List frameworks
Returns frameworks enabled for the authenticated tenant.
Each item includes mapped entities and compliance progress metrics.
Request extra columns with fields (comma-separated).
Filter by entityIds to frameworks linked to those entities.
List responses are a JSON array in data. There is no cursor pagination on this endpoint.
Requires scope framework:read or framework:write.
curl -X GET "https://api.scrut.io/v1/frameworks?entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&fields=addedBy%2CaddedOn%2ClastModifiedBy" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
import requests
import json
url = "https://api.scrut.io/v1/frameworks?entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&fields=addedBy%2CaddedOn%2ClastModifiedBy"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://api.scrut.io/v1/frameworks?entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&fields=addedBy%2CaddedOn%2ClastModifiedBy", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api.scrut.io/v1/frameworks?entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&fields=addedBy%2CaddedOn%2ClastModifiedBy", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN (JWT)")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://api.scrut.io/v1/frameworks?entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&fields=addedBy%2CaddedOn%2ClastModifiedBy')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN (JWT)'
response = http.request(request)
puts response.body
{
"data": [
{
"frameworkId": "3a10a604-b942-43e5-8294-d418a0448ee5",
"frameworkName": "ISO 27001",
"entities": [
{
"entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
"entityName": "Organization Wide"
}
],
"nextAuditDate": 1704067200000,
"complianceProgress": {
"controls": {
"compliant": 36,
"total": 50,
"percentage": 72
},
"policies": {
"published": 12,
"total": 15,
"percentage": 80
},
"evidence": {
"uploaded": 8,
"total": 20,
"percentage": 40
},
"tests": {
"passing": 5,
"total": 9,
"percentage": 55
}
},
"addedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"addedOn": 1704067200000,
"lastModifiedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"modifiedOn": 1704067200000,
"tscSelections": [
"Security"
]
}
],
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "validation_failed",
"message": "Request validation failed.",
"details": [
{
"field": "status",
"message": "status contains unknown value(s): unknown"
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "unauthorized",
"message": "Missing, malformed, or invalid Bearer token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_revoked",
"message": "The API credential was revoked.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_stale",
"message": "The access token is stale; obtain a new token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "forbidden",
"message": "Insufficient scope.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "not_found",
"message": "The requested resource was not found.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded.",
"details": [
{
"retryAfterSec": 12
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "internal_error",
"message": "An unexpected error occurred.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "upstream_unavailable",
"message": "Upstream service is unavailable.",
"details": [
{
"dependency": "frameworks",
"issue": "Failed to process frameworks."
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
/v1/frameworks
Target server for requests. Edit to use your own host.
Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).
Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: addedBy, addedOn, lastModifiedBy, modifiedOn, tscSelections.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
Query Parameters
Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).
8fa88e7b-eb16-4999-854a-2f407958740aAdditional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: addedBy, addedOn, lastModifiedBy, modifiedOn, tscSelections.
addedBy,addedOn,lastModifiedBy