List policies
Returns policies for the authenticated tenant.
Default items include identifiers, status, owners, entities, and gap status.
Request extra columns with fields (comma-separated).
List responses are a JSON array in data. There is no cursor pagination on this endpoint.
Requires scope policy:read or policy:write.
curl -X GET "https://api.scrut.io/v1/policies?status=published%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=policyBehavior%2CmappedFrameworkIds%2CmappedControlIds" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
import requests
import json
url = "https://api.scrut.io/v1/policies?status=published%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=policyBehavior%2CmappedFrameworkIds%2CmappedControlIds"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://api.scrut.io/v1/policies?status=published%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=policyBehavior%2CmappedFrameworkIds%2CmappedControlIds", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api.scrut.io/v1/policies?status=published%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=policyBehavior%2CmappedFrameworkIds%2CmappedControlIds", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN (JWT)")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://api.scrut.io/v1/policies?status=published%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=policyBehavior%2CmappedFrameworkIds%2CmappedControlIds')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN (JWT)'
response = http.request(request)
puts response.body
{
"data": [
{
"policyId": "f293847a-0476-4878-b999-598d2448d00d",
"policyCustomId": "POL-12",
"policyName": "Information Security Policy",
"status": "not_uploaded",
"department": "Security",
"assignees": [
{
"name": "Alex Rivera",
"email": "alex@example.com",
"isPrimary": true
}
],
"approvers": [
{
"name": "Alex Rivera",
"email": "alex@example.com"
}
],
"isRelevant": true,
"nextReviewDate": 1704067200000,
"entities": [
{
"entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
"entityName": "Organization Wide"
}
],
"gapStatus": "no_gaps",
"aiDetectedGaps": [
"Missing annual review date"
],
"mappedFrameworkIds": [
"14c4c45d-6c31-4097-a02a-ad9cfd04850e"
],
"mappedControlIds": [
"2aa1b21e-4705-47cd-b1a7-e74ed4808bc9"
],
"policyBehavior": "Requires acceptance",
"notRelevantReason": "Covered by the parent information security policy.",
"versionNumber": "3",
"effortEstimate": "low",
"recurrence": "annually",
"source": "Scrut",
"publishedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"publishedOn": 1704067200000,
"addedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"addedOn": 1704067200000,
"lastModifiedBy": {
"name": "Alex Rivera",
"email": "alex@example.com"
},
"modifiedOn": 1704067200000
}
],
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "validation_failed",
"message": "Request validation failed.",
"details": [
{
"field": "status",
"message": "status contains unknown value(s): unknown"
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "unauthorized",
"message": "Missing, malformed, or invalid Bearer token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_revoked",
"message": "The API credential was revoked.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_stale",
"message": "The access token is stale; obtain a new token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "forbidden",
"message": "Insufficient scope.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "not_found",
"message": "The requested resource was not found.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded.",
"details": [
{
"retryAfterSec": 12
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "internal_error",
"message": "An unexpected error occurred.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "upstream_unavailable",
"message": "Upstream service is unavailable.",
"details": [
{
"dependency": "frameworks",
"issue": "Failed to process frameworks."
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
/v1/policies
Target server for requests. Edit to use your own host.
Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.Filter by public policy status. Pass a comma-separated list (no spaces required). Allowed values: not_uploaded, draft, published, needs_attention, draft_approved, needs_review, pending_approval.
Filter to resources mapped to these framework IDs. Pass a comma-separated list (no spaces required).
Filter to resources mapped to these control IDs. Pass a comma-separated list (no spaces required).
Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).
Filter by relevance. Accepts true/false or 1/0.
Filter by assignee email addresses. Matches any assignees[].email. URL-encode + in plus-addressed emails as %2B. Pass a comma-separated list (no spaces required).
Filter by approver email addresses. Pass a comma-separated list (no spaces required).
Filter by department names. Use No Department for unassigned items. Pass a comma-separated list (no spaces required).
Inclusive lower bound for next review date, as Unix epoch milliseconds.
Inclusive upper bound for next review date, as Unix epoch milliseconds.
Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: policyBehavior, mappedFrameworkIds, mappedControlIds, notRelevantReason, versionNumber, effortEstimate, recurrence, source, publishedBy, publishedOn, addedBy, addedOn, lastModifiedBy, modifiedOn.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
Query Parameters
Filter by public policy status. Pass a comma-separated list (no spaces required). Allowed values: not_uploaded, draft, published, needs_attention, draft_approved, needs_review, pending_approval.
published,needs_reviewFilter to resources mapped to these framework IDs. Pass a comma-separated list (no spaces required).
14c4c45d-6c31-4097-a02a-ad9cfd04850e,3a10a604-b942-43e5-8294-d418a0448ee5Filter to resources mapped to these control IDs. Pass a comma-separated list (no spaces required).
2aa1b21e-4705-47cd-b1a7-e74ed4808bc9,8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2bFilter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).
8fa88e7b-eb16-4999-854a-2f407958740aFilter by assignee email addresses. Matches any assignees[].email. URL-encode + in plus-addressed emails as %2B. Pass a comma-separated list (no spaces required).
alex@example.com,alex@example.comFilter by approver email addresses. Pass a comma-separated list (no spaces required).
sam@example.comFilter by department names. Use No Department for unassigned items. Pass a comma-separated list (no spaces required).
Security,EngineeringInclusive lower bound for next review date, as Unix epoch milliseconds.
1735689600000Inclusive upper bound for next review date, as Unix epoch milliseconds.
1767225600000Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: policyBehavior, mappedFrameworkIds, mappedControlIds, notRelevantReason, versionNumber, effortEstimate, recurrence, source, publishedBy, publishedOn, addedBy, addedOn, lastModifiedBy, modifiedOn.
policyBehavior,mappedFrameworkIds,mappedControlIds