{
 "categories": [
  "devsecops",
  "enterprise"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-10-09",
   "fact": "homepage",
   "note": "The Drata developer portal presents Public API v2 for the compliance automation platform and links a Drata MCP.",
   "source": "https://developers.drata.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "license",
   "note": "The MCP guide requires a Drata administrator to create an OAuth configuration in the tenant. That is a customer account, not a public free API.",
   "source": "https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.exists",
   "note": "The developer portal says Drata's Public API v2 is the flagship API for automating the compliance platform.",
   "source": "https://developers.drata.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.kinds[0]",
   "note": "The OAuth guide shows HTTPS calls to a tenant token URL and then to https://<api-url>/v1/<endpoint>.",
   "source": "https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.auth[0]",
   "note": "OAuth 2.0 client credentials is the recommended machine-to-machine method. The example token response uses token_type Bearer and expires_in 86400.",
   "source": "https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.auth[1]",
   "note": "The same guide contrasts OAuth with long-lived API keys and says API keys often remain valid until they are revoked.",
   "source": "https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.coverage",
   "note": "Scopes are chosen per OAuth application and include read, create, update, and delete. The opened portal does not list every v1 route.",
   "source": "https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.docs",
   "note": "Opened the Drata developer portal for Public API v2.",
   "source": "https://developers.drata.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.mcp.first_party",
   "note": "Drata documents a hosted MCP server for US, EU, and APAC. An administrator configures MCP OAuth scopes before users connect.",
   "source": "https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.data_access.export[0]",
   "note": "The token example is JSON. API calls send the bearer token to the tenant API URL.",
   "source": "https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Opened a text/plain Drata Help Center index that links implementation articles.",
   "source": "https://help.drata.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "verdict.scores.api",
   "note": "Client-credentials tokens are scoped and time-limited. The opened pages do not include a full endpoint catalog, so coverage stays partial.",
   "source": "https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "verdict.scores.mcp",
   "note": "The hosted server covers controls, policies, risks, evidence, vendors, personnel, devices, and identities. Write scopes are optional and still limited by the user's role.",
   "source": "https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[0].url",
   "note": "Opened the Drata developer portal.",
   "source": "https://developers.drata.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[1].url",
   "note": "Opened the Drata MCP setup guide. The page header said updated over 2 weeks ago.",
   "source": "https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[2].url",
   "note": "Opened the Drata API OAuth guide, dated February 24, 2026 on the page.",
   "source": "https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-09",
  "volatility": "high",
  "watch": [
   {
    "type": "docs",
    "url": "https://developers.drata.com/"
   },
   {
    "type": "docs",
    "url": "https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide"
   },
   {
    "type": "docs",
    "url": "https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api"
   }
  ]
 },
 "homepage": "https://drata.com/",
 "id": "drata",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "oauth2-client-credentials",
    "api-key"
   ],
   "coverage": "partial",
   "docs": "https://developers.drata.com/",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No UI probe was run. Drata documents a public API and a hosted MCP server. A UI automation guide was not opened.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Drata",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "vanta",
   "onetrust"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Drata",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 7,
   "rpa": null
  },
  "summary": "Drata is automatable today through its public API. This record is Drata compliance data. It is not Vanta or OneTrust. The developer portal presents Public API v2. The recommended machine-to-machine method is OAuth 2.0 client credentials. An administrator creates an OAuth application, chooses scopes, and exchanges the client secret at the tenant token URL. The documented example token expires in 86400 seconds and is sent as Authorization: Bearer. Drata also documents long-lived API keys as the older credential. The hosted MCP server is at https://mcp.drata.com/mcp/, https://mcp-euc1.drata.com/mcp/, and https://mcp-apse2.drata.com/mcp/. An administrator creates the MCP OAuth configuration and selects scopes. Users then connect a client. Access is the intersection of those scopes and the user's Drata role. Documented areas include controls, policies, risks, evidence, frameworks, vendors, personnel, devices, and identities. Some scopes allow create, update, and delete. An SDK, a CLI, and connector catalogs were not opened. Computer-use viability is unassessed. The API scores 7 and is the best path. The MCP scores 7.\n"
 }
}