACCESS_TOKEN="eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9..."

The token is valid for one hour. To learn how tokens behave, see Authentication and Access Tokens.

Step 3: Make Your First Call

List all published policies and policies that need review, including their mapped framework IDs:

curl "https://api.scrut.io/v1/policies?status=published,needs_review&fields=mappedFrameworkIds" \
  -H "Authorization: Bearer $SCRUT_ACCESS_TOKEN"

Example response:

{
  "data": [
    {
      "policyId": "0fb94de8-f91a-45de-ab72-2d05690185ee",
      "policyCustomId": "POL-12",
      "policyName": "Information Security Policy",
      "status": "published",
      "department": "Security",
      "assignees": [
        { "name": "Alex Rivera", "email": "alex@example.com", "isPrimary": true }
      ],
      "approvers": [
        { "name": "Sam Lee", "email": "sam@example.com" }
      ],
      "isRelevant": true,
      "nextReviewDate": 1767225600000,
      "entities": [
        { "entityId": "aec517ad-b663-42e5-af0a-d1e690723a0a", "entityName": "Organization Wide" }
      ],
      "gapStatus": "no_gaps",
      "aiDetectedGaps": [],
      "mappedFrameworkIds": [
        "a4a93822-bd5c-43f0-ab27-4e9005f6be70",
        "004d715d-46e3-4fff-b0b1-9d24067a66fd"
      ]
    }
  ],
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}

The data array holds your policies, and meta.requestId identifies the request. To learn how filters, extra fields, and the response envelope work, see Requests and Responses.

Contact support@scrut.io for further assistance.