Hi everyone, I've been diving into Drata at my new job to help with our SOC 2 compliance. The UI is great, but I wanted to see if I could automate pulling our compliance score into a simple dashboard we have for engineering metrics.
I found the Drata API docs pretty comprehensive, but I thought I'd share my little weekend project in case it helps other folks starting out. The goal was to fetch our overall compliance score and a few key control failure counts to display on an internal status page.
Here's the basic Python script I put together using `requests`. You'll need an API key from Drata (Settings > API > Create Key). I'm storing mine as an environment variable.
```python
import os
import requests
from datetime import datetime
DRATA_API_KEY = os.environ.get('DRATA_API_KEY')
BASE_URL = 'https://api.drata.com/public/v1'
headers = {
'Authorization': f'Bearer {DRATA_API_KEY}'
}
# Get the overall company compliance score
def get_compliance_score():
response = requests.get(f'{BASE_URL}/score', headers=headers)
response.raise_for_status()
score_data = response.json()
return score_data['data']['currentScore']
# Get a list of currently failing controls (simplified)
def get_failing_controls():
params = {'status': 'FAILED'}
response = requests.get(f'{BASE_URL}/controls', headers=headers, params=params)
response.raise_for_status()
controls_data = response.json()
return controls_data['data']
if __name__ == '__main__':
try:
score = get_compliance_score()
failing = get_failing_controls()
print(f"Compliance Score: {score}%")
print(f"Number of Failing Controls: {len(failing)}")
for control in failing[:5]: # Just show first 5
print(f" - {control['title']}")
except requests.exceptions.HTTPError as e:
print(f"API Error: {e}")
```
This is super basic, but it got me what I needed. A couple of things I learned:
* The API paginates responses. My example doesn't handle that—you'd need to loop through `meta.nextCursor` for a full list in a real dashboard.
* The control statuses are uppercase strings like `FAILED`, `PASSED`, `NOT_APPLICABLE`. I initially messed up the param because I used lowercase.
* Rate limiting is a thing. I got a 429 once when I was experimenting, so you might want to add some error handling or caching.
My next step is to put this into a scheduled job, maybe in a GitHub Action, to post a weekly summary to a Slack channel. Has anyone else built something similar? I'm especially curious about how you might structure this to pull data for specific frameworks (like SOC 2 vs HIPAA) or if there are any gotchas with the webhook integrations for real-time updates.
Learning by breaking
Nice write-up. I'm also new to Drata and trying to automate some reporting. Quick question on that `/score` endpoint - does it return the score for a specific framework like SOC 2, or is it a combined overall score across everything? I've been trying to map API data to our specific compliance scope.
not a buyer, just a nerd