Scrut API Quickstart
Go from a new API credential to your first Scrut API call in three steps.
This guide takes you from a new API credential to your first successful call: you store your credentials, request an access token, and read your policies.
Prerequisites
- A Scrut account with admin access to create a Read Only credential.
- The examples use
https://api.scrut.io. If your organization is hosted in another region, replace it with your region's base URL.
Step 1: Create and Store a Credential
- Ask an Org Admin to create a credential in Settings → Developer Console with Read Only access. See Create API Credentials for the full steps.
- Copy the Client ID and Client Secret. The client secret is shown only once.
- Store both values as environment variables:
export SCRUT_CLIENT_ID="your-client-id"
export SCRUT_CLIENT_SECRET="your-client-secret"
Important: Never commit credentials to version control or expose them in client-side code.
Step 2: Request an Access Token
Exchange your client ID and client secret for an access token. The token endpoint accepts a JSON body only.
curl -X POST https://api.scrut.io/oauth/token \
-H "Content-Type: application/json" \
-d '{
"grant_type": "client_credentials",
"client_id": "'"$SCRUT_CLIENT_ID"'",
"client_secret": "'"$SCRUT_CLIENT_SECRET"'"
}'
const tokenResponse = await fetch("https://api.scrut.io/oauth/token", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
grant_type: "client_credentials",
client_id: process.env.SCRUT_CLIENT_ID,
client_secret: process.env.SCRUT_CLIENT_SECRET,
}),
});
const { access_token } = await tokenResponse.json();
import os
import requests
token_response = requests.post(
"https://api.scrut.io/oauth/token",
json={
"grant_type": "client_credentials",
"client_id": os.environ["SCRUT_CLIENT_ID"],
"client_secret": os.environ["SCRUT_CLIENT_SECRET"],
},
)
access_token = token_response.json()["access_token"]
The response contains your token:
{
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"token_type": "Bearer",
"expires_in": 3600,
"scope": "control:read, evidence:read, framework:read, policy:read, test:read, vulnerability:read"
}
Save the access_token value for the next steps:
export SCRUT_ACCESS_TOKEN="eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9..."
The token is valid for one hour. To learn how tokens behave, see Authentication and Access Tokens.
Step 3: Make Your First Call
List all published policies and policies that need review, including their mapped framework IDs:
curl "https://api.scrut.io/v1/policies?status=published,needs_review&fields=mappedFrameworkIds" \
-H "Authorization: Bearer $SCRUT_ACCESS_TOKEN"
const params = new URLSearchParams({
status: "published,needs_review",
fields: "mappedFrameworkIds",
});
const response = await fetch(`https://api.scrut.io/v1/policies?${params}`, {
headers: { Authorization: `Bearer ${accessToken}` },
});
const { data } = await response.json();
console.log(data);
response = requests.get(
"https://api.scrut.io/v1/policies",
headers={"Authorization": f"Bearer {access_token}"},
params={
"status": "published,needs_review",
"fields": "mappedFrameworkIds",
},
)
print(response.json()["data"])
Example response:
{
"data": [
{
"policyId": "0fb94de8-f91a-45de-ab72-2d05690185ee",
"policyCustomId": "POL-12",
"policyName": "Information Security Policy",
"status": "published",
"department": "Security",
"assignees": [
{ "name": "Alex Rivera", "email": "alex@example.com", "isPrimary": true }
],
"approvers": [
{ "name": "Sam Lee", "email": "sam@example.com" }
],
"isRelevant": true,
"nextReviewDate": 1767225600000,
"entities": [
{ "entityId": "aec517ad-b663-42e5-af0a-d1e690723a0a", "entityName": "Organization Wide" }
],
"gapStatus": "no_gaps",
"aiDetectedGaps": [],
"mappedFrameworkIds": [
"a4a93822-bd5c-43f0-ab27-4e9005f6be70",
"004d715d-46e3-4fff-b0b1-9d24067a66fd"
]
}
],
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
The data array holds your policies, and meta.requestId identifies the request. To learn how filters, extra fields, and the response envelope work, see Requests and Responses.
Contact support@scrut.io for further assistance.