# API Overview

The Scytale API is a read-only window into your compliance program. Everything
your team manages in Scytale (the frameworks you're certifying against, the
controls that make them up, the monitors behind those controls, and the
policies, people, vendors, and risks around them) is available as structured
JSON you can query on demand. If the Scytale UI is where your team does
compliance, the API is how your other systems read it.

V1 is read-only: every endpoint is a `GET`, across seven resources, each with a
list endpoint and a single-item endpoint.

It's built for compliance, security, and engineering teams who want their
compliance data to live where the rest of their tooling does (dashboards, data
warehouses, internal apps, and automations) instead of behind a login.

## Ways teams use it

- **Live reporting, no more manual exports.** Build an always-current audit readiness board or control-status report in your BI tool, instead of exporting CSVs by hand.
- **Monitoring on your terms.** Poll control and monitoring status on a schedule and route drift into Slack, PagerDuty, or your ticketing system.
- **One source of truth.** Sync compliance data into your warehouse alongside the rest of your business data for unified analytics.
- **Compliance inside your own products.** Surface "where do we stand?" answers directly in internal portals, onboarding flows, or customer-facing trust pages.
- **Agent-ready.** Pair the API with [Scytale's MCP server](/mcp/custom-connector) so AI agents (like Claude) can answer compliance questions from the same live data.


## Base URL

| Region | Base URL |
|  --- | --- |
| US | `https://api.scytale.ai/v1` |
| EU | `https://api.eu.scytale.ai/v1` |


Note that the US host carries no region segment. Examples throughout these docs
use the US host. Substitute your own.

## A request looks like this

```bash
curl "https://api.scytale.ai/v1/controls?applicable=true" \
  -H "Authorization: Bearer $ACCESS_TOKEN"
```

Returns a paginated list of your controls (each with its owner, framework
mapping, and linked monitors), ready to drop into a report or a check.

## Where to go next

New here? Start with the [Quickstart](/getting-started/quickstart) to make your first call,
then [Authentication](/getting-started/authentication) for application and token setup. When you're ready to
build, the API Reference documents every resource, field, and filter.