Operations 2
Documentation
Documentation
https://developer.vanta.com/docs/vanta-api-overview
Authentication
https://developer.vanta.com/docs/api-access-setup
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/vanta-resources-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Vanta Resources API
description: The Vanta REST API enables organizations to programmatically manage their security compliance posture. The API supports personnel management, vulnerability monitoring, resource scoping, document and test management, control oversight, vendor management, and custom integrations. Vanta helps automate compliance for SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR frameworks.
version: v1
contact:
name: Vanta Developer Hub
url: https://developer.vanta.com
termsOfService: https://www.vanta.com/terms
license:
name: Proprietary
url: https://www.vanta.com/terms
servers:
- url: https://api.vanta.com
description: Vanta API
security:
- OAuth2: []
tags:
- name: Resources
description: Monitored resource management and scoping
paths:
/v1/resources:
get:
operationId: listResources
summary: List Resources
description: List all monitored resources in scope for compliance.
tags:
- Resources
parameters:
- $ref: '#/components/parameters/pageSize'
- $ref: '#/components/parameters/pageCursor'
- name: resourceType
in: query
schema:
type: string
description: Filter by resource type (e.g., Computer, Repository, CloudResource)
responses:
'200':
description: Paginated list of resources
content:
application/json:
schema:
$ref: '#/components/schemas/ResourceListResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'429':
$ref: '#/components/responses/RateLimited'
/v1/computers:
get:
operationId: listComputers
summary: List Monitored Computers
description: List all monitored computers with compliance status including screenlock, encryption, antivirus, and password management status.
tags:
- Resources
parameters:
- $ref: '#/components/parameters/pageSize'
- $ref: '#/components/parameters/pageCursor'
- name: complianceStatus
in: query
schema:
type: string
enum:
- COMPLIANT
- NON_COMPLIANT
description: Filter computers by compliance status
responses:
'200':
description: Paginated list of monitored computers
content:
application/json:
schema:
$ref: '#/components/schemas/ComputerListResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'429':
$ref: '#/components/responses/RateLimited'
components:
schemas:
Resource:
type: object
properties:
id:
type: string
description: Unique resource identifier
type:
type: string
description: Resource type (Computer, Repository, CloudResource, etc.)
name:
type: string
description: Resource name
ownerId:
type: string
nullable: true
description: User ID of the resource owner
inScope:
type: boolean
description: Whether this resource is in compliance scope
createdAt:
type: string
format: date-time
description: When this resource was first observed
Computer:
type: object
properties:
id:
type: string
description: Unique computer identifier
hostname:
type: string
description: Computer hostname
osName:
type: string
description: Operating system name
osVersion:
type: string
description: Operating system version
userId:
type: string
nullable: true
description: Assigned user ID
screenlockEnabled:
type: boolean
description: Whether screenlock is enabled
diskEncryptionEnabled:
type: boolean
description: Whether disk encryption is enabled
antivirusInstalled:
type: boolean
description: Whether antivirus software is installed
passwordManagerInstalled:
type: boolean
description: Whether password manager is installed
isCompliant:
type: boolean
description: Overall compliance status
lastCheckedAt:
type: string
format: date-time
nullable: true
description: Last time compliance was checked
ComputerListResponse:
type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/Computer'
pageInfo:
$ref: '#/components/schemas/PageInfo'
PageInfo:
type: object
properties:
pageSize:
type: integer
description: Number of items returned
nextPageCursor:
type: string
nullable: true
description: Cursor for the next page of results
hasNextPage:
type: boolean
description: Whether there are more items after this page
Error:
type: object
properties:
error:
type: string
description: Error code
message:
type: string
description: Human-readable error description
details:
type: array
items:
type: string
description: Additional error details
ResourceListResponse:
type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/Resource'
pageInfo:
$ref: '#/components/schemas/PageInfo'
parameters:
pageSize:
name: pageSize
in: query
schema:
type: integer
minimum: 1
maximum: 100
default: 10
description: Number of items to return per page (1-100)
pageCursor:
name: pageCursor
in: query
schema:
type: string
description: Cursor for pagination — start from the item following this cursor
responses:
RateLimited:
description: Rate limit exceeded
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
Unauthorized:
description: Unauthorized — missing or invalid access token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
securitySchemes:
OAuth2:
type: oauth2
flows:
clientCredentials:
tokenUrl: https://api.vanta.com/oauth/token
scopes:
vanta.read: Read access to Vanta data
vanta.write: Write access to Vanta data
connectors.self:read-resource: Read connector resources
connectors.self:write-resource: Write connector resources
auditor-api.audit:read: Read audit data
auditor-api.auditor:read: Read auditor data