# Drata > Drata is a continuous security and compliance automation platform for SOC 2, ISO 27001, > HIPAA, PCI DSS, GDPR and other frameworks. It ships a 197-operation Public REST API v2, the > acquired SafeBase Trust API, a hosted remote MCP server, and a Custom Connections framework > for pushing external data in as compliance evidence. Generated by API Evangelist on 2026-08-27. Drata serves no llms.txt of its own (https://developers.drata.com/llms.txt -> 404, https://mcp.drata.com/llms.txt -> 404). ## What an agent needs to know first - Public API v2 base: https://public-api.drata.com/public/v2 (EU: https://public-api.eu.drata.com/public/v2, APAC: https://public-api.apac.drata.com/public/v2) - Auth: `Authorization: Bearer `. A long-lived Drata API key, not a JWT. Created under Settings -> API Keys; shown once; optional source-IP allowlist; scopes chosen as Custom / All read / All read and write. Revocation and expiry are permanent. - Rate limit: 500 requests/minute **per unique source IP** (not per key, not per tenant). 429 + Retry-After on exhaustion. No RateLimit-* headers. - Pagination: cursor. Send `cursor`, `size`, `sort`, `sortDir`; read `pagination.cursor`; stop when it is absent. `includeTotalCount` is opt-in. - Sparse payloads: use `expand[]` to pull related objects (70 operations support it). - Tenancy: 64 operations are workspace-scoped in the PATH (`{workspaceId}`). An entity id is only meaningful inside its workspace. - **412 on everything** until a Drata administrator accepts the API terms and conditions in the app. Valid credentials and correct scopes are not sufficient. - **402** on 37 operations means the tenant's plan lacks the entitlement. Widening scopes will not clear it. - Errors are a vendor envelope `{name, statusCode, message, code, debugInfo?}` — not RFC 9457. `code` is a Drata-internal number with no public registry. - **No idempotency keys.** A retried POST can duplicate. List and match before retrying. - **No reversal path.** 20 DELETE operations, zero restore/undo/unarchive operations, and no recovery window published anywhere. Deletes destroy audit evidence permanently. - **No sandbox.** There is no test tenant, no demo credential and no magic test identifier. - Unstable operations are marked with a 🧪 emoji in the summary. Zero operations use the OpenAPI `deprecated` flag. ## Contracts - Drata Public API v2 (OpenAPI 3.0.0, 132 paths, 197 operations, 520 schemas): https://developers.drata.com/openapi/reference/v2/overview/ - SafeBase Trust API (OpenAPI 3.1.0, 29 paths, 41 operations), base https://app.safebase.io/api/ext/v1/rest, auth `x-sb-api-key`: https://docs.safebase.io/reference/getaccounts ## Agent surfaces - MCP server (beta, hosted, remote): https://mcp.drata.com/mcp/ EU https://mcp-euc1.drata.com/mcp/ · APAC https://mcp-apse2.drata.com/mcp/ - MCP auth: OAuth 2.x + PKCE, discoverable at https://mcp.drata.com/.well-known/oauth-protected-resource (33 scopes) and https://mcp.drata.com/.well-known/oauth-authorization-server - MCP setup: https://developers.drata.com/developer-portal/v2/recipes/mcp-oauth-setup/ - Access is the intersection of granted OAuth scopes and the user's Drata role — a scope never widens what a user can see. - No A2A agent card is served on any Drata host. ## API domains (Public API v2) Assets · Audits · Audit Requests · Background Checks · Company · Control Library · Control Notes · Control Owners · Controls · Custom Connections · Custom Data Records · Custom Field Definitions · Device Documents · Devices · Events · Evidence · Evidence Library · Frameworks · Groups · HRIS User Identities · Monitoring Tests · Personnel · Policies · Policy Languages · Procurement Connection Mappings · Risk Documents · Risk Library · Risk Notes · Risk Registers · Risks · Tasks · Uploads · User Documents · User's Assigned Policies · Users and Roles · Vendor Documents · Vendor Security Reviews · Vendor Types · Vendors · Workspaces ## Docs - Developer portal: https://developers.drata.com/ - API reference: https://developers.drata.com/openapi/reference/v2/overview/ - Create an API key: https://developers.drata.com/developer-portal/v2/recipes/create-an-api-key/ - Custom Connections recipe: https://developers.drata.com/developer-portal/v2/recipes/custom-connections/ - Custom Fields recipe: https://developers.drata.com/developer-portal/v2/recipes/custom-fields/ - Help centre API article: https://help.drata.com/en/articles/6695964-drata-public-api - Product updates (dated): https://drata.com/updates - Status page (with JSON API): https://status.drata.com/ - Trust centre: https://trust.drata.com/ ## Client libraries Drata ships no working first-party SDK. github.com/drata/sdk-go is a two-file placeholder (README reads "# sdk-gopher") never published to proxy.golang.org; github.com/drata/sdk-php is an empty composer metapackage that 404s on Packagist; the npm package `drata` (1.0.1, 2024-06-06, published by drata_packages) has no dependencies and no code path to the V2 API. First-party tooling that does work: the drata-agent desktop app (3.9.0, 2025-10-28) and the compliance-as-code-action GitHub Action (v1.0.1, 2025-12-01). Everything else on npm is third-party. See packages/drata-packages.yml. ## Repo artifacts - openapi/drata-api-v2-openapi.yml — harvested Drata Public API v2 contract - openapi/drata-safebase-trust-api-openapi.yml — harvested SafeBase Trust API contract - mcp/drata-mcp.yml, mcp/drata-tool-crosswalk.yml - scopes/drata-scopes.yml — 33 MCP OAuth scopes with roles - conventions/drata-conventions.yml — pagination, expansion, idempotency, reversibility - errors/drata-problem-types.yml — error envelope and status semantics - lifecycle/drata-lifecycle.yml — versioning, status page, deprecation gap - conformance/drata-conformance.yml — standards declared and absent - data-model/drata-data-model.yml — entity graph - rate-limits/drata-rate-limits.yml, plans/drata-plans-pricing.yml - packages/drata-packages.yml, well-known/drata-well-known.yml - skills/ — five packaged agent skills grounded in real operationIds - overlays/drata-api-v2-overlay.yaml — API Evangelist annotations