Skip to content
Notifications
Clear all

Walkthrough: Using the Drata API to build a simple compliance scorecard

2 Posts
2 Users
0 Reactions
40 Views
(@devops_rookie_james)
Reputable Member
Joined: 4 months ago
Posts: 335
Topic starter   [#15945]

Hi everyone, I've been diving into Drata at my new job to help with our SOC 2 compliance. The UI is great, but I wanted to see if I could automate pulling our compliance score into a simple dashboard we have for engineering metrics.

I found the Drata API docs pretty comprehensive, but I thought I'd share my little weekend project in case it helps other folks starting out. The goal was to fetch our overall compliance score and a few key control failure counts to display on an internal status page.

Here's the basic Python script I put together using `requests`. You'll need an API key from Drata (Settings > API > Create Key). I'm storing mine as an environment variable.

```python
import os
import requests
from datetime import datetime

DRATA_API_KEY = os.environ.get('DRATA_API_KEY')
BASE_URL = 'https://api.drata.com/public/v1'

headers = {
'Authorization': f'Bearer {DRATA_API_KEY}'
}

# Get the overall company compliance score
def get_compliance_score():
response = requests.get(f'{BASE_URL}/score', headers=headers)
response.raise_for_status()
score_data = response.json()
return score_data['data']['currentScore']

# Get a list of currently failing controls (simplified)
def get_failing_controls():
params = {'status': 'FAILED'}
response = requests.get(f'{BASE_URL}/controls', headers=headers, params=params)
response.raise_for_status()
controls_data = response.json()
return controls_data['data']

if __name__ == '__main__':
try:
score = get_compliance_score()
failing = get_failing_controls()
print(f"Compliance Score: {score}%")
print(f"Number of Failing Controls: {len(failing)}")
for control in failing[:5]: # Just show first 5
print(f" - {control['title']}")
except requests.exceptions.HTTPError as e:
print(f"API Error: {e}")
```

This is super basic, but it got me what I needed. A couple of things I learned:

* The API paginates responses. My example doesn't handle that—you'd need to loop through `meta.nextCursor` for a full list in a real dashboard.
* The control statuses are uppercase strings like `FAILED`, `PASSED`, `NOT_APPLICABLE`. I initially messed up the param because I used lowercase.
* Rate limiting is a thing. I got a 429 once when I was experimenting, so you might want to add some error handling or caching.

My next step is to put this into a scheduled job, maybe in a GitHub Action, to post a weekly summary to a Slack channel. Has anyone else built something similar? I'm especially curious about how you might structure this to pull data for specific frameworks (like SOC 2 vs HIPAA) or if there are any gotchas with the webhook integrations for real-time updates.


Learning by breaking


   
Quote
(@jacksonw)
Estimable Member
Joined: 3 months ago
Posts: 63
 

Nice write-up. I'm also new to Drata and trying to automate some reporting. Quick question on that `/score` endpoint - does it return the score for a specific framework like SOC 2, or is it a combined overall score across everything? I've been trying to map API data to our specific compliance scope.


not a buyer, just a nerd


   
ReplyQuote