Drata icon

CONNECT APP

Build with Drata

Drata automates your compliance journey from start to audit-ready and beyond and provides support from the security and compliance experts who built it.

Business Management

  • API key

MCP

Give your agent Drata tools

Every Drata action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's Drata account for each tool call — you store no tokens.

// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
  new URL("https://remote.mcp.pipedream.net/v3"),
  {
    requestInit: {
      headers: {
        Authorization: `Bearer ${accessToken}`,
        "x-pd-project-id": "{project_id}",
        "x-pd-environment": "production",
        "x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
        "x-pd-app-slug": "drata",
      },
    },
  },
)

const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)

const { tools } = await mcp.listTools()

// e.g. run Create Asset:
const result = await mcp.callTool({
  name: "drata-create-asset",
  arguments: {
    name: "Name",
    description: "Description",
  },
})

API PROXY

Call the Drata API directly

For an endpoint with no pre-built tool, the Connect proxy forwards your request to the Drata API with the connected user's credentials attached. You store no tokens and write no refresh logic.

const resp = await pd.proxy.get({
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  accountId: "apn_xxxxxxx",
  url: "https://public-api.drata.com/public/controls",
})

// Any allowed Drata endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.

SDK

Run Drata actions from your backend

Connect a user's Drata account once, then run Create Asset on their behalf from your own code — TypeScript, Python, or plain HTTP.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "drata-create-asset",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    drata: { authProvisionId: "apn_xxxxxxx" },
    name: "Name",
    description: "Description",
  },
})

MULTI-APP

Use Drata with other popular apps

Most products don't stop at one integration. Pair Drata with the other apps your users rely on, and ship use cases that span both.

REFERENCE

App details

Reference metadata for the Drata connector in the Pipedream registry.

App slug
drata
Authentication
API key
Categories
Business Management
Actions
14
Triggers
8
API proxy
Available