{"id":3460,"date":"2026-08-13T08:40:05","date_gmt":"2026-08-13T07:40:05","guid":{"rendered":"https:\/\/icomply.pm\/api-integrations\/"},"modified":"2026-08-21T13:44:17","modified_gmt":"2026-08-21T12:44:17","slug":"api-integrations","status":"publish","type":"page","link":"https:\/\/icomply.pt\/en\/documentation\/api-integrations\/","title":{"rendered":"API &#038; Integrations"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"3460\" class=\"elementor elementor-3460 elementor-3255\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ad79a98 e-flex e-con-boxed e-con e-parent\" data-id=\"ad79a98\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;gradient&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-87add6d e-con-full e-flex e-con e-child\" data-id=\"87add6d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a43950b elementor-icon-list--layout-inline elementor-align-start elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"a43950b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items elementor-inline-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"\/\">\n\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Documentation<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">\/<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><span style=\"color: #c3ccd8\">API &amp; integrations<\/span><\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8741512 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"8741512\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Technical \u00b7 12 min<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-35df795 elementor-widget__width-initial elementor-widget elementor-widget-image-box\" data-id=\"35df795\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><div class=\"elementor-image-box-title\">API &amp; integrations<\/div><p class=\"elementor-image-box-description\">REST API, webhooks and integrating iComply with your tech stack \u2014 to collect evidence automatically rather than requesting it by email.\n\n<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-308edd5 e-flex e-con-boxed e-con e-parent\" data-id=\"308edd5\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2a69500 content_34535345 elementor-widget elementor-widget-text-editor\" data-id=\"2a69500\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<div class=\"icbody\" style=\"min-width: 0;\"><p style=\"font-size: clamp(16.5px,1.25vw,18.5px); color: #2a3644;\">Most of the compliance evidence already exists within your systems \u2014 in the identity directory, the vulnerability management system, the ticketing system and HR. The API is designed to automatically feed this evidence into the controls, complete with date and source, rather than someone having to take screenshots every quarter. <\/p><h2 id=\"disponibilidade\">Availability<\/h2><p>Access to the API and webhooks is available on the <strong>Enterprise <\/strong>plan and as an add-on on the <strong>Professional<\/strong> plans. See <a href=\"https:\/\/icomply.pt\/pt\/precos\/\">Pricing<\/a>. <\/p><h2 id=\"autenticacao\">Authentication<\/h2><p>The API is a REST API over HTTPS and uses <strong>service tokens<\/strong> for authentication. Create the token in <code>Administra\u00e7\u00e3o \u2192 API<\/code> assigning it the minimum required scope (domains and operations). Tokens may have an expiry date and can be revoked at any time.  <\/p><div class=\"icpre\"><code>curl https:\/\/api.icomply.pt\/v1\/controls \\<br\/>  -H \"Authorization: Bearer $ICOMPLY_TOKEN\" \\<br\/>  -H \"Accept: application\/json\"<\/code><\/div><p>Never place tokens in version-controlled source code or in the browser. Use your infrastructure\u2019s secret vault. Every use of the token is recorded in the audit log.  <\/p><h2 id=\"recursos\">Key features<\/h2><ul><li><code>\/v1\/controls<\/code> \u2014 to review and update controls, statuses and responsible persons.<\/li><li><code>\/v1\/requirements<\/code> \u2014 framework requirements and their corresponding mappings.<\/li><li><code>\/v1\/evidence<\/code> \u2014 load, list and replace records.<\/li><li><code>\/v1\/risks<\/code> \u2014 risk registration, scoring and linking to controls.<\/li><li><code>\/v1\/tasks<\/code> \u2014 tasks, deadlines and people responsible.<\/li><li><code>\/v1\/findings<\/code> \u2014 audit findings and CAPA actions.<\/li><li><code>\/v1\/audits<\/code> \u2014 audits, scope and results.<\/li><li><code>\/v1\/vendors<\/code> \u2014 suppliers, assessments and criticality.<\/li><li><code>\/v1\/reports<\/code> \u2014 generation of status reports by framework.<\/li><\/ul><h2 id=\"evidencia\">Upload evidence via API<\/h2><p>The most valuable use case. Upload the file and link it to one or more controls; the platform handles version control and propagation to all mapped requirements. <\/p><div class=\"icpre\"><p><code><code>POST \/v1\/evidence<br\/>Authorization: Bearer $ICOMPLY_TOKEN<br\/>Content-Type: multipart\/form-data<\/code><\/code><\/p><p>file=@access-review-2026-Q2.pdf<br\/>control_ids[]=ctrl_mfa_enforced<br\/>control_ids[]=ctrl_access_review<br\/>valid_from=2026-07-01<br\/>valid_until=2026-10-01<br\/>source=okta-automation<\/p><\/div><p>The <code>source<\/code> field is important: it indicates that the evidence was generated automatically and by which system \u2014 information that auditors value, as it eliminates manual intervention from the process.