How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

TrustLayer Request Records API

The Request Records API from TrustLayer — 7 operation(s) for request records.

TrustLayer Request Records API is one of 21 APIs that TrustLayer publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Request Records. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 14 operations across 7 paths, and defines 2 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 2 base URLs: http://localhost:4000/v1, https://api.trustlayer.io/v1.

14 operations 7 paths 2 schemas 3 DELETE5 GET1 PATCH4 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.trustlayer.io/v2
Authentication
API Key
License
Terms of Service
Resource Areas
1

Authentication & Security 1

TrustLayer Request Records API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (Token). By default, every request must be authenticated.

Paths & Operations 14

Across 7 paths, the API surfaces 14 operations — 3 DELETE, 5 GET, 1 PATCH, 4 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Request Records 14
GET
/request-records
List request records in the caller's organization. Results are always scoped to the caller's organization. Supports pagination via limit and skip. Filtering: id (objectId), createdAt (date), updatedA…
14 params → 200400401403404500
POST
/request-records
Create a new request record and assign it to a primary record. The owning organization is derived from the access token. Optionally pass a complianceProfileId to attach a compliance profile at creati…
body → 201400401403404500
GET
/request-records/{id}
Read a single request record by id, scoped to the caller's organization. Use the fields query parameter to limit the response to a projection of the record. Use ?fields=complianceModules to include t…
2 params → 200400401403404500
PATCH
/request-records/{id}
Partially update a request record. Any subset of writable fields may be provided; omitted fields are left unchanged. Status changes are accepted on this endpoint and are applied via the dedicated sta…
1 param body → 200400401403404500
DELETE
/request-records/{id}
Delete a request record. Returns the deleted record id on success. Deleting a record that does not exist returns 404 with the shared NotFoundError shape.
1 param → 200400401403404500
GET
/request-records/{id}/attributes
List attributes (custom field values) embedded in a request record. Attributes are stored as an embedded array on the record — there is no separate filtering beyond pagination. Results are scoped to…
3 params → 200400401403404500
GET
/request-records/{id}/attributes/{attributeId}
Read a single attribute (custom field value) embedded in a request record. Returns 404 when the request record or the specific attribute does not exist.
2 params → 200400401403404500
PUT
/request-records/{id}/attributes/{attributeId}
Create or replace an attribute (custom field value) on a request record. This is a full replacement — omitting value or optionIds clears that field. Returns 404 when the request record or the referen…
2 params body → 200400401403404500
DELETE
/request-records/{id}/attributes/{attributeId}
Delete an attribute (custom field value) from a request record. Returns 404 when the request record or the specific attribute does not exist.
2 params → 200400401403404500
POST
/request-records/{id}/compliance-profile
Assign a compliance profile to a request record, scoped to the caller's organization. Assigning a profile attaches its rules and document checklists to the request record and starts compliance evalua…
1 param body → 204400401403404500
DELETE
/request-records/{id}/compliance-profile
Unassign the compliance profile from a request record, scoped to the caller's organization. Removes the previously assigned profile and stops compliance tracking for the request record. The operation…
1 param → 204400401403404500
POST
/request-records/{id}/compliance-certificate
Create a compliance certificate for a request record. Accepts application/json with optional effectiveDate and expirationDate fields, or multipart/form-data with the same date fields plus a document…
1 param body → 201400401403404500
GET
/request-records/{id}/compliance-certificate
Get the latest non-archived compliance certificate document for a request record. Returns the document with a signed URL when present; returns 404 when no compliance certificate has been generated fo…
2 params → 200400401403404500
POST
/request-records/{id}/requirements
Add requirements to the request record's compliance profile. Each item is either a library reference (libraryRequirementId or attributeCode) or a custom definition (module/subject by code or label, a…
1 param body → 200400401403404500

Schemas 2

The contract defines 2 schemas that model the data the API accepts and returns. Each schema is shown below with its type and property counts.

objectIdInput
string
objectId
string

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

trustlayer-request-records-api-openapi.yml Raw ↑

Other APIs TrustLayer publishes across the network.

TrustLayer Auth API
TrustLayer branding API
TrustLayer compliance-profiles API
TrustLayer contacts API
TrustLayer Context Objects API
TrustLayer Context Records API
TrustLayer custom-fields API
TrustLayer Document Types API
TrustLayer documents API
TrustLayer Parties API
TrustLayer party-types API
TrustLayer Policies API
Where this information came from

This is an independent, third-party profile of TrustLayer Request Records API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.