aid: metricstream name: MetricStream description: MetricStream is a San Jose, California based enterprise software company and a market leader in integrated Governance, Risk, and Compliance (GRC) management, serving large regulated organizations across banking and financial services, insurance, healthcare, life sciences, energy, utilities, telecom, technology and manufacturing. Its AI-first Connected GRC platform unifies enterprise and operational risk, regulatory and corporate compliance, policy and document management, internal audit and SOX, IT and cyber risk, third-party and vendor risk, operational resilience and business continuity, ESG, and case and incident management on one data core. MetricStream publishes a public API developer portal describing its Business REST APIs — a family of OpenAPI-derived REST modules covering GRC Foundation objects, Issues, Loss Event Management, Metrics, Risk Assessments, Regulatory Engagements, Surveys and Self Assessment & Testing — that customers, partners and internal developers use to move GRC data in and out of a MetricStream instance over HTTPS. url: https://raw.githubusercontent.com/api-evangelist/metricstream/refs/heads/main/apis.yml deliveryModel: model: saas open_source: false commercial: true callable_host: false label: Hosted service · you call their endpoint confidence: medium source: - pricing generated: '2026-08-28' method: derived image: https://www.metricstream.com/sites/default/files/2025-05/metricstream-logo.png x-type: company x-source: harvest:secondary-market specificationVersion: '0.20' created: '2026-08-25' modified: '2026-08-25' tags: - Company - Governance - Risk - Compliance - GRC - Audit - Enterprise Software - Regulatory Technology - Cyber Risk - Third-Party Risk - Operational Resilience - ESG tags_raw: - Company - Governance - Risk - Compliance - GRC - Audit - Enterprise Software - Regulatory Technology - Cyber Risk - Third Party Risk - Operational Resilience - ESG maintainers: - FN: Kin Lane email: kin@apievangelist.com - FN: APIs.json email: info@apis.io apis: - aid: metricstream-grc-foundation name: MetricStream GRC Foundation APIs description: Business REST APIs over the GRC Foundation object model — Area of Compliance, Asset, Asset Class, Control, Evidence, Exception, Financial Accounts, Function, Framework/Model Reference, Objectives, Process, Product, Question & Procedure, Reference, Regulatory Body, Requirement, Risk and Standard. Each entity exposes the same six-operation surface (single read, single create, single patch, plus bulk collections read, bulk create and bulk patch), for 108 documented operations. humanURL: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcGRC%20API%20Overview.html baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0 tags: - GRC - Risk - Compliance - Controls properties: - type: APIReference url: https://www.metricstream.com/api-developer-portal.html - type: Documentation url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcGRC%20API%20Overview.html - aid: metricstream-issues name: MetricStream Issues APIs description: Business REST APIs for the Issues module — reporting issues and viewing issue details, so first-line users and upstream systems can flag weaknesses, gaps in internal controls and process deficiencies into MetricStream. humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsIsmISM-API-Overview.html baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0 tags: - Issues - Compliance properties: - type: Documentation url: https://assets.metricstream.com/pdf/Developer-Portal/MsIsmISM-API-Overview.html - type: APIReference url: https://assets.metricstream.com/pdf/Developer-Portal/Issues_API/MsIsmIssue.html - aid: metricstream-loss-event-management name: MetricStream Loss Event Management APIs description: Business REST APIs for operational loss data — internal and external loss events, impacts, approval (loss) rules, default currency configuration and risk/regulatory event type mapping. 36 documented operations across six resources. humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Loss_Event_Managment_API/MslsmLSM%20API%20Overview.html baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0 tags: - Operational Risk - Loss Events properties: - type: Documentation url: https://assets.metricstream.com/pdf/Developer-Portal/Loss_Event_Managment_API/MslsmLSM%20API%20Overview.html - aid: metricstream-metrics name: MetricStream Metrics APIs description: Business REST APIs for KRI/KPI metric definitions and metric data entry — create and maintain metric definitions and post metric data points into the GRC platform. humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Metric_API/MsMetMET%20API%20Overview.html baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0 tags: - Metrics - KRI properties: - type: Documentation