Get all vendors
curl --request GET \
--url https://api.matproof.com/v1/vendors \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.matproof.com/v1/vendors"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.matproof.com/v1/vendors', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.matproof.com/v1/vendors",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.matproof.com/v1/vendors"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.matproof.com/v1/vendors")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.matproof.com/v1/vendors")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"data": [
{
"id": "vnd_abc123def456",
"name": "CloudTech Solutions Inc.",
"description": "Cloud infrastructure provider offering AWS-like services",
"category": "cloud",
"status": "not_assessed",
"inherentProbability": "possible",
"inherentImpact": "moderate",
"residualProbability": "unlikely",
"residualImpact": "minor",
"website": "https://www.cloudtechsolutions.com",
"assigneeId": "mem_abc123def456",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z"
}
],
"count": 12,
"authType": "api-key",
"authenticatedUser": {
"id": "usr_def456ghi789",
"email": "user@example.com"
}
}{
"message": "Invalid or expired API key"
}{
"message": "Organization with ID org_abc123def456 not found"
}{
"message": "Internal server error"
}Sample endpoints
List vendors
Retrieve the full vendor register including criticality, DPA status, and DORA Article 28 fields.
GET
/
v1
/
vendors
Get all vendors
curl --request GET \
--url https://api.matproof.com/v1/vendors \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.matproof.com/v1/vendors"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.matproof.com/v1/vendors', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.matproof.com/v1/vendors",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.matproof.com/v1/vendors"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.matproof.com/v1/vendors")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.matproof.com/v1/vendors")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"data": [
{
"id": "vnd_abc123def456",
"name": "CloudTech Solutions Inc.",
"description": "Cloud infrastructure provider offering AWS-like services",
"category": "cloud",
"status": "not_assessed",
"inherentProbability": "possible",
"inherentImpact": "moderate",
"residualProbability": "unlikely",
"residualImpact": "minor",
"website": "https://www.cloudtechsolutions.com",
"assigneeId": "mem_abc123def456",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z"
}
],
"count": 12,
"authType": "api-key",
"authenticatedUser": {
"id": "usr_def456ghi789",
"email": "user@example.com"
}
}{
"message": "Invalid or expired API key"
}{
"message": "Organization with ID org_abc123def456 not found"
}{
"message": "Internal server error"
}The list-vendors endpoint returns your full vendor register — feeding GDPR Article 28 transparency, DORA Article 28-30 ICT third-party risk, and ISO 27001 A.5.19 supplier inventory. Use it to drive procurement-side dashboards, due-diligence reports, or to mirror the register into a parent organization’s GRC tool.
Combine filters to slice the register narrowly:
Common use cases
- Article 28 register export — pull the full register for GDPR DPA submissions
- DORA Register of Information (ROI) — feed the ESAs’ XLSX submission format
- Concentration risk analysis — pipe the data into a custom analysis (e.g. counting how many critical functions depend on a single hyperscaler)
- Procurement integration — sync vendor records bidirectionally with Coupa / Ariba / etc.
Filtering
Common filters:| Query parameter | Values | Use |
|---|---|---|
criticality | critical / important / standard | DORA-style criticality slicing |
processesPersonalData | true / false | GDPR Art. 28 register subset |
ictService | true / false | DORA Art. 28 ICT-vendor subset |
category | freeform string | Industry / category match |
country | ISO 3166-1 alpha-2 | Filter by country of registration |
# Critical ICT vendors that process personal data
curl "https://api.matproof.com/v1/vendors?criticality=critical&ictService=true&processesPersonalData=true" \
-H "X-API-Key: ..."
Pagination
DefaultperPage is 50, max 200. For organizations with hundreds of vendors, paginate with page and stop when meta.page === meta.totalPages.
DPA status
Each vendor record includesdpaStatus: signed / pending / not_required. Filter by dpaStatus=pending to surface vendors still missing DPAs — useful for an end-of-quarter DPA cleanup sweep.
Sub-processors
Sub-processors of each vendor (when collected via the Article 28 questionnaire) are returned in thesubProcessors array. Each sub-processor entry includes name, country, and processing-purpose category.
Response shape
The interactive playground below renders the full schema. The fields most often consumed by external systems are:id,name,country,categorycriticality,ictService,processesPersonalDatadpaStatus,dpaSignedAt,dpaUrllastReviewedAt,nextReviewDuesubProcessors[]— sub-processor disclosurestransferMechanism— for non-EU vendors handling personal data
Authorizations
Organisation API key. Generate one in the app under Settings, then API keys. Keys are stored hashed, so the plaintext is shown once.
Headers
Organization ID (required for session auth, optional for API key auth)
Was this page helpful?