List evidence
Returns evidence records for the authenticated tenant.
Default items include identifiers, status, owners, entities, gap status, and gap count.
Mapped framework names are not included on list; request mappedFrameworkIds via fields, or use get-by-id.
Request extra columns with fields (comma-separated).
List responses are a JSON array in data. There is no cursor pagination on this endpoint.
Requires scope evidence:read or evidence:write.
curl -X GET "https://api.scrut.io/v1/evidence?status=uploaded%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=mappedFrameworkIds%2CmappedControlIds%2CnotRelevantReason" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
import requests
import json
url = "https://api.scrut.io/v1/evidence?status=uploaded%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=mappedFrameworkIds%2CmappedControlIds%2CnotRelevantReason"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://api.scrut.io/v1/evidence?status=uploaded%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=mappedFrameworkIds%2CmappedControlIds%2CnotRelevantReason", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api.scrut.io/v1/evidence?status=uploaded%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=mappedFrameworkIds%2CmappedControlIds%2CnotRelevantReason", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN (JWT)")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://api.scrut.io/v1/evidence?status=uploaded%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=mappedFrameworkIds%2CmappedControlIds%2CnotRelevantReason')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN (JWT)'
response = http.request(request)
puts response.body
{
"data": [
{
"evidenceId": "92af7e7f-b18e-495b-bf92-61c23ebd34a7",
"evidenceName": "Identity Verification Procedure and Records",
"status": "not_uploaded",
"department": "Security",
"assignees": [
{
"name": "Alex Rivera",
"email": "alex@example.com",
"isPrimary": true
}
],
"approvers": [
{
"name": "Alex Rivera",
"email": "alex@example.com"
}
],
"isRelevant": true,
"nextReviewDate": 1704067200000,
"entities": [
{
"entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
"entityName": "Organization Wide"
}
],
"gapStatus": "no_gaps",
"gapCount": 2,
"mappedFrameworkIds": [
"14c4c45d-6c31-4097-a02a-ad9cfd04850e"
],
"mappedControlIds": [
"2aa1b21e-4705-47cd-b1a7-e74ed4808bc9"
],
"notRelevantReason": "Covered by the parent information security policy.",
"recurrence": "annually",
"effortEstimate": "low",
"source": "Scrut",
"evidenceCollectionMethod": "manual",
"ticketsCount": 1,
"addedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"addedOn": 1704067200000,
"lastModifiedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"modifiedOn": 1704067200000
}
],
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "validation_failed",
"message": "Request validation failed.",
"details": [
{
"field": "status",
"message": "status contains unknown value(s): unknown"
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "unauthorized",
"message": "Missing, malformed, or invalid Bearer token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_revoked",
"message": "The API credential was revoked.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_stale",
"message": "The access token is stale; obtain a new token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "forbidden",
"message": "Insufficient scope.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "not_found",
"message": "The requested resource was not found.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded.",
"details": [
{
"retryAfterSec": 12
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "internal_error",
"message": "An unexpected error occurred.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "upstream_unavailable",
"message": "Upstream service is unavailable.",
"details": [
{
"dependency": "frameworks",
"issue": "Failed to process frameworks."
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
/v1/evidence
Target server for requests. Edit to use your own host.
Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.Filter by public evidence status. Pass a comma-separated list (no spaces required). Allowed values: not_uploaded, uploaded, needs_attention, draft, needs_review, pending_approval, needs_revision.
Filter to resources mapped to these framework IDs. Pass a comma-separated list (no spaces required).
Filter to resources mapped to these control IDs. Pass a comma-separated list (no spaces required).
Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).
Filter by relevance. Accepts true/false or 1/0.
Filter by assignee email addresses. Matches any assignees[].email. URL-encode + in plus-addressed emails as %2B. Pass a comma-separated list (no spaces required).
Filter by approver email addresses. Pass a comma-separated list (no spaces required).
Filter by department names. Use No Department for unassigned items. Pass a comma-separated list (no spaces required).
Inclusive lower bound for next review date, as Unix epoch milliseconds.
Inclusive upper bound for next review date, as Unix epoch milliseconds.
Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: mappedFrameworkIds, mappedControlIds, notRelevantReason, recurrence, effortEstimate, source, evidenceCollectionMethod, ticketsCount, addedBy, addedOn, lastModifiedBy, modifiedOn.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
Query Parameters
Filter by public evidence status. Pass a comma-separated list (no spaces required). Allowed values: not_uploaded, uploaded, needs_attention, draft, needs_review, pending_approval, needs_revision.
uploaded,needs_reviewFilter to resources mapped to these framework IDs. Pass a comma-separated list (no spaces required).
14c4c45d-6c31-4097-a02a-ad9cfd04850e,3a10a604-b942-43e5-8294-d418a0448ee5Filter to resources mapped to these control IDs. Pass a comma-separated list (no spaces required).
2aa1b21e-4705-47cd-b1a7-e74ed4808bc9,8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2bFilter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).
8fa88e7b-eb16-4999-854a-2f407958740aFilter by assignee email addresses. Matches any assignees[].email. URL-encode + in plus-addressed emails as %2B. Pass a comma-separated list (no spaces required).
alex@example.com,alex@example.comFilter by approver email addresses. Pass a comma-separated list (no spaces required).
sam@example.comFilter by department names. Use No Department for unassigned items. Pass a comma-separated list (no spaces required).
Security,EngineeringInclusive lower bound for next review date, as Unix epoch milliseconds.
1735689600000Inclusive upper bound for next review date, as Unix epoch milliseconds.
1767225600000Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: mappedFrameworkIds, mappedControlIds, notRelevantReason, recurrence, effortEstimate, source, evidenceCollectionMethod, ticketsCount, addedBy, addedOn, lastModifiedBy, modifiedOn.
mappedFrameworkIds,mappedControlIds,notRelevantReason