Home
Providers
MetricStream
MetricStream
MetricStream is a San Jose, California based enterprise software company and a market leader in integrated Governance, Risk, and Compliance (GRC) management, serving large regulated organizations across banking and financial services, insurance, healthcare, life sciences, energy, utilities, telecom, technology and manufacturing. Its AI-first Connected GRC platform unifies enterprise and operational risk, regulatory and corporate compliance, policy and document management, internal audit and SOX, IT and cyber risk, third-party and vendor risk, operational resilience and business continuity, ESG, and case and incident management on one data core. MetricStream publishes a public API developer portal describing its Business REST APIs — a family of OpenAPI-derived REST modules covering GRC Foundation objects, Issues, Loss Event Management, Metrics, Risk Assessments, Regulatory Engagements, Surveys and Self Assessment & Testing — that customers, partners and internal developers use to move GRC data in and out of a MetricStream instance over HTTPS.
MetricStream publishes 8 APIs on the APIs.io network. Tagged areas include Company, Governance, Risk, Compliance, and GRC.
MetricStream’s developer surface includes API reference, documentation, engineering blog, support, signup flow, authentication, changelog, and 18 more developer resources.
8 APIs
On this page
Kin Score
APIs 8
Pricing Plans 1
Rate Limits 1
Security Posture 4
Resources 25
apis.yml
18 Operational Transparency
Composite quality — 29.9/100 · thin
Agent readiness — 9/100 · agent aware
Individual APIs this provider publishes, each with its own machine-readable definition.
Scroll for all 8
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Get Started 2
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 2
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 5
Pagination, idempotency, versioning, errors, and events
Build 2
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Source (apis.yml)
aid: metricstream
name: MetricStream
description: MetricStream is a San Jose, California based enterprise software company and a market leader in integrated Governance,
Risk, and Compliance (GRC) management, serving large regulated organizations across banking and financial services, insurance,
healthcare, life sciences, energy, utilities, telecom, technology and manufacturing. Its AI-first Connected GRC platform
unifies enterprise and operational risk, regulatory and corporate compliance, policy and document management, internal audit
and SOX, IT and cyber risk, third-party and vendor risk, operational resilience and business continuity, ESG, and case and
incident management on one data core. MetricStream publishes a public API developer portal describing its Business REST
APIs — a family of OpenAPI-derived REST modules covering GRC Foundation objects, Issues, Loss Event Management, Metrics,
Risk Assessments, Regulatory Engagements, Surveys and Self Assessment & Testing — that customers, partners and internal
developers use to move GRC data in and out of a MetricStream instance over HTTPS.
url: https://raw.githubusercontent.com/api-evangelist/metricstream/refs/heads/main/apis.yml
deliveryModel:
model: saas
open_source: false
commercial: true
callable_host: false
label: Hosted service · you call their endpoint
confidence: medium
source:
- pricing
generated: '2026-08-28'
method: derived
accessModel:
pricing: unknown
onboarding: open
trial: false
try_now: false
public: true
label: Open access
confidence: medium
source:
- authentication
- rate-limits
- security
generated: '2026-09-02'
method: derived
image: https://www.metricstream.com/sites/default/files/2025-05/metricstream-logo.png
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-25'
modified: '2026-08-25'
tags:
- Company
- Governance
- Risk
- Compliance
- GRC
- Audit
- Enterprise Software
- Regulatory Technology
- Cyber Risk
- Third-Party Risk
- Operational Resilience
- ESG
tags_raw:
- Company
- Governance
- Risk
- Compliance
- GRC
- Audit
- Enterprise Software
- Regulatory Technology
- Cyber Risk
- Third Party Risk
- Operational Resilience
- ESG
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
- FN: APIs.json
email: info@apis.io
apis:
- aid: metricstream-grc-foundation
name: MetricStream GRC Foundation APIs
description: Business REST APIs over the GRC Foundation object model — Area of Compliance, Asset, Asset Class, Control,
Evidence, Exception, Financial Accounts, Function, Framework/Model Reference, Objectives, Process, Product, Question &
Procedure, Reference, Regulatory Body, Requirement, Risk and Standard. Each entity exposes the same six-operation surface
(single read, single create, single patch, plus bulk collections read, bulk create and bulk patch), for 108 documented
operations.
humanURL: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcGRC%20API%20Overview.html
baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
tags:
- GRC
- Risk
- Compliance
- Controls
properties:
- type: APIReference
url: https://www.metricstream.com/api-developer-portal.html
- type: Documentation
url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcGRC%20API%20Overview.html
- aid: metricstream-issues
name: MetricStream Issues APIs
description: Business REST APIs for the Issues module — reporting issues and viewing issue details, so first-line users
and upstream systems can flag weaknesses, gaps in internal controls and process deficiencies into MetricStream.
humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsIsmISM-API-Overview.html
baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
tags:
- Issues
- Compliance
properties:
- type: Documentation
url: https://assets.metricstream.com/pdf/Developer-Portal/MsIsmISM-API-Overview.html
- type: APIReference
url: https://assets.metricstream.com/pdf/Developer-Portal/Issues_API/MsIsmIssue.html
- aid: metricstream-loss-event-management
name: MetricStream Loss Event Management APIs
description: Business REST APIs for operational loss data — internal and external loss events, impacts, approval (loss)
rules, default currency configuration and risk/regulatory event type mapping. 36 documented operations across six resources.
humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Loss_Event_Managment_API/MslsmLSM%20API%20Overview.html
baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
tags:
- Operational Risk
- Loss Events
properties:
- type: Documentation
url: https://assets.metricstream.com/pdf/Developer-Portal/Loss_Event_Managment_API/MslsmLSM%20API%20Overview.html
- aid: metricstream-metrics
name: MetricStream Metrics APIs
description: Business REST APIs for KRI/KPI metric definitions and metric data entry — create and maintain metric definitions
and post metric data points into the GRC platform.
humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Metric_API/MsMetMET%20API%20Overview.html
baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
tags:
- Metrics
- KRI
properties:
- type: Documentation
url: https://assets.metricstream.com/pdf/Developer-Portal/Metric_API/MsMetMET%20API%20Overview.html
- aid: metricstream-risk-assessments
name: MetricStream Risk Assessments APIs
description: Business REST APIs for risk assessment tasks and the setup of risk aggregation weights used when rolling assessment
scores up a risk hierarchy.
humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Risk_Assemment_API/MsRskRSK%20API%20Overview.html
baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
tags:
- Risk Assessment
properties:
- type: Documentation
url: https://assets.metricstream.com/pdf/Developer-Portal/Risk_Assemment_API/MsRskRSK%20API%20Overview.html
- aid: metricstream-regulatory-engagements
name: MetricStream Regulatory Engagements APIs
description: Business REST APIs for the Regulatory Engagement module — engagements with regulators and the tasks raised
under them.
humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Regulatory_Engg_API/MsRenREN%20API%20Overview.html
baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
tags:
- Regulatory
- Engagement
properties:
- type: Documentation
url: https://assets.metricstream.com/pdf/Developer-Portal/Regulatory_Engg_API/MsRenREN%20API%20Overview.html
- aid: metricstream-surveys
name: MetricStream Surveys APIs
description: Business REST APIs for the Survey/Questionnaire module — creating questionnaires and initiating survey, scorecard
and certification campaigns.
humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsQsmQSM-API-Overview.html
baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
tags:
- Surveys
- Questionnaires
properties:
- type: Documentation
url: https://assets.metricstream.com/pdf/Developer-Portal/MsQsmQSM-API-Overview.html
- aid: metricstream-self-assessment-testing
name: MetricStream Self Assessment & Testing APIs
description: Business REST APIs for the Compliance module's test and self-assessment plans — creating and maintaining the
plans that drive control testing cycles.
humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsCmpCMP-API-Overview.html
baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
tags:
- Controls Testing
- Self Assessment
properties:
- type: Documentation
url: https://assets.metricstream.com/pdf/Developer-Portal/MsCmpCMP-API-Overview.html
common:
- type: TrustCenter
url: security/metricstream-trust-center.yml
- type: Website
url: https://www.metricstream.com/
- type: DeveloperPortal
url: https://www.metricstream.com/developer-portal.html
- type: APIReference
url: https://www.metricstream.com/api-developer-portal.html
- type: Documentation
url: https://www.metricstream.com/platform/apis.htm
- type: Blog
url: https://www.metricstream.com/blog
- type: GitHubOrganization
url: https://github.com/MetricStream
- type: Support
url: https://www.metricstream.com/about-us/lets-talk.html
- type: SignUp
url: https://www.metricstream.com/about-us/get-started.htm
- type: TermsOfService
url: https://www.metricstream.com/customer-agreements
- type: PrivacyPolicy
url: https://www.metricstream.com/about-us/privacy-policy.htm
- type: Compliance
url: conformance/metricstream-conformance.yml
- type: LLMsTxt
url: llms/metricstream-llms.txt
- type: Packages
url: packages/metricstream-packages.yml
- type: Conformance
url: conformance/metricstream-conformance.yml
- type: ErrorCatalog
url: errors/metricstream-problem-types.yml
- type: Lifecycle
url: lifecycle/metricstream-lifecycle.yml
- type: Authentication
url: authentication/metricstream-authentication.yml
- type: DomainSecurity
url: security/metricstream-domain-security.yml
- type: Conventions
url: conventions/metricstream-conventions.yml
- type: DataModel
url: data-model/metricstream-data-model.yml
- type: Plans
url: plans/metricstream-plans-pricing.yml
- type: RateLimits
url: rate-limits/metricstream-rate-limits.yml
- type: AgentSkill
url: skills/_index.yml
- type: ChangeLog
url: changelog/metricstream-changelog.yml
x-enrichment:
date: '2026-08-25'
status: enriched
artifacts_added: 21
pass: local-v1
x-coverage:
state: covered
reason: no-machine-readable-spec
detail: MetricStream publishes a real, public, unauthenticated API reference — 34 swagger-codegen HTML pages under assets.metricstream.com/pdf/Developer-Portal/
describing 204 operations across 8 API families — but no downloadable OpenAPI/Swagger document exists at any probed location,
so the catalog holds the API surface as derived artifacts rather than as a contract.
evidence:
- url: https://www.metricstream.com/api-developer-portal.html
status: 200
- url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcRisk.html
status: 200
- url: https://www.metricstream.com/openapi.json
status: 404
- url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/swagger.json
status: 404
- url: https://www.metricstream.com/llms.txt
status: 200
checked: '2026-08-25'
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.
get_provider_artifactsEvery artifact this provider publishes, grouped by type.
get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
get_provider_ratingPRO — composite, band, trend and facet scores.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This provider
curl "https://apis.io/api/v1/providers/metricstream"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/metricstream/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/metricstream/evidence"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no email required.
A second provider on the same verified email joins the account you already have.