<\/p><h2 id=\"webhooks\">Webhooks<\/h2><p>Instead of querying the API periodically, subscribe to events. Configure endpoints in <code>Administra\u00e7\u00e3o \u2192 Webhooks<\/code>. <\/p><ul><li><code>control.status_changed<\/code> \u2014 a control has changed state.<\/li><li><code>evidence.expiring<\/code> \u2014 evidence that is nearing its expiry date.<\/li><li><code>evidence.expired<\/code> \u2014 The evidence has expired.<\/li><li><code>task.assigned<\/code> \/ <code>task.overdue<\/code> \u2014 tasks.<\/li><li><code>finding.created<\/code> \u2014 new audit finding.<\/li><li><code>capa.due<\/code> \u2014 CAPA share with a short-term expiry date.<\/li><li><code>risk.escalated<\/code> \u2014 risk has risen above the defined tolerance level.<\/li><\/ul><p>Each delivery is signed using HMAC-SHA256 in the <code>X-iComply-Signature<\/code> header. Always validate the signature before processing. Failed deliveries are retried using exponential backoff.  <\/p><h2 id=\"integracoes\">Typical integrations<\/h2><h3>Identity and access<\/h3><p>Connect your identity provider (Entra ID, Okta, Google Workspace) to provide access audit logs and MFA evidence. Combined with SCIM, this eliminates the most common source of non-compliance: active accounts belonging to former employees. <\/p><h3>Security and vulnerabilities<\/h3><p>Submit findings from your vulnerability management tool to the relevant controls, along with a remediation SLA. The evidence for the control is now its actual status, not a declaration. <\/p><h3>Tickets and changes<\/h3><p>Integrate Jira, ServiceNow or an equivalent system so that remediation and CAPA tasks are housed where technical teams already work, whilst keeping the status synchronised in iComply.<\/p><h3>HR<\/h3><p>Track enrolment, completion and exit from compulsory training \u2014 providing direct evidence for People Governance and safety awareness checks.<\/p><h3>Communication<\/h3><p>Send notifications about at-risk checks, expired evidence and new findings to Slack or Teams via a webhook.<\/p><h3>BI and reporting<\/h3><p>Export compliance and risk reports to Power BI, Looker or Tableau for executive dashboards alongside other business metrics.<\/p><h2 id=\"limites\">Limits and pagination<\/h2><ul><li><strong>Rate limit <\/strong>\u2014 per token; the <code>X-RateLimit-Remaining<\/code> and <code>X-RateLimit-Reset<\/code> headers indicate the status. Handle <code>429<\/code> with backoff. <\/li><li><strong>Pagination <\/strong>\u2014 by cursor, using <code>limit<\/code> and <code>cursor<\/code>; follow <code>next_cursor<\/code> until it reaches a null value.<\/li><li><strong>Idempotence<\/strong> \u2014 send <code>Idempotency-Key<\/code> in write operations to avoid duplicates on retries.<\/li><li><strong>Versioning<\/strong> \u2014 the version is included in the path (<code>\/v1\/<\/code>). Incompatible changes only occur in new versions, with a pre-announced overlap period. <\/li><\/ul><h2 id=\"erros\">Error handling<\/h2><p>Error responses follow a consistent format, comprising a machine-readable code and a message for humans:<\/p><div class=\"icpre\"><code>{<br\/>  \"error\": {<br\/>    \"code\": \"control_not_found\",<br\/>    \"message\": \"No control matches id 'ctrl_xyz'.\",<br\/>    \"request_id\": \"req_01J9F2K7Q\"<br\/>  }<br\/>}<\/code><\/div><p>Always enter <code>request_id<\/code> \u2014 it really speeds up the support process when you need to investigate a specific case with our team.<\/p><h2 id=\"boas-praticas\">Best practice<\/h2><ul><li><strong>One token per integration.<\/strong> It makes it easier to revoke without affecting the rest.<\/li><li><strong>Minimum scope.<\/strong> A token that only carries evidence does not need to read the risk log.<\/li><li><strong>Periodic rotation.<\/strong> Set the expiry time and treat rotation as a control with a set frequency.<\/li><li><strong>Choose webhooks over polling.<\/strong> Less load, faster response.<\/li><li><strong>Always enter <\/strong><code>source<\/code> and expiry dates in the automated records \u2014 otherwise, half the value will be lost during the audit.<\/li><\/ul><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-aaf443c e-con-full max_w_280 e-flex e-con e-child\" data-id=\"aaf443c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-98cb5c0 elementor-widget__width-inherit elementor-widget elementor-widget-table-of-contents\" data-id=\"98cb5c0\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;headings_by_tags&quot;:[&quot;h2&quot;],&quot;exclude_headings_by_selector&quot;:[],&quot;marker_view&quot;:&quot;bullets&quot;,&quot;icon&quot;:{&quot;value&quot;:&quot;&quot;,&quot;library&quot;:&quot;&quot;},&quot;min_height&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:0,&quot;sizes&quot;:[]},&quot;min_height_tablet_extra&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"table-of-contents.default\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-toc__header\">\n\t\t\t\t\t\t<h4 