Want to put your evidence gathering and control testing on autopilot? Our Public API lets you do exactly that, right from the PolicyCo platform. Before you dive in, here are a few key things to know.
Each user has unique API keys
For security, every PolicyCo user can generate their own unique API key. We do this so API activity stays scoped to what that person is actually allowed to do in your organization.
If someone is set as an assignee for a specific evidence template or control test, their API key can POST and DELETE evidence for it. If multiple people need to do this, just add everyone who needs access as an assignee, and their keys will work as expected.
X-API-KEY Header
We manage authentication with an X-API-KEY header.
Documentation
This article covers the essentials. Full documentation is available separately. If you'd like one-on-one assistance, reach out through our support link and we'll schedule time with our technical team to walk you through it.
