Drata Risks API

Risks are potential events that could impact the security, reputation, and financial health of a company.

Business capability
Risk Identification & Assessment BC-120.20

Operations 8

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

GET /risk-registers/{riskRegisterId}/risks List risks in a register · List Risks #
Ask an LLM
“Which risks in a register are currently active?”
“Can I list a register's risks tied to a particular vendor?”
Tell an agent
List risks in register {riskRegisterId} with status {status}.
List risks in register {riskRegisterId} scoring at least {minScore}.
POST /risk-registers/{riskRegisterId}/risks Create a risk in a register · Create Risk #
Ask an LLM
“How do I add a custom risk to a risk register?”
“Can I set impact and likelihood when I log a new risk?”
Tell an agent
Create risk {title} in register {riskRegisterId}: {description}.
Log risk {title} in register {riskRegisterId} as {description} with impact {impact} and likelihood {likelihood}.
GET /risk-registers/{riskRegisterId}/risks-search Search risks within one register · Search Risks by Risk Register #
Ask an LLM
“Can I full-text search the risks inside one register?”
“Which risks in one register have a residual score above a threshold?”
Tell an agent
Search register {riskRegisterId} for risks matching {q}.
Find risks in register {riskRegisterId} owned by {ownerEmails}.
GET /risks-search Search risks across all registers · Search Risks #
Ask an LLM
“How do I search risks across every risk register I can access?”
“Can I find all risks linked to control AC-04 in any register?”
Tell an agent
Search all risk registers for {q}.
Find risks across registers mapped to control {controls}.
GET /risk-registers/{riskRegisterId}/risks/{riskId} Get a risk's details · Get Risk #
Ask an LLM
“What are the details of risk RISK-001?”
“Can I look up one risk by its string identifier instead of its number?”
Tell an agent
Get risk {riskId} in register {riskRegisterId}.
Show risk {riskId} from register {riskRegisterId} with {expand} expanded.
PUT /risk-registers/{riskRegisterId}/risks/{riskId} Update a risk · Update Risk #
Ask an LLM
“How do I change a risk's treatment plan?”
“Can I record residual impact and likelihood after treatment?”
Tell an agent
Set the treatment plan of risk {riskId} in register {riskRegisterId} to {treatmentPlan}.
Mark risk {riskId} in register {riskRegisterId} as treated on {completionDate}.
DELETE /risk-registers/{riskRegisterId}/risks/{riskId} Delete a risk · Delete Risk #
Ask an LLM
“How do I delete a risk that was logged by mistake?”
“Can a risk be removed from a register permanently?”
Tell an agent destructive · confirm first
Delete risk {riskId} from register {riskRegisterId}.
Permanently remove the risk {riskId} logged in register {riskRegisterId}.
GET /risk-registers/{riskRegisterId}/insights Get risk register insights · Get Risk Insights #
Ask an LLM
“What does the risk heatmap look like for a register?”
“Can I see risk trends over time for only certain owners?”
Tell an agent
Get risk insights for register {riskRegisterId}.
Show risk insights for register {riskRegisterId} limited to owners {ownerIds}.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/drata:drata-risks-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

drata-risks-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Drata Risks API
  description: '### What''s New in V2

    - Support for Custom Fields

    - Get and acknowledge user''s assigned policies

    - Payloads are streamlined to include only the essential information.'
  version: V2
  contact: {}
servers:
- url: https://public-api.drata.com/public/v2
- url: https://public-api.eu.drata.com/public/v2
- url: https://public-api.apac.drata.com/public/v2
tags:


# --- truncated at 32 KB (90 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/drata/refs/heads/main/openapi/drata-risks-api-openapi.yml