Drata · OpenAPI Overlay 1.0.0

API Evangelist enhancements for the Drata Public API v2

5 actions 5 updates documentation extends openapi/drata-api-v2-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Drata's API. It is a proposal applied on top of the contract, not a document Drata publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

contactx-developer-portalx-api-referencex-getting-startedx-status-pagex-changelogx-trust-centerx-rate-limit

Targets 5

$.info
$
$.paths.*.*[?(@.summary =~ /🧪/)]
$.paths.*.delete
$.components.securitySchemes.bearer

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for the Drata Public API v2
  version: 1.0.0
extends: openapi/drata-api-v2-openapi.yml
x-provenance:
  generated: '2026-08-27'
  method: generated
  source: >-
    Derived from openapi/drata-api-v2-openapi.yml plus Drata's own published documentation.
    This overlay records API Evangelist annotations only; it never mutates the harvested spec.
  spec_origin: >-
    The base document was harvested verbatim from the Redocly developer-portal page data at
    https://developers.drata.com/page-data/openapi/reference/v2/overview/page-data.json
    (result.data.contentItem.data.redocStoreStr -> definition.data). Drata serves no
    /openapi.json on either the docs host or the API host.
actions:
- target: $.info
  description: Attach contact, licence-of-documentation and portal links the published spec omits.
  update:
    contact:
      name: Drata Support
      url: https://help.drata.com/
    x-developer-portal: https://developers.drata.com/
    x-api-reference: https://developers.drata.com/openapi/reference/v2/overview/
    x-getting-started: https://developers.drata.com/developer-portal/v2/recipes/create-an-api-key/
    x-status-page: https://status.drata.com/
    x-changelog: https://drata.com/updates
    x-trust-center: https://trust.drata.com/
- target: $
  description: >-
    Record the runtime semantics that are documented outside the contract, so an agent reading
    only the spec still learns them.
  update:
    x-rate-limit:
      limit: 500
      window: 1m
      scope: per unique source IP
      status: 429
      headers: [Retry-After]
      source: https://help.drata.com/en/articles/6695964-drata-public-api
    x-pagination:
      style: cursor
      request: [cursor, size, sort, sortDir, includeTotalCount]
      response_field: pagination.cursor
    x-expansion:
      param: 'expand[]'
      operations: 70
    x-idempotency:
      supported: false
      note: No idempotency-key mechanism is published; retried POSTs can duplicate.
    x-reversibility:
      grade: none
      note: >-
        20 DELETE operations, no restore/undo/unarchive counterpart anywhere in the contract
        and no recovery window stated in the docs. Deletes destroy compliance evidence.
    x-error-envelope:
      schema: ExceptionResponsePublicV2Dto
      rfc9457: false
      note: The `code` member is a Drata-internal numeric error code with no public registry.
    x-regions:
      us: https://public-api.drata.com/public/v2
      eu: https://public-api.eu.drata.com/public/v2
      apac: https://public-api.apac.drata.com/public/v2
    x-agent-surfaces:
      mcp: https://mcp.drata.com/mcp/
      mcp_scopes: https://mcp.drata.com/.well-known/oauth-protected-resource
- target: $.paths.*.*[?(@.summary =~ /🧪/)]
  description: >-
    Drata marks unstable operations with a 🧪 suffix on the summary. Surface that as a
    machine-readable flag, since the contract carries no `deprecated` or `x-beta` marker.
  update:
    x-stability: beta
    x-stability-source: provider summary marker (🧪)
- target: $.paths.*.delete
  description: >-
    Flag every DELETE as irreversible. Drata publishes no restore path for any of them and the
    objects being removed are audit evidence.
  update:
    x-reversible: false
    x-consequence: destructive
    x-agent-guidance: >-
      Read and persist the full resource body before deleting. There is no API to restore it.
- target: $.components.securitySchemes.bearer
  description: Clarify that the bearer credential is a long-lived API key, not a JWT.
  update:
    description: >-
      Long-lived Drata API key presented as a bearer token. Created under Settings -> API Keys;
      shown once; carries an expiry (12 months by default), an optional source-IP allowlist and
      a scope selection (Custom / All read / All read and write). Revocation and expiry are
      permanent.