---
title: "SecBoost API | Assessment integrations and automation"
source: "https://secboost.com/api/"
---

API and integrations

# Connect your tools to your assessment work.

Connect scripts, agents and integration tools to read and update assessment records, attach evidence and generate documents. Use scoped read/write tokens for the work you want to automate.

 [Discuss your integration](<https://secboost.com/contact/>)  [Developer resources](<https://secboost.com/api/#developer-resources>) 

Your tools, connected to SecBoost

**Scripts, agents and integrations** Preparation, evidence collection and assessment work 

**Scoped API token** Read/write access with selected permissions 

**Your SecBoost records** System context, controls, evidence, assessments and documents 

Retrieve records and outputs. Send updates, evidence and generation requests.

## Support preparation and assessment.

Use the API for the repeated work around an assessment, while keeping records in the same project workflow.

### Prepare a system

Set up organisation and system context, configure assessment projects and maintain supporting contacts and registers using the appropriate scoped credentials.

### Keep evidence connected

Update implementation notes, upload configuration exports and link supporting records to the relevant control. Maintain evidence metadata as the system changes.

### Perform assessment work

Read authorised evidence and assessment information, record assessment details and perform permitted workflow transitions. The normal review and approval rules still apply.

### Produce and retrieve documents

Maintain document-library content, request Documentation Suite generation, check its status and download the resulting output when it is ready.

## Give your integration the access it needs.

Choose a target, select the relevant permissions and enable read/write access to maintain records and run supported workflows. Set an expiry and revoke the token when it is no longer needed.

API requests follow the owner’s current access, the product tier and normal workflow rules. Approval permissions are selected explicitly.

### Only need your agent to report?

A read-only token lets it summarise assessment progress, review evidence inventories, download existing outputs or copy permitted records into another system, without editing SecBoost.

Use this option when you want an agent to retrieve data but keep changes in your hands.

## Explore the developer resources.

Browse the API guide and permissions, or download the OpenAPI definition to plan your integration. The guide covers setup, reads, updates, evidence uploads and document generation.

For writes, follow the documented concurrency and retry rules. Check status after asynchronous operations such as evidence uploads and document generation.

-    [Read the API and agent guide](<https://secboost.com/api/reference/agent-guide/>)  Workflows, request examples and recovery 
-    [Read authentication and permissions](<https://secboost.com/api/reference/authentication/>)  Token types, scope and read/write access 
-    [Download the OpenAPI definition](<https://secboost.com/developers/api/v1/openapi.json>)  Paths, fields and operation permissions 

Public documentation snapshot: 2026-10-09. Your deployment’s documentation describes its installed version.

Working with the API

## API questions

### Can agents update SecBoost through the API?

Yes. With a read/write token and the relevant permissions, an agent can update implementation and assessment records, attach evidence and request document generation. The same scope, access and workflow rules apply as for other integrations.

### What if I want an agent to have read-only access?

Create a read-only token for the records it needs. The agent can summarise evidence, prepare reports or transfer permitted data to another system, without editing SecBoost. It can download existing document outputs, but generating new SecBoost documents requires read/write access.

### Does an API token grant access to everything?

No. Access depends on the selected permissions, credential type and target, the owner’s current permissions and access, product tier and normal workflow rules. Project credentials are bound to one project; organisation credentials support the permitted work within one organisation.

### Which documentation should I use?

Use the public snapshot to explore the API and plan an integration. When connecting to SecBoost, use the guides and OpenAPI definition served by your deployment: they describe the contract for its installed version.

### Are these ready-made integrations?

The API supports your own scripts, agents and integration tools. The examples on this page describe workflows you can build using the API. They do not imply a preconfigured connector to every reporting or assurance platform.

## What would you like to connect?

Tell us which records you need, which tools use them and whether your integration needs to read or write.

 [Discuss your integration](<https://secboost.com/contact/>)
