Control
Control comment created
An external comment was created on an audit control. Fires once per comment.
This event is delivered only to Audit Partner accounts and is gated by the early-access audit_control_comment_webhook feature — reach out to your Vanta contact to enable it.
The payload contains only identifiers. Fetch the comment body from GET /v1/audits/{auditId}/controls/{controlId}/comments.
POST
/
v1.control.comment.created
Control comment created
curl --request POST \
--url https://your-endpoint.example.com/v1.control.comment.created \
--header 'Content-Type: application/json' \
--data '
{
"control": {
"id": "8f9e0d1c2b3a4f5e6d7c8b9a",
"auditId": "5f8d0f3b9d3f2a1b4c5d6e7f"
},
"comment": {
"id": "6a7b8c9d0e1f2a3b4c5d6e7f"
}
}
'import requests
url = "https://your-endpoint.example.com/v1.control.comment.created"
payload = {
"control": {
"id": "8f9e0d1c2b3a4f5e6d7c8b9a",
"auditId": "5f8d0f3b9d3f2a1b4c5d6e7f"
},
"comment": { "id": "6a7b8c9d0e1f2a3b4c5d6e7f" }
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
control: {id: '8f9e0d1c2b3a4f5e6d7c8b9a', auditId: '5f8d0f3b9d3f2a1b4c5d6e7f'},
comment: {id: '6a7b8c9d0e1f2a3b4c5d6e7f'}
})
};
fetch('https://your-endpoint.example.com/v1.control.comment.created', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-endpoint.example.com/v1.control.comment.created",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'control' => [
'id' => '8f9e0d1c2b3a4f5e6d7c8b9a',
'auditId' => '5f8d0f3b9d3f2a1b4c5d6e7f'
],
'comment' => [
'id' => '6a7b8c9d0e1f2a3b4c5d6e7f'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-endpoint.example.com/v1.control.comment.created"
payload := strings.NewReader("{\n \"control\": {\n \"id\": \"8f9e0d1c2b3a4f5e6d7c8b9a\",\n \"auditId\": \"5f8d0f3b9d3f2a1b4c5d6e7f\"\n },\n \"comment\": {\n \"id\": \"6a7b8c9d0e1f2a3b4c5d6e7f\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-endpoint.example.com/v1.control.comment.created")
.header("Content-Type", "application/json")
.body("{\n \"control\": {\n \"id\": \"8f9e0d1c2b3a4f5e6d7c8b9a\",\n \"auditId\": \"5f8d0f3b9d3f2a1b4c5d6e7f\"\n },\n \"comment\": {\n \"id\": \"6a7b8c9d0e1f2a3b4c5d6e7f\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-endpoint.example.com/v1.control.comment.created")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"control\": {\n \"id\": \"8f9e0d1c2b3a4f5e6d7c8b9a\",\n \"auditId\": \"5f8d0f3b9d3f2a1b4c5d6e7f\"\n },\n \"comment\": {\n \"id\": \"6a7b8c9d0e1f2a3b4c5d6e7f\"\n }\n}"
response = http.request(request)
puts response.read_bodyRelated topics
Delete a comment for a control within an auditUpdate a comment for a control within an auditCreate a comment for a control within an auditEvidence comment createdList comments for a control within an auditWas this page helpful?
⌘I
Control comment created
curl --request POST \
--url https://your-endpoint.example.com/v1.control.comment.created \
--header 'Content-Type: application/json' \
--data '
{
"control": {
"id": "8f9e0d1c2b3a4f5e6d7c8b9a",
"auditId": "5f8d0f3b9d3f2a1b4c5d6e7f"
},
"comment": {
"id": "6a7b8c9d0e1f2a3b4c5d6e7f"
}
}
'import requests
url = "https://your-endpoint.example.com/v1.control.comment.created"
payload = {
"control": {
"id": "8f9e0d1c2b3a4f5e6d7c8b9a",
"auditId": "5f8d0f3b9d3f2a1b4c5d6e7f"
},
"comment": { "id": "6a7b8c9d0e1f2a3b4c5d6e7f" }
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
control: {id: '8f9e0d1c2b3a4f5e6d7c8b9a', auditId: '5f8d0f3b9d3f2a1b4c5d6e7f'},
comment: {id: '6a7b8c9d0e1f2a3b4c5d6e7f'}
})
};
fetch('https://your-endpoint.example.com/v1.control.comment.created', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-endpoint.example.com/v1.control.comment.created",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'control' => [
'id' => '8f9e0d1c2b3a4f5e6d7c8b9a',
'auditId' => '5f8d0f3b9d3f2a1b4c5d6e7f'
],
'comment' => [
'id' => '6a7b8c9d0e1f2a3b4c5d6e7f'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-endpoint.example.com/v1.control.comment.created"
payload := strings.NewReader("{\n \"control\": {\n \"id\": \"8f9e0d1c2b3a4f5e6d7c8b9a\",\n \"auditId\": \"5f8d0f3b9d3f2a1b4c5d6e7f\"\n },\n \"comment\": {\n \"id\": \"6a7b8c9d0e1f2a3b4c5d6e7f\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-endpoint.example.com/v1.control.comment.created")
.header("Content-Type", "application/json")
.body("{\n \"control\": {\n \"id\": \"8f9e0d1c2b3a4f5e6d7c8b9a\",\n \"auditId\": \"5f8d0f3b9d3f2a1b4c5d6e7f\"\n },\n \"comment\": {\n \"id\": \"6a7b8c9d0e1f2a3b4c5d6e7f\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-endpoint.example.com/v1.control.comment.created")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"control\": {\n \"id\": \"8f9e0d1c2b3a4f5e6d7c8b9a\",\n \"auditId\": \"5f8d0f3b9d3f2a1b4c5d6e7f\"\n },\n \"comment\": {\n \"id\": \"6a7b8c9d0e1f2a3b4c5d6e7f\"\n }\n}"
response = http.request(request)
puts response.read_body