E-ARI API v1
Programmatic access to your assessments, AI registry, vendor risk results, and compliance controls — pull E-ARI state into your GRC platform, BI stack, or internal dashboards. Read and write access on the Enterprise plan.
Authentication
Create a key in Portal → API Keys and send it as a Bearer token. Keys are scoped read or write and can be revoked at any time. Rate limit: 30 requests / 15 minutes per key.
curl https://www.e-ari.com/api/v1/assessments \ -H "Authorization: Bearer eari_live_..."
Endpoints
/api/v1/assessmentsreadCompleted assessments with overall score, maturity band, entity type, and per-pillar scores.
/api/v1/systemsreadAI system registry — name, purpose, deployer role, risk tier, classification rationale.
/api/v1/systems/:idreadSingle registry entry including open obligation gaps.
/api/v1/systemswriteCreate a registry entry (name, description, purpose, deployerRole, sector).
/api/v1/systems/:idwriteUpdate registry-entry fields.
/api/v1/systems/:idwriteDelete a registry entry and its dependent artefacts.
/api/v1/vendorsreadThird-party AI vendors with questionnaire status, risk score, tier, and review dates.
/api/v1/controlsreadDerived compliance controls: passing / failing / pending per EU AI Act obligation, plus attestation warnings.
Evidence connectors
Point E-ARI at a source with your own credentials and it fetches the evidence — every connector lands bytes through the same ingestion core as the push API: server-recomputed SHA-256, content-addressed dedupe, the evidence quota, and a sourceRef trace on every artifact. All pulls need a write-scoped key and a systemId you own. The endpoint-by-endpoint guide (request bodies, credentials, env fallbacks, limitations) lives in the repository's evidence-connectors documentation.
curl -X POST https://www.e-ari.com/api/integrations/pull/confluence \
-H "Authorization: Bearer eari_live_..." \
-H "Content-Type: application/json" \
-d '{ "site": "https://yourco.atlassian.net",
"email": "you@yourco.eu",
"apiToken": "ATATT…",
"systemId": "sys_…" }'/api/integrations/pull/githubGitHublivePAT (GITHUB_TOKEN env or repo-scoped) · Policies, model cards, docs — real evidence
/api/integrations/pull/confluenceConfluenceexperimentalAtlassian email + API token · CQL-swept wiki pages, flattened to text
/api/integrations/pull/gdriveGoogle DriveexperimentalYour OAuth token (drive.readonly) · Folder documents (editor-native formats excluded)
/api/integrations/pull/notionNotionexperimentalIntegration token, shared with pages · Workspace pages, newest first, as text
/api/integrations/pull/slackSlackexperimentalxoxp/xoxb token (search:read, channels:history) · Decision threads as transcripts
/api/integrations/pull/jiraJiraexperimentalAtlassian email + API token · Issues as JSON records (audited, vault-skipped)
/api/integrations/pull/servicenowServiceNowexperimentalBasic auth or OAuth bearer · Table API records as JSON (audited, vault-skipped)
/api/integrations/pull/m365Microsoft 365experimentalGraph access token (Files/Sites.Read.All) · SharePoint / OneDrive documents
/api/integrations/pull/expenseExpense feedexperimentalThe signed HTTPS report URL itself · CSV + merchants feed shadow-AI discovery
/api/integrations/pull/entraEntra IDexperimentalGraph token (AuditLog.Read.All) · App-consent inventory → discovery feed
/api/integrations/pull/oktaOktaexperimentalSSWS API token · SSO app inventory → discovery feed
Experimental means built and mock-tested but not yet validated against a real tenant — the label comes off per connector once one has. Rate limit: 10 pulls / hour per key.
Responses & errors
Success responses wrap payloads in { "data": … }. Errors return { "error": "…" } with conventional status codes: 401 (missing/invalid key), 403 (insufficient scope or tier), 404, 429 (rate limit — includes retryAfter). List endpoints return up to 100–200 records, newest first.