List of vendors who are in scope for this audit
Returns a list of vendors who are in scope for this audit.
End of life — this endpoint works for classic audits only; it does not support controlled audit view. It remains available for existing classic audits but will be removed once classic audits are fully phased out, so do not build new integrations on it.
Rate limit: 10 requests / minute.
curl --request GET \
--url https://api.vanta.com/v1/audits/{auditId}/vendors \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.vanta.com/v1/audits/{auditId}/vendors"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.vanta.com/v1/audits/{auditId}/vendors', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.vanta.com/v1/audits/{auditId}/vendors",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.vanta.com/v1/audits/{auditId}/vendors"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.vanta.com/v1/audits/{auditId}/vendors")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.vanta.com/v1/audits/{auditId}/vendors")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"results": {
"data": [
{
"id": "a2f7e1b9d0c3f4e5a6c7b8d8",
"name": "Vanta",
"websiteUrl": "https://www.vanta.com/",
"accountManagerName": "John Doe",
"accountManagerEmail": "john@doe.com",
"servicesProvided": "SaaS",
"additionalNotes": "Automate compliance and streamline security reviews with the leading trust management platform.",
"authDetails": {
"method": "O_AUTH",
"passwordMFA": true,
"passwordRequiresNumber": true,
"passwordRequiresSymbol": true,
"passwordMinimumLength": 16
},
"securityOwnerUserId": "6626afa6490ec920099773e7",
"businessOwnerUserId": "6626afb14c912f0a50e85619",
"contractStartDate": "2024-02-01T00:00:00.000Z",
"contractRenewalDate": "2025-02-01T00:00:00.000Z",
"contractTerminationDate": null,
"lastSecurityReviewCompletionDate": "2024-01-01T00:00:00.000Z",
"nextSecurityReviewDueDate": "2025-01-01T00:00:00.000Z",
"isVisibleToAuditors": true,
"isRiskAutoScored": true,
"category": {
"displayName": "cloudMonitoring"
},
"riskAttributeIds": [
"6626b0298acc44f8674390da",
"6626b02ea4cd9ba80d773c20"
],
"status": "MANAGED",
"inherentRiskLevel": "HIGH",
"residualRiskLevel": "MEDIUM",
"vendorHeadquarters": "USA",
"contractAmount": {
"amount": 1000000,
"currency": "USD"
},
"customFields": null,
"latestDecision": {
"status": "APPROVED",
"lastUpdatedAt": "2024-01-01T00:00:00.000Z"
},
"linkedTaskTrackerTaskProcurementRequest": {
"service": "jira",
"url": "https://random-company.atlassian.net/browse/PROJ-123"
}
}
],
"pageInfo": {
"hasNextPage": false,
"hasPreviousPage": false,
"startCursor": "6696ea0595df50d5cd6ec3b7",
"endCursor": "6696ece48eb1f98ff3d927c6"
}
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Query Parameters
Controls the maximum number of items returned in one response from the API.
1 <= x <= 100A marker or pointer, telling the API where to start fetching items for the subsequent page in a paginated dataset. Note that the requested page will not include the item that corresponds to this cursor but will start from the one immediately after this cursor.
Response
Ok
Show child attributes
Show child attributes
Was this page helpful?
curl --request GET \
--url https://api.vanta.com/v1/audits/{auditId}/vendors \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.vanta.com/v1/audits/{auditId}/vendors"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.vanta.com/v1/audits/{auditId}/vendors', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.vanta.com/v1/audits/{auditId}/vendors",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.vanta.com/v1/audits/{auditId}/vendors"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.vanta.com/v1/audits/{auditId}/vendors")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.vanta.com/v1/audits/{auditId}/vendors")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"results": {
"data": [
{
"id": "a2f7e1b9d0c3f4e5a6c7b8d8",
"name": "Vanta",
"websiteUrl": "https://www.vanta.com/",
"accountManagerName": "John Doe",
"accountManagerEmail": "john@doe.com",
"servicesProvided": "SaaS",
"additionalNotes": "Automate compliance and streamline security reviews with the leading trust management platform.",
"authDetails": {
"method": "O_AUTH",
"passwordMFA": true,
"passwordRequiresNumber": true,
"passwordRequiresSymbol": true,
"passwordMinimumLength": 16
},
"securityOwnerUserId": "6626afa6490ec920099773e7",
"businessOwnerUserId": "6626afb14c912f0a50e85619",
"contractStartDate": "2024-02-01T00:00:00.000Z",
"contractRenewalDate": "2025-02-01T00:00:00.000Z",
"contractTerminationDate": null,
"lastSecurityReviewCompletionDate": "2024-01-01T00:00:00.000Z",
"nextSecurityReviewDueDate": "2025-01-01T00:00:00.000Z",
"isVisibleToAuditors": true,
"isRiskAutoScored": true,
"category": {
"displayName": "cloudMonitoring"
},
"riskAttributeIds": [
"6626b0298acc44f8674390da",
"6626b02ea4cd9ba80d773c20"
],
"status": "MANAGED",
"inherentRiskLevel": "HIGH",
"residualRiskLevel": "MEDIUM",
"vendorHeadquarters": "USA",
"contractAmount": {
"amount": 1000000,
"currency": "USD"
},
"customFields": null,
"latestDecision": {
"status": "APPROVED",
"lastUpdatedAt": "2024-01-01T00:00:00.000Z"
},
"linkedTaskTrackerTaskProcurementRequest": {
"service": "jira",
"url": "https://random-company.atlassian.net/browse/PROJ-123"
}
}
],
"pageInfo": {
"hasNextPage": false,
"hasPreviousPage": false,
"startCursor": "6696ea0595df50d5cd6ec3b7",
"endCursor": "6696ece48eb1f98ff3d927c6"
}
}
}