class=\"elementor-toc__header-title\">\n\t\t\t\tOn this page\t\t\t<\/h4>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div id=\"elementor-toc__98cb5c0\" class=\"elementor-toc__body\">\n\t\t\t<div class=\"elementor-toc__spinner-container\">\n\t\t\t\t<svg class=\"elementor-toc__spinner eicon-animation-spin e-font-icon-svg e-eicon-loading\" aria-hidden=\"true\" viewBox=\"0 0 1000 1000\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M500 975V858C696 858 858 696 858 500S696 142 500 142 142 304 142 500H25C25 237 238 25 500 25S975 237 975 500 763 975 500 975Z\"><\/path><\/svg>\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-071cf1f e-con-full e-flex e-con e-child\" data-id=\"071cf1f\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6b25e2f elementor-widget__width-inherit elementor-widget elementor-widget-image-box\" data-id=\"6b25e2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><div class=\"elementor-image-box-title\">Would you like to automate the collection of evidence?<\/div><p class=\"elementor-image-box-description\">We design the integrations in collaboration with your technical team and provide the test credentials.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-702ed44 elementor-align-justify elementor-widget__width-inherit elementor-widget elementor-widget-button\" data-id=\"702ed44\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/icomply.pt\/en\/contact\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Talk to the team<br \/><\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-552aea1 e-flex e-con-boxed e-con e-parent\" data-id=\"552aea1\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-c3d1a26 elementor-widget elementor-widget-heading\" data-id=\"c3d1a26\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Continue reading\n<\/h3>\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-babdaa9 e-con-full e-grid e-con e-child\" data-id=\"babdaa9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<a class=\"elementor-element elementor-element-4137abf e-con-full e-flex e-con e-child\" data-id=\"4137abf\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\" href=\"https:\/\/icomply.pt\/en\/documentation\/administration-access\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b9387f5 elementor-widget__width-inherit elementor-widget elementor-widget-image-box\" data-id=\"b9387f5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><div class=\"elementor-image-box-title\">Administration &amp; access<\/div><p class=\"elementor-image-box-description\">Profiles, permissions, SSO, billing and organisation settings.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-7a9bac5 e-con-full e-flex e-con e-child\" data-id=\"7a9bac5\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\" href=\"https:\/\/icomply.pt\/en\/documentation\/evidence-audits\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e482f8c elementor-widget__width-inherit elementor-widget elementor-widget-image-box\" data-id=\"e482f8c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><div class=\"elementor-image-box-title\">Evidence &amp; audits<\/div><p class=\"elementor-image-box-description\">Collect reusable evidence and carry out audit and CAPA workflows.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-18c275c e-con-full e-flex e-con e-child\" data-id=\"18c275c\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\" href=\"https:\/\/icomply.pt\/en\/documentation\/controls-mapping\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9212b4f elementor-widget__width-inherit elementor-widget elementor-widget-image-box\" data-id=\"9212b4f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><div class=\"elementor-image-box-title\">Controls &amp; mapping<\/div><p class=\"elementor-image-box-description\">Map controls once and reuse them across all frameworks.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Documentation \/ API &amp; integrations Technical \u00b7 12 min API &amp; integrations REST API, webhooks and integrating iComply with your tech stack \u2014 to collect evidence automatically rather than requesting it by email. Most of the compliance evidence already exists within your systems \u2014 in the identity directory, the vulnerability management system, the ticketing system [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":2895,"menu_order":6,"comment_status":"closed","ping_status":"closed","template":"elementor_header_footer","meta":{"_ice_seo_score":0,"_ice_review":"","footnotes":""},"class_list":["post-3460","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/pages\/3460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/comments?post=3460"}],"version-history":[{"count":6,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/pages\/3460\/revisions"}],"predecessor-version":[{"id":3854,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/pages\/3460\/revisions\/3854"}],"up":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/pages\/2895"}],"wp:attachment":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media?parent=3460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}