FrameworksList frameworks

List frameworks

Returns frameworks enabled for the authenticated tenant. Each item includes mapped entities and compliance progress metrics. Request extra columns with fields (comma-separated). Filter by entityIds to frameworks linked to those entities. List responses are a JSON array in data. There is no cursor pagination on this endpoint. Requires scope framework:read or framework:write.

curl -X GET "https://api.scrut.io/v1/frameworks?entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&fields=addedBy%2CaddedOn%2ClastModifiedBy" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
{
  "data": [
    {
      "frameworkId": "3a10a604-b942-43e5-8294-d418a0448ee5",
      "frameworkName": "ISO 27001",
      "entities": [
        {
          "entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
          "entityName": "Organization Wide"
        }
      ],
      "nextAuditDate": 1704067200000,
      "complianceProgress": {
        "controls": {
          "compliant": 36,
          "total": 50,
          "percentage": 72
        },
        "policies": {
          "published": 12,
          "total": 15,
          "percentage": 80
        },
        "evidence": {
          "uploaded": 8,
          "total": 20,
          "percentage": 40
        },
        "tests": {
          "passing": 5,
          "total": 9,
          "percentage": 55
        }
      },
      "addedBy": {
        "name": "Alex Rivera",
        "email": "alex@example.com"
      },
      "addedOn": 1704067200000,
      "lastModifiedBy": {
        "name": "Alex Rivera",
        "email": "alex@example.com"
      },
      "modifiedOn": 1704067200000,
      "tscSelections": [
        "Security"
      ]
    }
  ],
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}
GET
/v1/frameworks
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
query
entityIdsstring

Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).

query
fieldsstring

Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: addedBy, addedOn, lastModifiedBy, modifiedOn, tscSelections.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Query Parameters

entityIdsstring

Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).

Example:
8fa88e7b-eb16-4999-854a-2f407958740a
fieldsstring

Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: addedBy, addedOn, lastModifiedBy, modifiedOn, tscSelections.

Example:
addedBy,addedOn,lastModifiedBy

Responses

dataarray
Required
metaobject
Required