url: https://assets.metricstream.com/pdf/Developer-Portal/Metric_API/MsMetMET%20API%20Overview.html - aid: metricstream-risk-assessments name: MetricStream Risk Assessments APIs description: Business REST APIs for risk assessment tasks and the setup of risk aggregation weights used when rolling assessment scores up a risk hierarchy. humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Risk_Assemment_API/MsRskRSK%20API%20Overview.html baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0 tags: - Risk Assessment properties: - type: Documentation url: https://assets.metricstream.com/pdf/Developer-Portal/Risk_Assemment_API/MsRskRSK%20API%20Overview.html - aid: metricstream-regulatory-engagements name: MetricStream Regulatory Engagements APIs description: Business REST APIs for the Regulatory Engagement module — engagements with regulators and the tasks raised under them. humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Regulatory_Engg_API/MsRenREN%20API%20Overview.html baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0 tags: - Regulatory - Engagement properties: - type: Documentation url: https://assets.metricstream.com/pdf/Developer-Portal/Regulatory_Engg_API/MsRenREN%20API%20Overview.html - aid: metricstream-surveys name: MetricStream Surveys APIs description: Business REST APIs for the Survey/Questionnaire module — creating questionnaires and initiating survey, scorecard and certification campaigns. humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsQsmQSM-API-Overview.html baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0 tags: - Surveys - Questionnaires properties: - type: Documentation url: https://assets.metricstream.com/pdf/Developer-Portal/MsQsmQSM-API-Overview.html - aid: metricstream-self-assessment-testing name: MetricStream Self Assessment & Testing APIs description: Business REST APIs for the Compliance module's test and self-assessment plans — creating and maintaining the plans that drive control testing cycles. humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsCmpCMP-API-Overview.html baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0 tags: - Controls Testing - Self Assessment properties: - type: Documentation url: https://assets.metricstream.com/pdf/Developer-Portal/MsCmpCMP-API-Overview.html common: - type: TrustCenter url: security/metricstream-trust-center.yml - type: Website url: https://www.metricstream.com/ - type: DeveloperPortal url: https://www.metricstream.com/developer-portal.html - type: APIReference url: https://www.metricstream.com/api-developer-portal.html - type: Documentation url: https://www.metricstream.com/platform/apis.htm - type: Blog url: https://www.metricstream.com/blog - type: GitHubOrganization url: https://github.com/MetricStream - type: Support url: https://www.metricstream.com/about-us/lets-talk.html - type: SignUp url: https://www.metricstream.com/about-us/get-started.htm - type: TermsOfService url: https://www.metricstream.com/customer-agreements - type: PrivacyPolicy url: https://www.metricstream.com/about-us/privacy-policy.htm - type: Compliance url: conformance/metricstream-conformance.yml - type: LLMsTxt url: llms/metricstream-llms.txt - type: Packages url: packages/metricstream-packages.yml - type: Conformance url: conformance/metricstream-conformance.yml - type: ErrorCatalog url: errors/metricstream-problem-types.yml - type: Lifecycle url: lifecycle/metricstream-lifecycle.yml - type: Authentication url: authentication/metricstream-authentication.yml - type: DomainSecurity url: security/metricstream-domain-security.yml - type: Conventions url: conventions/metricstream-conventions.yml - type: DataModel url: data-model/metricstream-data-model.yml - type: Plans url: plans/metricstream-plans-pricing.yml - type: RateLimits url: rate-limits/metricstream-rate-limits.yml - type: AgentSkill url: skills/_index.yml - type: ChangeLog url: changelog/metricstream-changelog.yml x-enrichment: date: '2026-08-25' status: enriched artifacts_added: 21 pass: local-v1 x-coverage: state: covered reason: no-machine-readable-spec detail: >- MetricStream publishes a real, public, unauthenticated API reference — 34 swagger-codegen HTML pages under assets.metricstream.com/pdf/Developer-Portal/ describing 204 operations across 8 API families — but no downloadable OpenAPI/Swagger document exists at any probed location, so the catalog holds the API surface as derived artifacts rather than as a contract. evidence: - url: https://www.metricstream.com/api-developer-portal.html status: 200 - url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcRisk.html status: 200 - url: https://www.metricstream.com/openapi.json status: 404 - url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/swagger.json status: 404 - url: https://www.metricstream.com/llms.txt status: 200 checked: '2026-08-25'